Vulnerability index

Browse CVEs

7,366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Navigate Cms HIGH 8.8
CVE-2020-37054

Navigate CMS 2.8.7 contains a cross-site request forgery vulnerability that allows attackers to upload malicious extensions through a crafted HTML pa…

No fix yet
Fix from $1,950 2026-01-30
Unclassified MEDIUM 5.3
CVE-2020-37046

Sistem Informasi Pengumuman Kelulusan Online 1.0 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized admin …

No fix yet
Fix from $1,600 2026-01-30
Unclassified MEDIUM 5.3
CVE-2020-37026

Sickbeard alpha contains a cross-site request forgery vulnerability that allows attackers to disable authentication by submitting crafted configurati…

No fix yet
Fix from $1,600 2026-01-30
Unclassified MEDIUM 5.3
CVE-2025-15550

birkir prime <= 0.4.0.beta.0 contains a cross-site request forgery vulnerability in its GraphQL endpoint that allows attackers to exploit GET-based q…

Mitigation only
Fix from $1,600 2026-01-29
Acquia Content Hub HIGH 8.1
CVE-2025-14472

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia Content Hub allows Cross Site Request Forgery.This issue affects Acquia Content Hub:…

Fix: 3.6.4 / 3.7.3+
Fix from $1,950 2026-01-28
Login Time Restriction HIGH 8.1
CVE-2025-13982

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Login Time Restriction allows Cross Site Request Forgery.This issue affects Login Time Rest…

Fix: 1.0.3+
Fix from $1,950 2026-01-28
Unclassified HIGH 8.5
CVE-2025-59901

Disk Pulse Enterprise v10.4.18 has an authenticated reflected XSS vulnerability in the '/monitor_directory?sid=' endpoint, caused by insufficient val…

Mitigation only
Fix from $1,950 2026-01-28
Diskpulse HIGH 8.0
CVE-2025-59891

Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user c…

Mitigation only
Fix from $1,950 2026-01-28
Diskpulse HIGH 8.0
CVE-2025-59892

Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user c…

Mitigation only
Fix from $1,950 2026-01-28
Diskpulse HIGH 8.0
CVE-2025-59893

Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user c…

Mitigation only
Fix from $1,950 2026-01-28
Diskpulse HIGH 8.0
CVE-2025-59894

Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user c…

Mitigation only
Fix from $1,950 2026-01-28
Ezcast Pro Dongle Ii Firmware HIGH 8.8
CVE-2026-24345

Cross-Site Request Forgery in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to bypass authorization checks and gain full access to t…

Mitigation only
Fix from $1,950 2026-01-27
Sigstore Python MEDIUM 5.0
CVE-2026-24408

sigstore-python is a Python tool for generating and verifying Sigstore signatures. Prior to version 4.2.0, the sigstore-python OAuth authentication f…

Fix: 4.2.0+
Fix from $1,600 2026-01-26
Unclassified MEDIUM 5.4
CVE-2026-24384

Cross-Site Request Forgery (CSRF) vulnerability in launchinteractive Merge + Minify + Refresh merge-minify-refresh allows Cross Site Request Forgery.…

Mitigation only
Fix from $1,600 2026-01-22
Unclassified MEDIUM 5.4
CVE-2026-24374

Cross-Site Request Forgery (CSRF) vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Cross …

Mitigation only
Fix from $1,600 2026-01-22
Unclassified MEDIUM 5.4
CVE-2026-24365

Cross-Site Request Forgery (CSRF) vulnerability in storeapps Stock Manager for WooCommerce woocommerce-stock-manager allows Cross Site Request Forger…

Mitigation only
Fix from $1,600 2026-01-22
Unclassified MEDIUM 5.4
CVE-2026-22483

Cross-Site Request Forgery (CSRF) vulnerability in winkm89 teachPress teachpress allows Cross Site Request Forgery.This issue affects teachPress: fro…

Mitigation only
Fix from $1,600 2026-01-22
Unclassified MEDIUM 5.4
CVE-2026-22382

Cross-Site Request Forgery (CSRF) vulnerability in Mikado-Themes PawFriends - Pet Shop and Veterinary WordPress Theme pawfriends allows Cross Site Re…

Mitigation only
Fix from $1,600 2026-01-22
Unclassified HIGH 7.1
CVE-2026-22355

Cross-Site Request Forgery (CSRF) vulnerability in gregmolnar Simple XML Sitemap simple-xml-sitemap allows Stored XSS.This issue affects Simple XML S…

Mitigation only
Fix from $1,950 2026-01-22
Online Course Registration MEDIUM 6.5
CVE-2025-70899

PHPgurukul Online Course Registration v3.1 lacks Cross-Site Request Forgery (CSRF) protection on all administrative forms. An attacker can perform un…

No fix yet
Fix from $1,600 2026-01-22
Getsimplecms MEDIUM 6.5
CVE-2021-47830

GetSimple CMS My SMTP Contact Plugin 1.1.1 contains a cross-site request forgery (CSRF) vulnerability. Attackers can craft a malicious webpage that, …

No fix yet
Fix from $1,600 2026-01-21
Tar MEDIUM 5.9
CVE-2026-23950

node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicod…

Fix: 7.5.4+
Fix from $1,600 2026-01-20
Prime HIGH 8.8
CVE-2026-1169

A security vulnerability has been detected in birkir prime up to 0.4.0.beta.0. This vulnerability affects unknown code. Such manipulation leads to cr…

Fix: after 0.4.0
Fix from $1,950 2026-01-19
Patients Waiting Area Queue Management System MEDIUM 6.5
CVE-2026-1148

A vulnerability was determined in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. This vulnerability affects unknown …

Mitigation only
Fix from $1,600 2026-01-19
News Portal MEDIUM 6.5
CVE-2026-1142

A security flaw has been discovered in PHPGurukul News Portal 1.0. The impacted element is an unknown function. Performing a manipulation results in …

No fix yet
Fix from $1,600 2026-01-19
Unclassified MEDIUM 5.3
CVE-2021-47820

Ubee EVW327 contains a cross-site request forgery vulnerability that allows attackers to enable remote access without user interaction. Attackers can…

No fix yet
Fix from $1,600 2026-01-16
Unclassified MEDIUM 5.3
CVE-2021-47800

b2evolution 7.2.2 contains a cross-site request forgery vulnerability that allows attackers to modify admin account details without authentication. A…

No fix yet
Fix from $1,600 2026-01-16
Easy\!appointments HIGH 8.8
CVE-2026-23622

Easy!Appointments is a self hosted appointment scheduler. In 1.5.2 and earlier, application/core/EA_Security.php::csrf_verify() only enforces CSRF fo…

Fix: after 1.5.2
Fix from $1,950 2026-01-15
Arunna MEDIUM 6.5
CVE-2021-47754

Arunna 1.0.0 contains a cross-site request forgery vulnerability that allows attackers to manipulate user profile settings without authentication. At…

No fix yet
Fix from $1,600 2026-01-15
Unclassified HIGH 7.1
CVE-2025-14615

The DASHBOARD BUILDER – WordPress plugin for Charts and Graphs plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to…

Mitigation only
Fix from $1,950 2026-01-14