Vulnerability index

Browse CVEs

7,366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Qloapps MEDIUM 5.4
CVE-2021-41074

A CSRF issue in index.php in QloApps hotel eCommerce 1.5.1 allows an attacker to change the admin's email address via a crafted HTML document.

Mitigation only
Fix from $1,600 2026-01-12
Unclassified MEDIUM 5.4
CVE-2025-14976

The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugi…

Mitigation only
Fix from $1,600 2026-01-10
React Router MEDIUM 6.5
CVE-2026-22030

React Router is a router for React. In @remix-run/server-runtime version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, React Router (or Rem…

Fix: 2.17.3+
Fix from $1,600 2026-01-10
Gestsup HIGH 8.8
CVE-2026-22194

GestSup versions up to and including 3.2.60 contain a cross-site request forgery (CSRF) vulnerability where the application does not verify the authe…

Fix: after 3.2.56
Fix from $1,950 2026-01-09
Authlib HIGH 8.8
CVE-2025-68158

Authlib is a Python library which builds OAuth and OpenID Connect servers. In versions 1.0.0 through 1.6.5, cache-backed state/request-token storage …

Fix: 1.6.6+
Fix from $1,950 2026-01-08
Print Shop Pro Webdesk MEDIUM 6.8
CVE-2025-61547

Cross-Site Request Forgery (CSRF) is present on all functions in edu Business Solutions Print Shop Pro WebDesk version 18.34 (fixed in 19.76). The ap…

No fix yet
Fix from $1,600 2026-01-08
Unclassified MEDIUM 5.3
CVE-2019-25259

Leica Geosystems GR10/GR25/GR30/GR50 GNSS 4.30.063 contains a cross-site request forgery vulnerability that allows attackers to perform administrativ…

No fix yet
Fix from $1,600 2026-01-08
Unclassified MEDIUM 6.1
CVE-2025-13519

The SVG Map Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missi…

Mitigation only
Fix from $1,600 2026-01-07
Snapgear Sg560 Firmware HIGH 8.8
CVE-2020-36908

SnapGear Management Console SG560 version 3.1.5 contains a cross-site request forgery vulnerability that allows attackers to perform administrative a…

No fix yet
Fix from $1,950 2026-01-06
Unclassified MEDIUM 5.4
CVE-2023-52212

Cross-Site Request Forgery (CSRF) vulnerability in Automattic WP Job Manager allows Cross Site Request Forgery.This issue affects WP Job Manager: fro…

Mitigation only
Fix from $1,600 2026-01-05
Emlog CRITICAL 9.3
CVE-2026-21430

Emlog is an open source website building system. In version 2.5.23, article creation functionality is vulnerable to cross-site request forgery (CSRF)…

No fix yet
Fix from $2,300 2026-01-02
Phpems HIGH 8.8
CVE-2025-15405

A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function. The manipulation results in cross-site request forger…

Fix: after 11.0
Fix from $1,950 2026-01-01
Unclassified HIGH 7.1
CVE-2025-31054

Cross-Site Request Forgery (CSRF) vulnerability in Themefy Bloggie allows Reflected XSS.This issue affects Bloggie: from n/a through 2.0.8.

Mitigation only
Fix from $1,950 2025-12-31
Unclassified MEDIUM 5.4
CVE-2025-62134

Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Contact Form Widget new-contact-form-widget allows Cross Site Request Forgery.This issue…

Mitigation only
Fix from $1,600 2025-12-31
Unclassified MEDIUM 5.4
CVE-2025-62117

Cross-Site Request Forgery (CSRF) vulnerability in Jayce53 EasyIndex easyindex allows Cross Site Request Forgery.This issue affects EasyIndex: from n…

Mitigation only
Fix from $1,600 2025-12-31
Unclassified MEDIUM 5.4
CVE-2025-62120

Cross-Site Request Forgery (CSRF) vulnerability in Rick Beckman OpenHook thesis-openhook allows Cross Site Request Forgery.This issue affects OpenHoo…

Mitigation only
Fix from $1,600 2025-12-31
Everest Backup HIGH 8.1
CVE-2025-62992

Cross-Site Request Forgery (CSRF) vulnerability in everestthemes Everest Backup everest-backup allows Path Traversal.This issue affects Everest Backu…

Fix: after 2.3.9
Fix from $1,950 2025-12-31
Unclassified HIGH 7.1
CVE-2025-49028

Cross-Site Request Forgery (CSRF) vulnerability in Zoho Mail Zoho ZeptoMail transmail allows Stored XSS.This issue affects Zoho ZeptoMail: from n/a t…

Mitigation only
Fix from $1,950 2025-12-31
Unclassified HIGH 7.1
CVE-2025-49353

Cross-Site Request Forgery (CSRF) vulnerability in Marcin Kijak Noindex by Path noindex-by-path allows Stored XSS.This issue affects Noindex by Path:…

Mitigation only
Fix from $1,950 2025-12-31
Unclassified HIGH 7.1
CVE-2025-49354

Cross-Site Request Forgery (CSRF) vulnerability in Mindstien Technologies Recent Posts From Each Category recent-posts-from-each-category allows Stor…

Mitigation only
Fix from $1,950 2025-12-31
Unclassified HIGH 7.1
CVE-2025-68885

Cross-Site Request Forgery (CSRF) vulnerability in page-carbajal Custom Post Status custom-post-status allows Stored XSS.This issue affects Custom Po…

Mitigation only
Fix from $1,950 2025-12-31
Unclassified HIGH 7.1
CVE-2025-49342

Cross-Site Request Forgery (CSRF) vulnerability in merzedes Custom Style custom-style allows Stored XSS.This issue affects Custom Style: from n/a thr…

Mitigation only
Fix from $1,950 2025-12-31
Unclassified HIGH 7.1
CVE-2025-49343

Cross-Site Request Forgery (CSRF) vulnerability in socialprofilr Social Profilr social-profilr-display-social-network-profile allows Stored XSS.This …

No fix yet
Fix from $1,950 2025-12-31
Unclassified HIGH 7.1
CVE-2025-49344

Cross-Site Request Forgery (CSRF) vulnerability in reneade SensitiveTagCloud sensitive-tag-cloud allows Stored XSS.This issue affects SensitiveTagClo…

Mitigation only
Fix from $1,950 2025-12-31
Unclassified HIGH 7.1
CVE-2025-49345

Cross-Site Request Forgery (CSRF) vulnerability in mg12 WP-EasyArchives wp-easyarchives allows Stored XSS.This issue affects WP-EasyArchives: from n/…

Mitigation only
Fix from $1,950 2025-12-31
Unclassified HIGH 7.1
CVE-2025-59137

Cross-Site Request Forgery (CSRF) vulnerability in eleopard Behance Portfolio Manager portfolio-manager-powered-by-behance allows Stored XSS.This iss…

Mitigation only
Fix from $1,950 2025-12-31
Unclassified HIGH 7.1
CVE-2025-49346

Cross-Site Request Forgery (CSRF) vulnerability in peterwsterling Simple Archive Generator simple-archive-generator allows Stored XSS.This issue affe…

Mitigation only
Fix from $1,950 2025-12-31
Unclassified HIGH 7.1
CVE-2025-59131

Cross-Site Request Forgery (CSRF) vulnerability in hoernerfranz WP-CalDav2ICS wp-caldav2ics allows Stored XSS.This issue affects WP-CalDav2ICS: from …

Mitigation only
Fix from $1,950 2025-12-30
Onu Jf511 Tv Firmware HIGH 8.8
CVE-2022-50804

JM-DATA ONU JF511-TV version 1.0.67 is vulnerable to cross-site request forgery (CSRF) attacks, allowing attackers to perform administrative actions …

No fix yet
Fix from $1,950 2025-12-30
Unclassified CRITICAL 9.6
CVE-2025-52835

Cross-Site Request Forgery (CSRF) vulnerability in ConoHa by GMO WING WordPress Migrator wing-migrator allows Upload a Web Shell to a Web Server.This…

Mitigation only
Fix from $2,300 2025-12-30