Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Users Ultra Membership HIGH 8.8
CVE-2015-9394

The users-ultra plugin before 1.5.63 for WordPress has CSRF via action=package_add_new to wp-admin/admin-ajax.php.

Fix: 1.5.63+
Fix from $1,950 2019-09-20
Beauty Premium MEDIUM 6.5
CVE-2016-10997

The beauty-premium theme 1.0.8 for WordPress has CSRF with resultant arbitrary file upload in includes/sendmail.php.

No fix yet
Fix from $1,600 2019-09-20
Mtouch Quiz MEDIUM 6.5
CVE-2015-9387

The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/options-general.php CSRF.

Fix: 3.1.3+
Fix from $1,600 2019-09-20
Mtouch Quiz MEDIUM 6.5
CVE-2015-9388

The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/edit.php CSRF with resultant XSS.

Fix: 3.1.3+
Fix from $1,600 2019-09-20
Adas HIGH 8.8
CVE-2019-15089

An issue was discovered in PRiSE adAS 1.7.0. Forms have no CSRF protection, letting an attacker execute actions as the administrator.

Mitigation only
Fix from $1,950 2019-09-20
Layerbb HIGH 8.8
CVE-2019-16531

LayerBB before 1.1.4 has multiple CSRF issues, as demonstrated by changing the System Settings via admin/general.php.

Fix: 1.1.4+
Fix from $1,950 2019-09-20
Leenk.me HIGH 8.8
CVE-2016-10989

The leenkme plugin before 2.6.0 for WordPress has wp-admin/admin.php?page=leenkme_facebook CSRF.

Fix: 2.6.0+
Fix from $1,950 2019-09-17
Fluid Responsive Slideshow HIGH 8.8
CVE-2016-10974

The fluid-responsive-slideshow plugin before 2.2.7 for WordPress has frs_save CSRF with resultant stored XSS.

Fix: 2.2.7+
Fix from $1,950 2019-09-17
Tag Miner HIGH 8.8
CVE-2016-10978

The fossura-tag-miner plugin before 1.1.5 for WordPress has CSRF.

Fix: after 1.1.2
Fix from $1,950 2019-09-17
Kento Post View Counter HIGH 8.8
CVE-2016-10982

The kento-post-view-counter plugin through 2.8 for WordPress has wp-admin/admin.php?page=kentopvc_settings CSRF.

Fix: after 2.8
Fix from $1,950 2019-09-17
Icegram Engage MEDIUM 6.5
CVE-2016-10962

The icegram plugin before 1.9.19 for WordPress has CSRF via the wp-admin/edit.php option_name parameter.

Fix: 1.9.19+
Fix from $1,600 2019-09-16
Niushop HIGH 8.8
CVE-2019-16311

NIUSHOP V1.11 has CSRF via search_info to index.php.

No fix yet
Fix from $1,950 2019-09-14
Fedora MEDIUM 6.5
CVE-2019-12922EPSS 10%

A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.

Fix: after 4.9.0.1
Fix from $1,600 2019-09-13
Piwigo CRITICAL 9.6
CVE-2019-13363

admin.php?page=notification_by_mail in Piwigo 2.9.5 has XSS via the nbm_send_html_mail, nbm_send_mail_as, nbm_send_de…

No fix yet
Fix from $2,300 2019-09-13
Piwigo CRITICAL 9.6
CVE-2019-13364

admin.php?page=account_billing in Piwigo 2.9.5 has XSS via the vat_number, billing_name, company, or billing_address parameter. This is e…

No fix yet
Fix from $2,300 2019-09-13
Wp D3 HIGH 8.8
CVE-2016-10946

The wp-d3 plugin before 2.4.1 for WordPress has CSRF.

Fix: 2.4.1+
Fix from $1,950 2019-09-13
Multisite Post Duplicator HIGH 8.8
CVE-2016-10944

The multisite-post-duplicator plugin before 1.1.3 for WordPress has wp-admin/tools.php?page=mpd CSRF.

Fix: 1.1.3+
Fix from $1,950 2019-09-13
Pagelines HIGH 8.8
CVE-2016-10945

The PageLines theme 1.1.4 for WordPress has wp-admin/admin-post.php?page=pagelines CSRF.

Fix: after 1.1.4
Fix from $1,950 2019-09-13
Copy Me MEDIUM 6.5
CVE-2016-10938

The copy-me plugin 1.0.0 for WordPress has CSRF for copying non-public posts to a public location.

No fix yet
Fix from $1,600 2019-09-13
Pr S300ne Firmware HIGH 8.8
CVE-2019-5986

Cross-site request forgery (CSRF) vulnerability in Hikari Denwa router/Home GateWay (Hikari Denwa router/Home GateWay provided by NIPPON TELEGRAPH AN…

Fix: after 19.41
Fix from $1,950 2019-09-12
Wordpress Ultra Simple Paypal Shopping Cart HIGH 8.8
CVE-2019-5992

Cross-site request forgery (CSRF) vulnerability in WordPress Ultra Simple Paypal Shopping Cart v4.4 and earlier allows remote attackers to hijack the…

Fix: after 4.4
Fix from $1,950 2019-09-12
Category Specific Rss Feed Subscription HIGH 8.8
CVE-2019-5993

Cross-site request forgery (CSRF) vulnerability in Category Specific RSS feed Subscription version v2.0 and earlier allows remote attackers to hijack…

Fix: after 2.0
Fix from $1,950 2019-09-12
Sharepoint Foundation HIGH 8.8
CVE-2019-1259

A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, resulting in cross-site reques…

Patch available
Fix from $1,950 2019-09-11
Sharepoint Enterprise Server HIGH 8.8
CVE-2019-1261

A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, resulting in cross-site reques…

Patch available
Fix from $1,950 2019-09-11
Jira Server MEDIUM 6.5
CVE-2019-14998

The Webwork action Cross-Site Request Forgery (CSRF) protection implementation in Jira before version 8.4.0 allows remote attackers to bypass its pro…

Fix: 8.4.0+
Fix from $1,600 2019-09-11
Avada HIGH 8.8
CVE-2017-18607

The avada theme before 5.1.5 for WordPress has CSRF.

Fix: 5.1.5+
Fix from $1,950 2019-09-10
Teammate\+ MEDIUM 6.5
CVE-2019-10253

A Cross-Site Request Forgery (CSRF) vulnerability exists in TeamMate+ 21.0.0.0 that allows a remote attacker to modify application data (upload malic…

No fix yet
Fix from $1,600 2019-09-09
Unity Edgeconnect Sd Wan Firmware HIGH 8.8
CVE-2019-16099

Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows CSRF via JSON data to a .swf file.

No fix yet
Fix from $1,950 2019-09-08
If.svnadmin MEDIUM 6.5
CVE-2019-15128

iF.SVNAdmin through 1.6.2 allows svnadmin/usercreate.php CSRF to create a user.

Fix: after 1.6.2
Fix from $1,600 2019-09-06
Sentrifugo HIGH 8.8
CVE-2019-16059

Sentrifugo 3.2 lacks CSRF protection. This could lead to an attacker tricking the administrator into executing arbitrary code at index.php/dashboard/…

No fix yet
Fix from $1,950 2019-09-06