Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Breadcrumbs By Menu HIGH 8.8
CVE-2019-15865

The breadcrumbs-by-menu plugin before 1.0.3 for WordPress has CSRF.

Fix: 1.0.3+
Fix from $1,950 2019-09-03
Affiliates Manager HIGH 8.8
CVE-2019-15868

The affiliates-manager plugin before 2.6.6 for WordPress has CSRF.

Fix: 2.6.6+
Fix from $1,950 2019-09-03
Webp Converter For Media HIGH 8.8
CVE-2019-15834

The webp-converter-for-media plugin before 1.0.3 for WordPress has CSRF.

Fix: 1.0.3+
Fix from $1,950 2019-08-30
Wp Better Permalinks HIGH 8.8
CVE-2019-15835

The wp-better-permalinks plugin before 3.0.5 for WordPress has CSRF.

Fix: 3.0.5+
Fix from $1,950 2019-08-30
Facebook For Woocommerce HIGH 8.8
CVE-2019-15840

The facebook-for-woocommerce plugin before 1.9.14 for WordPress has CSRF.

Fix: 1.9.14+
Fix from $1,950 2019-08-30
Facebook For Woocommerce HIGH 8.8
CVE-2019-15841

The facebook-for-woocommerce plugin before 1.9.15 for WordPress has CSRF via ajax_woo_infobanner_post_click, ajax_woo_infobanner_post_xout, or ajax_f…

Fix: 1.9.15+
Fix from $1,950 2019-08-30
One Click Ssl HIGH 8.8
CVE-2019-15828

The one-click-ssl plugin before 1.4.7 for WordPress has CSRF.

Fix: 1.4.7+
Fix from $1,950 2019-08-30
Visitor Traffic Real Time Statistics HIGH 8.8
CVE-2019-15831

The visitors-traffic-real-time-statistics plugin before 1.12 for WordPress has CSRF in the settings page.

Fix: 1.12+
Fix from $1,950 2019-08-30
Visitor Traffic Real Time Statistics HIGH 8.8
CVE-2019-15832

The visitors-traffic-real-time-statistics plugin before 1.13 for WordPress has CSRF.

Fix: 1.13+
Fix from $1,950 2019-08-30
Photo Gallery HIGH 8.8
CVE-2015-9380

The photo-gallery plugin before 1.2.42 for WordPress has CSRF.

Fix: 1.2.42+
Fix from $1,950 2019-08-30
Wp Social Feed Gallery HIGH 8.8
CVE-2019-15779

The insta-gallery plugin before 2.4.8 for WordPress has no nonce validation for qligg_dismiss_notice or qligg_form_item_delete.

Fix: 2.4.8+
Fix from $1,950 2019-08-29
Social Likebox \& Feed HIGH 8.8
CVE-2019-15781

The facebook-by-weblizar plugin before 2.8.5 for WordPress has CSRF.

Fix: 2.8.5+
Fix from $1,950 2019-08-29
Handl Utm Grabber HIGH 8.8
CVE-2019-15769

The handl-utm-grabber plugin before 2.6.5 for WordPress has CSRF via add_option and update_option.

Fix: 2.6.5+
Fix from $1,950 2019-08-29
Woocommerce Address Book HIGH 8.8
CVE-2019-15770

The woo-address-book plugin before 1.6.0 for WordPress has save calls without nonce verification checks.

Fix: 1.6.0+
Fix from $1,950 2019-08-29
Cs31x Firmware MEDIUM 6.5
CVE-2019-10057

Various Lexmark products have CSRF.

No fix yet
Fix from $1,600 2019-08-28
Myt Project Management HIGH 8.8
CVE-2019-15496

MyT Project Management 1.5.1 lacks CSRF protection and, for example, allows a user/create CSRF attack. This could lead to an attacker tricking the ad…

No fix yet
Fix from $1,950 2019-08-28
Jenkins HIGH 8.8
CVE-2019-10384

Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed users to obtain CSRF tokens without an associated web session ID, resulting in CSRF tokens…

Fix: after 2.191
Fix from $1,950 2019-08-28
Django Crm HIGH 8.8
CVE-2019-11457

Multiple CSRF issues exist in MicroPyramid Django CRM 0.2.1 via /change-password-by-admin/, /api/settings/add/, /cases/create/, /change-password-by-a…

No fix yet
Fix from $1,950 2019-08-27
Wp Members HIGH 8.8
CVE-2019-15660

The wp-members plugin before 3.2.8 for WordPress has CSRF.

Fix: 3.2.8+
Fix from $1,950 2019-08-27
Insert Or Embed Articulate Content MEDIUM 6.5
CVE-2019-15648

The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a …

Fix: 4.29991+
Fix from $1,600 2019-08-27
Js Help Desk HIGH 8.8
CVE-2018-21002

The js-support-ticket plugin before 2.0.6 for WordPress has CSRF.

Fix: 2.0.6+
Fix from $1,950 2019-08-27
Bbpress Move Topics HIGH 8.8
CVE-2018-21006

The bbp-move-topics plugin before 1.1.6 for WordPress has CSRF.

Fix: 1.1.6+
Fix from $1,950 2019-08-27
Salesiq HIGH 8.8
CVE-2019-15645

The zoho-salesiq plugin before 1.0.9 for WordPress has CSRF.

Fix: 1.0.9+
Fix from $1,950 2019-08-27
Wp Rollback HIGH 8.8
CVE-2015-9343

The wp-rollback plugin before 1.2.3 for WordPress has CSRF.

Fix: 1.2.3+
Fix from $1,950 2019-08-27
Discourse MEDIUM 6.5
CVE-2019-15515

Discourse 2.3.2 sends the CSRF token in the query string.

Patch available
Fix from $1,600 2019-08-26
Jira MEDIUM 6.5
CVE-2019-11587

Various exposed resources of the ViewLogging class in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 bef…

Fix: 7.13.6 / 8.2.3+
Fix from $1,600 2019-08-23
Openitcockpit HIGH 8.8
CVE-2019-15491

openITCOCKPIT before 3.7.1 has CSRF, aka RVID 2-445b21.

Fix: 3.7.1+
Fix from $1,950 2019-08-23
Import Users From Csv With Meta HIGH 8.8
CVE-2019-15329

The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF.

Fix: 1.14.0.3+
Fix from $1,950 2019-08-22
Photo Gallery HIGH 8.8
CVE-2016-10918

The gallery-by-supsystic plugin before 1.8.6 for WordPress has CSRF.

Fix: 1.8.6+
Fix from $1,950 2019-08-22
Ios Xe HIGH 8.8
CVE-2019-12624EPSS 18%

A vulnerability in the web-based management interface of Cisco IOS XE New Generation Wireless Controller (NGWC) could allow an unauthenticated, remot…

Fix: after 3.11.xe
Fix from $1,950 2019-08-21