An issue was discovered on NETGEAR Nighthawk M1 (MR1100) devices before 12.06.03. The web-interface Cross-Site Request Forgery token is stored in a d…
It was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in some requests. An attacker could use this flaw t…
The custom-sidebars plugin before 3.1.0 for WordPress has CSRF related to set location, import actions, and export actions.
The custom-sidebars plugin before 3.0.8.1 for WordPress has CSRF.
The newsletter-by-supsystic plugin before 1.1.8 for WordPress has CSRF.
The responsive-menu plugin before 3.1.4 for WordPress has no CSRF protection mechanism for the admin interface.
The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF.
The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF.
The simple-fields plugin before 1.2 for WordPress has CSRF in the admin interface.
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature.
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature.
The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature.
The google-document-embedder plugin before 2.6.2 for WordPress has CSRF.
The simple-add-pages-or-posts plugin before 1.7 for WordPress has CSRF for deleting users.
The simple-membership plugin before 3.3.3 for WordPress has multiple CSRF issues.
The wp-editor plugin before 1.2.6 for WordPress has CSRF.
The web server component of TIBCO Software Inc.'s TIBCO LogLogic Enterprise Virtual Appliance, and TIBCO LogLogic Log Management Intelligence contain…
The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF.
The twitter-cards-meta plugin before 2.5.0 for WordPress has CSRF.
The wp-database-backup plugin before 4.3.3 for WordPress has CSRF.
The wp-database-backup plugin before 4.3.1 for WordPress has CSRF.
Bagisto 0.1.5 allows CSRF under /admin URIs.
The Lightbox Plus Colorbox plugin through 2.7.2 for WordPress has cross-site request forgery (CSRF) via wp-admin/admin.php?page=lightboxplus, as demo…
Neet AirStream NAS1.1 devices have a password of ifconfig for the root account. This cannot be changed via the configuration page.
Edimax Wi-Fi Extender devices allow goform/formwlencryptvxd CSRF with resultant PSK key disclosure.
Cognitoys Dino devices allow profiles_add.html CSRF.
6kbbs 7.1 and 8.0 allows CSRF via portalchannel_ajax.php (id or code parameter) or admin.php (fileids parameter).
The codection "Import users from CSV with meta" plugin before 1.14.2.2 for WordPress allows wp-admin/admin-ajax.php?action=acui_delete_attachment CSR…
core/views/arprice_import_export.php in the ARPrice Lite plugin 2.2 for WordPress allows wp-admin/admin.php?page=arplite_import_export CSRF.
The admin-renamer-extended (aka Admin renamer extended) plugin 3.2.1 for WordPress allows wp-admin/plugins.php?page=admin-renamer-extended/admin.php …