Vulnerability index

Browse CVEs

7,366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Unclassified MEDIUM 5.4
CVE-2025-69021

Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Popup box ays-popup-box allows Cross Site Request Forgery.This issue affects Popup box: fr…

Mitigation only
Fix from $1,600 2025-12-30
Unclassified MEDIUM 5.4
CVE-2025-68998

Cross-Site Request Forgery (CSRF) vulnerability in Heateor Support Heateor Social Login heateor-social-login allows Cross Site Request Forgery.This i…

Mitigation only
Fix from $1,600 2025-12-30
Dedecms HIGH 8.8
CVE-2024-30855

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/makehtml_list_action.php.

No fix yet
Fix from $1,950 2025-12-29
D0116s1ula 22454 Firmware MEDIUM 6.5
CVE-2025-67013

The web management interface in ETL Systems Ltd DEXTRA Series ' Digital L-Band Distribution System v1.8 does not implement Cross-Site Request Forgery…

No fix yet
Fix from $1,600 2025-12-26
Net Admin HIGH 8.8
CVE-2019-25254

KYOCERA Net Admin 3.4.0906 contains a cross-site request forgery vulnerability that allows attackers to create administrative users without proper re…

No fix yet
Fix from $1,950 2025-12-24
Unclassified MEDIUM 5.3
CVE-2019-25250

Devolo dLAN 500 AV Wireless+ 3.1.0-1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions with…

No fix yet
Fix from $1,600 2025-12-24
Unclassified MEDIUM 5.3
CVE-2019-25247

Beward N100 H.264 VGA IP Camera M2.1.6 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions wi…

No fix yet
Fix from $1,600 2025-12-24
Unclassified MEDIUM 5.3
CVE-2019-25233

AVE DOMINAplus 1.10.x contains cross-site request forgery and cross-site scripting vulnerabilities that allow attackers to perform administrative act…

No fix yet
Fix from $1,600 2025-12-24
Unclassified MEDIUM 5.3
CVE-2019-25234

SmartHouse Webapp 6.5.33 contains multiple cross-site request forgery and cross-site scripting vulnerabilities that allow attackers to perform unauth…

No fix yet
Fix from $1,600 2025-12-24
Ipn4g Firmware MEDIUM 6.5
CVE-2018-25149

Microhard Systems IPn4G 1.1.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without use…

No fix yet
Fix from $1,600 2025-12-24
Unclassified MEDIUM 5.3
CVE-2018-25150

Ecessa ShieldLink SL175EHQ 10.7.4 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts wi…

No fix yet
Fix from $1,600 2025-12-24
Unclassified MEDIUM 5.3
CVE-2018-25152

Ecessa Edge EV150 10.7.4 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without aut…

No fix yet
Fix from $1,600 2025-12-24
Unclassified MEDIUM 5.3
CVE-2018-25127

SOCA Access Control System 180612 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without…

No fix yet
Fix from $1,600 2025-12-24
Unclassified MEDIUM 5.4
CVE-2025-68601

Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Cross Site Request For…

Mitigation only
Fix from $1,600 2025-12-24
Unclassified MEDIUM 5.4
CVE-2025-68573

Cross-Site Request Forgery (CSRF) vulnerability in Alessandro Piconi Simple Keyword to Link simple-keyword-to-link allows Cross Site Request Forgery.…

Mitigation only
Fix from $1,600 2025-12-24
Unclassified MEDIUM 5.4
CVE-2025-68567

Cross-Site Request Forgery (CSRF) vulnerability in wphocus My auctions allegro my-auctions-allegro-free-edition allows Cross Site Request Forgery.Thi…

Mitigation only
Fix from $1,600 2025-12-24
Unclassified HIGH 7.1
CVE-2025-67622

Cross-Site Request Forgery (CSRF) vulnerability in titopandub Evergreen Post Tweeter evergreen-post-tweeter allows Stored XSS.This issue affects Ever…

Mitigation only
Fix from $1,950 2025-12-24
Unclassified MEDIUM 5.4
CVE-2025-14734

The Amazon affiliate lite Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This i…

Mitigation only
Fix from $1,600 2025-12-20
Unclassified MEDIUM 6.1
CVE-2025-13365

The WP Hallo Welt plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing …

Mitigation only
Fix from $1,600 2025-12-20
Fastapi Users HIGH 8.8
CVE-2025-68481

FastAPI Users allows users to quickly add a registration and authentication system to their FastAPI project. Prior to version 15.0.2, the OAuth login…

Fix: 15.0.2+
Fix from $1,950 2025-12-19
Turms MEDIUM 6.1
CVE-2025-66906

Cross Site Request Forgery (CSRF) vulnerability in Turms Admin API thru v0.10.0-SNAPSHOT allows attackers to gain escalated privileges.

No fix yet
Fix from $1,600 2025-12-19
Online Food Delivery System HIGH 7.1
CVE-2025-1927

Cross-Site Request Forgery (CSRF) vulnerability in Restajet Information Technologies Inc. Online Food Delivery System allows Cross Site Request Forge…

Mitigation only
Fix from $1,950 2025-12-19
Freshrss MEDIUM 6.5
CVE-2025-59949

FreshRSS is a free, self-hostable RSS aggregator. Versions prior to 1.27.1 have a logout cross-site request forgery vulnerability that can lead to de…

Fix: 1.27.1+
Fix from $1,600 2025-12-18
Open Source Point Of Sale HIGH 8.8
CVE-2025-68434

Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.…

Fix: 3.4.2+
Fix from $1,950 2025-12-17
Ritecms MEDIUM 6.8
CVE-2025-67173

A Cross-Site Request Forgery (CSRF) in the page creation/editing function of RiteCMS v3.1.0 allows attackers to arbitrarily create pages via a crafte…

No fix yet
Fix from $1,600 2025-12-17
Upc2 Firmware HIGH 8.8
CVE-2025-66953

CSRF vulnerability in narda miteq Uplink Power Contril Unit UPC2 v.1.17 allows a remote attacker to execute arbitrary code via the Web-based manageme…

No fix yet
Fix from $1,950 2025-12-17
Keepassxc Browser HIGH 7.1
CVE-2025-65203

KeePassXC-Browser thru 1.9.9.2 autofills or prompts to fill stored credentials into documents rendered under a browser-enforced CSP directive and ifr…

Fix: after 1.9.9.2
Fix from $1,950 2025-12-17
Nopcommerce HIGH 8.8
CVE-2025-65593

nopCommerce 4.90.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Schedule Tasks functionality.

Mitigation only
Fix from $1,950 2025-12-16
Unclassified MEDIUM 5.4
CVE-2025-68082

Cross-Site Request Forgery (CSRF) vulnerability in SEMrush CY LTD Semrush Content Toolkit semrush-contentshake allows Cross Site Request Forgery.This…

Mitigation only
Fix from $1,600 2025-12-16
Unclassified MEDIUM 5.4
CVE-2025-68083

Cross-Site Request Forgery (CSRF) vulnerability in Meks Meks Quick Plugin Disabler meks-quick-plugin-disabler allows Cross Site Request Forgery.This …

Mitigation only
Fix from $1,600 2025-12-16