Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Xbtit MEDIUM 6.1
CVE-2018-15677

The newsfeed (aka /index.php?page=viewnews) in BTITeam XBTIT 2.5.4 has stored XSS via the title of a news item. This is also exploitable via CSRF.

Patch available
Fix from $1,600 2018-09-05
Xbtit HIGH 8.8
CVE-2018-15682

An issue was discovered in BTITeam XBTIT. Due to a lack of cross-site request forgery protection, it is possible to automate the action of sending pr…

Fix: after 2.5.4
Fix from $1,950 2018-09-05
Camera HIGH 8.8
CVE-2018-14769

VIVOTEK FD8177 devices before XXXXXX-VVTK-xx06a allow CSRF.

No fix yet
Fix from $1,950 2018-09-05
Baigo Cms MEDIUM 6.5
CVE-2018-16458

An issue was discovered in baigo CMS v2.1.1. There is an index.php?m=article&c=request CSRF that can cause publication of any article.

No fix yet
Fix from $1,600 2018-09-04
Frogcms HIGH 8.8
CVE-2018-16447

Frog CMS 0.9.5 has admin/?/user/edit/1 CSRF.

No fix yet
Fix from $1,950 2018-09-04
Cscms HIGH 8.8
CVE-2018-16448

Cscms 4 allows CSRF for creating a member via upload/admin.php/user/save, authenticating vip members via upload/admin.php/user/init/tid and upload/ad…

No fix yet
Fix from $1,950 2018-09-04
Onethink MEDIUM 6.5
CVE-2018-16449

OneThink 1.1.141212 allows CSRF for adding a page via admin.php?s=/Channel/add.html, adding a blog via admin.php?s=/Article/update.html, and setting …

No fix yet
Fix from $1,600 2018-09-04
Yfcmf HIGH 8.8
CVE-2018-16431

admin/admin/adminsave.html in YFCMF v3.0 allows CSRF to add an administrator account.

No fix yet
Fix from $1,950 2018-09-04
Fuel Cms HIGH 8.8
CVE-2018-16416

Cross-site request forgery (CSRF) vulnerability in my_profile/edit?inline= in FUEL CMS 1.4 allows remote attackers to change the administrator's pass…

No fix yet
Fix from $1,950 2018-09-03
Elefantcms HIGH 8.8
CVE-2018-16387

An issue was discovered in Elefant CMS before 2.0.5. There is a CSRF vulnerability that can add an account via user/add.

Fix: 2.0.5+
Fix from $1,950 2018-09-03
Ogma Cms HIGH 8.8
CVE-2018-16380

An issue was discovered in Ogma CMS 0.4 Beta. There is a CSRF vulnerability in users.php?action=createnew that can add an admin account.

No fix yet
Fix from $1,950 2018-09-03
Icms HIGH 8.8
CVE-2018-16366

An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=user&do=save allows CSRF.

No fix yet
Fix from $1,950 2018-09-02
Icms HIGH 8.8
CVE-2018-16365

An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=group&do=save allows CSRF.

No fix yet
Fix from $1,950 2018-09-02
Easycms HIGH 8.8
CVE-2018-16345

An issue was discovered in EasyCMS 1.5. There is a CSRF vulnerability that can update the admin password via index.php?s=/admin/rbacuser/update/navTa…

No fix yet
Fix from $1,950 2018-09-02
Cscms MEDIUM 6.5
CVE-2018-16337

An issue was discovered in Cscms V4.1.8. There is a CSRF vulnerability that can modify a website's basic configuration via upload/admin.php/setting/s…

No fix yet
Fix from $1,600 2018-09-02
Auracms HIGH 8.8
CVE-2018-16338

An issue was discovered in AuraCMS 2.3. There is a CSRF vulnerability that can change the administrator's password via admin.php?mod=users and subseq…

No fix yet
Fix from $1,950 2018-09-02
Empirecms HIGH 8.8
CVE-2018-16339

An issue was discovered in EmpireCMS 7.0. There is a CSRF vulnerability that can add administrators via upload/e/admin/user/AddUser.php?enews=AddUser.

No fix yet
Fix from $1,950 2018-09-02
Damicms HIGH 8.8
CVE-2018-16331

admin.php?s=/Admin/doedit in DamiCMS v6.0.0 allows CSRF to change the administrator account's password.

No fix yet
Fix from $1,950 2018-09-02
Icms HIGH 8.8
CVE-2018-16332

An issue was discovered in iCMS 7.0.9. There is an admincp.php?app=article&do=update CSRF vulnerability.

No fix yet
Fix from $1,950 2018-09-02
Icms HIGH 8.8
CVE-2018-16314

An issue was discovered in admincp.php in idreamsoft iCMS 7.0.11. When verifying CSRF_TOKEN, if CSRF_TOKEN does not exist, only the Referer header is…

No fix yet
Fix from $1,950 2018-09-01
Waimai Super Cms MEDIUM 6.5
CVE-2018-16315

In waimai Super Cms 20150505, there is a CSRF vulnerability that can change the configuration via admin.php?m=Config&a=add.

No fix yet
Fix from $1,600 2018-09-01
Pc2r Firmware HIGH 8.8
CVE-2018-11718

Xovis PC2, PC2R, and PC3 devices through 3.6.0 allow CSRF.

Fix: after 3.6.0
Fix from $1,950 2018-08-30
Aspnet HIGH 8.8
CVE-2018-15121

An issue was discovered in Auth0 auth0-aspnet and auth0-aspnet-owin. Affected packages do not use or validate the state parameter of the OAuth 2.0 an…

Mitigation only
Fix from $1,950 2018-08-29
Mp C4504ex Firmware HIGH 8.8
CVE-2018-15884

RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.

No fix yet
Fix from $1,950 2018-08-28
E107 HIGH 8.8
CVE-2018-15901

e107 2.1.8 has CSRF in 'usersettings.php' with an impact of changing details such as passwords of users including administrators.

No fix yet
Fix from $1,950 2018-08-28
Phpmyfaq HIGH 8.8
CVE-2014-6046

Multiple cross-site request forgery (CSRF) vulnerabilities in phpMyFAQ before 2.8.13 allow remote attackers to hijack the authentication of unspecifi…

Fix: 2.8.13+
Fix from $1,950 2018-08-28
Redaxo Cms HIGH 8.8
CVE-2018-15850

An issue was discovered in REDAXO CMS 4.7.2. There is a CSRF vulnerability that can add an administrator account via index.php?page=user.

Mitigation only
Fix from $1,950 2018-08-25
Flexo Cms HIGH 8.8
CVE-2018-15851

An issue was discovered in Flexo CMS v0.1.6. There is a CSRF vulnerability that can add an administrator via /admin/user/add.

Mitigation only
Fix from $1,950 2018-08-25
Damicms HIGH 8.8
CVE-2018-15844

An issue was discovered in DamiCMS 6.0.0. There is an CSRF vulnerability that can revise the administrator account's password via /admin.php?s=/Admin…

No fix yet
Fix from $1,950 2018-08-25
Gleez Cms HIGH 8.8
CVE-2018-15845

There is a CSRF vulnerability that can add an administrator account in Gleez CMS 1.2.0 via admin/users/add.

No fix yet
Fix from $1,950 2018-08-25