Vulnerability index

Browse CVEs

7,366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Weblate MEDIUM 5.0
CVE-2025-66407

Weblate is a web based localization tool. The Create Component functionality in Weblate allows authorized users to add new translation components by …

Fix: 5.15+
Fix from $1,600 2025-12-16
Unclassified HIGH 8.0
CVE-2025-13970

OpenPLC_V3 is vulnerable to a cross-site request forgery (CSRF) attack due to the absence of proper CSRF validation. This issue allows an unauthent…

Mitigation only
Fix from $1,950 2025-12-13
Easyimages2.0 HIGH 8.8
CVE-2025-65472

A Cross-Site Request Forgery (CSRF) in the /admin/admin.inc.php component of EasyImages 2.0 v2.8.6 and below allows attackers to escalate privileges …

Fix: after 2.8.6
Fix from $1,950 2025-12-11
Digital Signage System HIGH 8.8
CVE-2020-36900

All-Dynamics Digital Signage System 2.0.2 contains a cross-site request forgery vulnerability that allows attackers to create administrative users wi…

No fix yet
Fix from $1,950 2025-12-10
Medivision Digital Signage Firmware HIGH 8.8
CVE-2020-36901

UBICOD Medivision Digital Signage 1.5.1 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accou…

No fix yet
Fix from $1,950 2025-12-10
Fusion Digital Signage HIGH 8.8
CVE-2020-36886

SpinetiX Fusion Digital Signage 3.4.8 contains a cross-site request forgery vulnerability that allows attackers to create administrative user account…

Fix: after 3.4.8
Fix from $1,950 2025-12-10
1panel HIGH 7.1
CVE-2025-34429

1Panel versions 1.10.33 - 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the web port configuration functionality. The port-chan…

Fix: after 2.0.15
Fix from $1,950 2025-12-10
1panel HIGH 7.1
CVE-2025-34410

1Panel versions 1.10.33 - 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the Change Username functionality available from the se…

Fix: after 2.0.15
Fix from $1,950 2025-12-10
Izero Box Full Firmware HIGH 8.8
CVE-2021-47730

Selea Targa IP OCR-ANPR Camera contains a cross-site request forgery vulnerability that allows attackers to create administrative users without authe…

No fix yet
Fix from $1,950 2025-12-09
Provision HIGH 8.8
CVE-2021-47723

STVS ProVision 5.9.10 contains a cross-site request forgery vulnerability that allows attackers to perform actions with administrative privileges by …

No fix yet
Fix from $1,950 2025-12-09
Allsky HIGH 8.8
CVE-2025-65573

Cross Site Request Forgery (CSRF) vulnerability in AllskyTeam AllSky v2024.12.06_06 allows remote attackers to cause a denial of service via function…

No fix yet
Fix from $1,950 2025-12-09
Unclassified HIGH 7.1
CVE-2025-67534

Cross-Site Request Forgery (CSRF) vulnerability in Jacques Malgrange Rencontre rencontre allows Stored XSS.This issue affects Rencontre: from n/a thr…

Mitigation only
Fix from $1,950 2025-12-09
Online Booking \& Scheduling Calendar HIGH 8.8
CVE-2025-67472

Cross-Site Request Forgery (CSRF) vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allow…

Fix: 4.6.0+
Fix from $1,950 2025-12-09
Unclassified MEDIUM 5.4
CVE-2025-67467

Cross-Site Request Forgery (CSRF) vulnerability in StellarWP GiveWP give allows Cross Site Request Forgery.This issue affects GiveWP: from n/a throug…

Mitigation only
Fix from $1,600 2025-12-09
Unclassified HIGH 7.1
CVE-2025-63030

Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal New User Approve new-user-approve allows Cross Site Request Forgery.This issue affects …

Mitigation only
Fix from $1,950 2025-12-09
Unclassified MEDIUM 6.5
CVE-2025-62739

Cross-Site Request Forgery (CSRF) vulnerability in SaifuMak Add Custom Codes add-custom-codes allows Cross Site Request Forgery.This issue affects Ad…

Mitigation only
Fix from $1,600 2025-12-09
Unclassified HIGH 7.1
CVE-2025-49341

Cross-Site Request Forgery (CSRF) vulnerability in Alex Furr PDF Creator Lite pdf-creator-lite allows Stored XSS.This issue affects PDF Creator Lite:…

Mitigation only
Fix from $1,950 2025-12-09
Unclassified HIGH 7.1
CVE-2025-49347

Cross-Site Request Forgery (CSRF) vulnerability in Jupitercow WP sIFR wp-sifr allows Stored XSS.This issue affects WP sIFR: from n/a through <= 0.6.8…

Mitigation only
Fix from $1,950 2025-12-09
Unclassified HIGH 7.1
CVE-2025-49351

Cross-Site Request Forgery (CSRF) vulnerability in Valentin Agachi Create Posts & Terms create-posts-terms allows Stored XSS.This issue affects Creat…

Mitigation only
Fix from $1,950 2025-12-09
Unclassified CRITICAL 9.6
CVE-2025-11022

Cross-Site Request Forgery (CSRF) vulnerability in Personal Project Panilux allows Cross Site Request Forgery.  This CSRF vulnerability resulting …

Mitigation only
Fix from $2,300 2025-12-09
Tuleap MEDIUM 5.4
CVE-2025-64499

Tuleap is a free and open source suite for management of software development and collaboration. Tuleap Community Editon versions prior to 17.0.99.17…

Fix: 16.12-10 / 16.13-7+
Fix from $1,600 2025-12-08
Unclassified HIGH 7.0
CVE-2025-42616

Some endpoints in vulnerability-lookup that modified application state (e.g. changing database entries, user data, configurations, or other privile…

Mitigation only
Fix from $1,950 2025-12-08
Halo MEDIUM 6.5
CVE-2025-14117

A vulnerability has been found in fit2cloud Halo 2.21.10. Impacted is an unknown function. The manipulation leads to cross-site request forgery. The …

No fix yet
Fix from $1,600 2025-12-06
Unclassified HIGH 8.8
CVE-2025-12879

The User Generator and Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.2.2. This is due t…

Mitigation only
Fix from $1,950 2025-12-05
Unclassified MEDIUM 6.1
CVE-2025-13621

The dream gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing …

Mitigation only
Fix from $1,600 2025-12-05
Bread \& Butter HIGH 8.8
CVE-2025-12189

The Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents plugin for WordPress is vulnerable to Cross-Site…

Fix: after 7.11.1374
Fix from $1,950 2025-12-05
Diskstation Manager CRITICAL 9.6
CVE-2024-45538

Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Sy…

Fix: 3.1.4-23079 / 7.2.1-69057-2+
Fix from $2,300 2025-12-04
Romm HIGH 7.6
CVE-2025-65027

RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. RomM contains multiple…

Fix: 4.4.1+
Fix from $1,950 2025-12-03
Opinio HIGH 8.8
CVE-2025-13871

Cross-Site Request Forgery (CSRF) in the resource-management feature of ObjectPlanet Opinio 7.26 rev12562 allows to upload files on behalf of th…

Mitigation only
Fix from $1,950 2025-12-02
Unclassified MEDIUM 6.5
CVE-2025-13606

The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i…

Mitigation only
Fix from $1,600 2025-12-02