Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Yzmcms MEDIUM 6.8
CVE-2018-10223

An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add an admin account via /index.php/admin/admin_manage/add.html.

No fix yet
Fix from $1,600 2018-04-19
Yzmcms MEDIUM 6.8
CVE-2018-10224

An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add a tag via /index.php/admin/tag/add.html.

No fix yet
Fix from $1,600 2018-04-19
Tuzicms HIGH 8.8
CVE-2018-10185

An issue was discovered in TuziCMS v2.0.6. There is a CSRF vulnerability that can add an admin account, as demonstrated by a history.pushState call.

No fix yet
Fix from $1,950 2018-04-17
Uberforx HIGH 8.8
CVE-2018-10137

iScripts UberforX 2.2 has CSRF in the "manage_settings" section of the Admin Panel via the /cms?section=manage_settings&action=edit URI.

No fix yet
Fix from $1,950 2018-04-16
Xyhcms HIGH 8.8
CVE-2018-10127

An issue was discovered in XYHCMS 3.5. It has CSRF via an index.php?g=Manage&m=Rbac&a=addUser request, resulting in addition of an account with the a…

Mitigation only
Fix from $1,950 2018-04-16
Pbootcms HIGH 8.8
CVE-2018-10132

PbootCMS v0.9.8 has CSRF via an admin.php/Message/mod/id/19.html?backurl=/index.php request, resulting in PHP code injection in the recontent paramet…

No fix yet
Fix from $1,950 2018-04-16
Icms HIGH 8.8
CVE-2018-10117

An issue was discovered in idreamsoft iCMS V7.0.7. There is a CSRF vulnerability that can add an admin account via admincp.php?app=members&do=save&fr…

No fix yet
Fix from $1,950 2018-04-16
Debian Linux HIGH 8.8
CVE-2017-0362

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where the "Mark all pages visited" on the watchlist does not require a CSRF token.

Fix: 1.27.2 / 1.28.1+
Fix from $1,950 2018-04-13
Online Tutoring Script HIGH 8.8
CVE-2018-6934

CSRF exists in student/personal-info in PHP Scripts Mall Online Tutoring Script 2.0.3.

No fix yet
Fix from $1,950 2018-04-12
Dir 815 Firmware HIGH 8.8
CVE-2015-0151

Cross-site request forgery (CSRF) vulnerability in D-Link DIR-815 devices with firmware before 2.07.B01 allows remote attackers to hijack the authent…

Fix: 2.07.b01+
Fix from $1,950 2018-04-12
Eswap HIGH 8.8
CVE-2018-10048

iScripts eSwap v2.4 has CSRF via "registration_settings.php" in the Admin Panel.

No fix yet
Fix from $1,950 2018-04-11
Cms Made Simple HIGH 8.8
CVE-2018-10030

CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/siteprefs.php.

Fix: after 2.2.7
Fix from $1,950 2018-04-11
Cms Made Simple HIGH 8.8
CVE-2018-10031

CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/moduleinterface.php.

Fix: after 2.2.7
Fix from $1,950 2018-04-11
Icms HIGH 8.8
CVE-2018-9923

An issue was discovered in idreamsoft iCMS through 7.0.7. CSRF exists in admincp.php, as demonstrated by adding an article via an app=article&do=save…

Fix: after 7.0.7
Fix from $1,950 2018-04-10
Wuzhicms HIGH 8.8
CVE-2018-9926

An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add an admin account via index.php?m=core&f=power&v=add.

No fix yet
Fix from $1,950 2018-04-10
Wuzhicms HIGH 8.8
CVE-2018-9927

An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add a user account via index.php?m=member&f=index&v=add.

No fix yet
Fix from $1,950 2018-04-10
Kotti HIGH 8.8
CVE-2018-9856

Kotti before 1.3.2 and 2.x before 2.0.0b2 has CSRF in the local roles implementation, as demonstrated by triggering a permission change via a /admin-…

Fix: 1.3.2+
Fix from $1,950 2018-04-09
Brute Force Login Protection HIGH 8.8
CVE-2014-5034

Cross-site request forgery (CSRF) vulnerability in the Brute Force Login Protection module 1.3 for WordPress allows remote attackers to hijack the au…

No fix yet
Fix from $1,950 2018-04-06
Wp Security Audit Log HIGH 8.8
CVE-2014-5072

Cross-site request forgery (CSRF) vulnerability in WP Security Audit Log plugin before 1.2.5 for WordPress allows remote attackers to hijack the auth…

Fix: 1.2.5+
Fix from $1,950 2018-04-06
Vsphere HIGH 8.8
CVE-2018-1000153

A cross-site request forgery vulnerability exists in Jenkins vSphere Plugin 2.16 and older in Clone.java, CloudSelectorParameter.java, ConvertToTempl…

Fix: after 2.16
Fix from $1,950 2018-04-05
Auth0.js HIGH 8.8
CVE-2018-6874

CSRF exists in the Auth0 authentication service through 14591 if the Legacy Lock API flag is enabled.

Fix: after 8.12.1
Fix from $1,950 2018-04-04
Wolf Cms MEDIUM 6.5
CVE-2018-8814

Cross-site request forgery (CSRF) vulnerability in WolfCMS 0.8.3.1 allows remote attackers to hijack the authentication of users for requests that mo…

No fix yet
Fix from $1,600 2018-04-04
Network Security Manager HIGH 8.8
CVE-2017-3965

Cross-Site Request Forgery (CSRF) (aka Session Riding) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42…

Fix: 8.2.7.42.2+
Fix from $1,950 2018-04-04
Etcd HIGH 8.8
CVE-2018-1098

A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attacker can set up a website that tries to send a POST request to the etcd…

Fix: after 3.3.1
Fix from $1,950 2018-04-03
Z Blogphp HIGH 8.8
CVE-2018-8893

Z-BlogPHP 1.5.1 Zero has CSRF in plugin_edit.php, resulting in the ability to execute arbitrary PHP code.

Mitigation only
Fix from $1,950 2018-03-31
Frog Cms HIGH 8.8
CVE-2018-8908

An issue was discovered in /admin/?/user/add in Frog CMS 0.9.5. The application's add user functionality suffers from CSRF. A malicious user can craf…

No fix yet
Fix from $1,950 2018-03-31
Dedecms HIGH 8.8
CVE-2018-9134

file_manage_control.php in DedeCMS 5.7 has CSRF in an fmdo=rename action, as demonstrated by renaming an arbitrary file under uploads/userup to a .ph…

Mitigation only
Fix from $1,950 2018-03-30
Qradar Security Information And Event Manager HIGH 8.8
CVE-2015-2009

Cross-site request forgery (CSRF) vulnerability in the xmlrpc.cgi service in IBM QRadar SIEM 7.1 before MR2 Patch 11 Interim Fix 02 and 7.2.x before …

Fix: 7.2.5+
Fix from $1,950 2018-03-29
Quickapps Cms HIGH 8.8
CVE-2018-9108

CSRF in /admin/user/manage/add in QuickAppsCMS 2.0.0-beta2 allows an unauthorized remote attacker to create an account with admin privileges.

Mitigation only
Fix from $1,950 2018-03-28
Minicms HIGH 8.8
CVE-2018-9092

There is a CSRF vulnerability in mc-admin/conf.php in MiniCMS 1.10 that can change the administrator account password.

No fix yet
Fix from $1,950 2018-03-27