Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Responsive Coming Soon Page HIGH 8.8
CVE-2018-5658

An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. CSRF exists via wp-admin/admin.php.

No fix yet
Fix from $1,950 2018-01-13
Read And Understood HIGH 8.8
CVE-2018-5669

An issue was discovered in the read-and-understood plugin 2.1 for WordPress. CSRF exists via wp-admin/options-general.php.

No fix yet
Fix from $1,950 2018-01-13
Security Identity Manager HIGH 8.8
CVE-2016-0335

Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SI…

Patch available
Fix from $1,950 2018-01-12
Lm53q1 Firmware HIGH 8.8
CVE-2017-16886EPSS 7%

The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorize…

No fix yet
Fix from $1,950 2018-01-12
Srbtranslatin HIGH 8.8
CVE-2018-5368

The SrbTransLatin plugin 1.46 for WordPress has CSRF via an srbtranslatoptions action to wp-admin/options-general.php.

No fix yet
Fix from $1,950 2018-01-12
Wpglobus HIGH 8.8
CVE-2018-5361

The WPGlobus plugin 1.9.6 for WordPress has CSRF via wp-admin/options.php.

No fix yet
Fix from $1,950 2018-01-12
Family Connections Cms HIGH 8.8
CVE-2012-0699

Multiple cross-site request forgery (CSRF) vulnerabilities in Family Connections CMS (aka FCMS) 2.9 and earlier allow remote attackers to hijack the …

Fix: after 2.9.0
Fix from $1,950 2018-01-11
Asp.net Core MEDIUM 6.5
CVE-2018-0785

ASP.NET Core 1.0. 1.1, and 2.0 allow a cross site request forgery vulnerability due to the ASP.NET Core project templates, aka "ASP.NET Core Cross Si…

Patch available
Fix from $1,600 2018-01-10
Magento MEDIUM 6.5
CVE-2018-5301

Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have CSRF resulting in deletion of a customer address from an a…

Fix: 2.0.10 / 2.1.2+
Fix from $1,600 2018-01-08
Imageinject HIGH 8.8
CVE-2018-5285

The ImageInject plugin 1.15 for WordPress has CSRF via wp-admin/options-general.php.

No fix yet
Fix from $1,950 2018-01-08
Security Key Lifecycle Manager HIGH 8.8
CVE-2017-1672

IBM Tivoli Key Lifecycle Manager 2.6 and 2.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unaut…

Mitigation only
Fix from $1,950 2018-01-04
Advanced Real Estate Script MEDIUM 6.8
CVE-2018-5073

Online Ticket Booking has CSRF via admin/movieedit.php.

No fix yet
Fix from $1,600 2018-01-03
Pfsense HIGH 8.8
CVE-2017-1000479EPSS 33%

pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrary code, b…

Fix: 16.1.16+
Fix from $1,950 2018-01-03
phpMyAdmin HIGH 8.8
CVE-2017-1000499EPSS 8%

phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible t…

Fix: 4.7.7+
Fix from $1,950 2018-01-03
Vanilla Forums HIGH 8.0
CVE-2017-1000432

Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access

Fix: 2.1.5+
Fix from $1,950 2018-01-02
Muslim Matrimonial Script MEDIUM 6.8
CVE-2017-17982

PHP Scripts Mall Muslim Matrimonial Script has CSRF via admin/subadmin_edit.php.

No fix yet
Fix from $1,600 2017-12-30
Biometric Shift Employee Management System HIGH 8.8
CVE-2017-17990

Biometric Shift Employee Management System has CSRF via index.php in an edit_holiday action.

No fix yet
Fix from $1,950 2017-12-30
Jboss Fuse HIGH 8.8
CVE-2014-0120

Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary us…

Fix: after 1.2.2
Fix from $1,950 2017-12-29
Php Multivendor Ecommerce HIGH 8.8
CVE-2017-17960

PHP Scripts Mall PHP Multivendor Ecommerce has CSRF via admin/sellerupd.php.

No fix yet
Fix from $1,950 2017-12-28
Marketplace Digital Products Php HIGH 8.8
CVE-2017-17936

Vanguard Marketplace Digital Products PHP has CSRF via /search.

Fix: after 1.9
Fix from $1,950 2017-12-28
Single Theater Booking Script HIGH 8.8
CVE-2017-17939

PHP Scripts Mall Single Theater Booking has CSRF via admin/sitesettings.php.

No fix yet
Fix from $1,950 2017-12-28
Lynda Clone HIGH 8.8
CVE-2017-17903

FS Lynda Clone has CSRF via user/edit_profile, as demonstrated by adding content to the user panel.

No fix yet
Fix from $1,950 2017-12-27
Car Rental Script HIGH 8.8
CVE-2017-17905

PHP Scripts Mall Car Rental Script has CSRF via admin/sitesettings.php.

No fix yet
Fix from $1,950 2017-12-27
Responsive Realestate Script HIGH 8.8
CVE-2017-17908

PHP Scripts Mall Responsive Realestate Script has CSRF via admin/general.

No fix yet
Fix from $1,950 2017-12-27
Professional Service Script HIGH 8.8
CVE-2017-17930

PHP Scripts Mall Professional Service Script has CSRF via admin/general_settingupd.php, as demonstrated by modifying a setting in the user panel.

No fix yet
Fix from $1,950 2017-12-27
Readymade Video Sharing Script HIGH 8.8
CVE-2017-17891

Readymade Video Sharing Script has CSRF via user-profile-edit.php.

No fix yet
Fix from $1,950 2017-12-27
Basic Job Site Script HIGH 8.8
CVE-2017-17894

Readymade Job Site Script has CSRF via the /job URI.

No fix yet
Fix from $1,950 2017-12-27
Bus Booking Script MEDIUM 6.8
CVE-2017-17830

Bus Booking Script has CSRF via admin/new_master.php.

No fix yet
Fix from $1,600 2017-12-21
Piwigo HIGH 8.8
CVE-2017-17827

Piwigo 2.9.2 is vulnerable to Cross-Site Request Forgery via /admin.php?page=configuration&section=main or /admin.php?page=batch_manager&mode=unit. A…

Patch available
Fix from $1,950 2017-12-21
Cnpilot R190v Firmware HIGH 8.0
CVE-2017-5263

Versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware lack CSRF controls that can mitigate the effects of CSRF attacks, which are most typ…

Fix: after 4.3.2-r4
Fix from $1,950 2017-12-20