Vulnerability index

Browse CVEs

7,366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Saleserp HIGH 8.8
CVE-2025-13177

A vulnerability was detected in Bdtask/CodeCanyon SalesERP up to 20250728. This affects an unknown part. The manipulation results in cross-site reque…

Fix: after 2025-10-16
Fix from $1,950 2025-11-14
Mattermost Mobile MEDIUM 6.5
CVE-2025-59480

Mattermost Mobile Apps versions <=2.32.0 fail to verify that SSO redirect tokens originate from the trusted server, which allows a malicious Mattermo…

Fix: 2.33.0+
Fix from $1,600 2025-11-13
Simple E Banking System MEDIUM 6.5
CVE-2025-13119

A flaw has been found in Fabian Ros/SourceCodester Simple E-Banking System 1.0. This affects an unknown part. This manipulation causes cross-site req…

No fix yet
Fix from $1,600 2025-11-13
Wp Plugin Manager MEDIUM 6.5
CVE-2025-64271

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes WP Plugin Manager wp-plugin-manager allows Cross Site Request Forgery.This issue affects…

Fix: 1.4.8+
Fix from $1,600 2025-11-13
Unclassified MEDIUM 6.5
CVE-2025-64262

Cross-Site Request Forgery (CSRF) vulnerability in ramon fincken Auto Prune Posts auto-prune-posts allows Cross Site Request Forgery.This issue affec…

Mitigation only
Fix from $1,600 2025-11-13
Simple Faucet Script HIGH 8.8
CVE-2025-57310

A Cross-Site Request Forgery (CSRF) vulnerability in Salmen2/Simple-Faucet-Script v1.07 via crafted POST request to admin.php?p=ads&c=1 allowing atta…

No fix yet
Fix from $1,950 2025-11-12
Xxl Api MEDIUM 6.5
CVE-2025-60645

A Cross-Site Request Forgery (CSRF) in xxl-api v1.3.0 allows attackers to arbitrarily add users to the management module via a crafted GET request.

Fix: after 1.3.0
Fix from $1,600 2025-11-12
Unclassified MEDIUM 6.1
CVE-2025-12589

The WP-Walla plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in all versions up to, and including, 0.…

Mitigation only
Fix from $1,600 2025-11-11
Unclassified MEDIUM 6.1
CVE-2025-12590

The YSlider plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in all versions up to, and including, 1.1…

Mitigation only
Fix from $1,600 2025-11-11
Client Database Management System HIGH 7.1
CVE-2025-63711

A Cross-Site Request Forgery (CSRF) vulnerability in the SourceCodester Client Database Management System 1.0 allows an attacker to cause an authenti…

No fix yet
Fix from $1,950 2025-11-10
Web Based Pharmacy Product Management System HIGH 8.8
CVE-2025-63712

Cross-Site Request Forgery (CSRF) in SourceCodester Product Expiry Management System. The User Management module (delete-user.php) allows remote atta…

No fix yet
Fix from $1,950 2025-11-10
Simple Public Chat Room MEDIUM 6.5
CVE-2025-63710

The send_message.php endpoint in SourceCodester Simple Public Chat Room 1.0 is vulnerable to Cross-Site Request Forgery (CSRF). The application does …

No fix yet
Fix from $1,600 2025-11-10
Pet Grooming Management Software MEDIUM 6.5
CVE-2025-63717

The change password functionality at /pet_grooming/admin/change_pass.php in SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cros…

No fix yet
Fix from $1,600 2025-11-07
Leads Manager Tool MEDIUM 6.5
CVE-2025-63716

The SourceCodester Leads Manager Tool v1.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow unauthorized state-changing operatio…

No fix yet
Fix from $1,600 2025-11-07
Qulog Center HIGH 8.8
CVE-2025-58469

A cross-site request forgery (CSRF) vulnerability has been reported to affect QuLog Center. The remote attackers can then exploit the vulnerability t…

Fix: 1.8.2.923+
Fix from $1,950 2025-11-07
Unclassified HIGH 7.1
CVE-2025-53316

Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel WP GDPR Cookie Consent wp-gdpr-cookie-consent allows Stored XSS.This issue affects…

Mitigation only
Fix from $1,950 2025-11-06
Unclassified HIGH 7.1
CVE-2025-48077

Cross-Site Request Forgery (CSRF) vulnerability in nitinmaurya12 Block Country block-country allows Stored XSS.This issue affects Block Country: from…

Mitigation only
Fix from $1,950 2025-11-06
Unclassified HIGH 7.1
CVE-2025-48078

Cross-Site Request Forgery (CSRF) vulnerability in Norbert Slick Google Map slick-google-map allows Stored XSS.This issue affects Slick Google Map: f…

Mitigation only
Fix from $1,950 2025-11-06
Unclassified HIGH 7.1
CVE-2025-48083

Cross-Site Request Forgery (CSRF) vulnerability in andriassundskard wpNamedUsers wpnamedusers allows Stored XSS.This issue affects wpNamedUsers: from…

Mitigation only
Fix from $1,950 2025-11-06
Unclassified HIGH 7.1
CVE-2025-48085

Cross-Site Request Forgery (CSRF) vulnerability in ZIPANG Simple Stripe simple-stripe allows Stored XSS.This issue affects Simple Stripe: from n/a th…

Mitigation only
Fix from $1,950 2025-11-06
Unclassified MEDIUM 6.1
CVE-2025-12456

The Centangle-Team plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missi…

Mitigation only
Fix from $1,600 2025-11-04
Unclassified MEDIUM 6.1
CVE-2025-12452

The Visit Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validati…

Mitigation only
Fix from $1,600 2025-11-04
Unclassified MEDIUM 6.1
CVE-2025-12412

The Top Bar Notification plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.12. This is due to …

Mitigation only
Fix from $1,600 2025-11-04
Unclassified MEDIUM 5.4
CVE-2025-12413

The Social Media WPCF7 Stop Words plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.3. This …

Mitigation only
Fix from $1,600 2025-11-04
Unclassified MEDIUM 6.1
CVE-2025-12415

The MapMap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing or inco…

Mitigation only
Fix from $1,600 2025-11-04
Unclassified MEDIUM 6.1
CVE-2025-12416

The Pagerank Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Site Request Forgery in all versions up to, and includ…

Mitigation only
Fix from $1,600 2025-11-04
Unclassified MEDIUM 6.1
CVE-2025-12400

The LMB^Box Smileys plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2. This is due to missin…

Mitigation only
Fix from $1,600 2025-11-04
Unclassified MEDIUM 6.1
CVE-2025-12402

The LinkedIn Resume plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.00. This is due to missi…

Mitigation only
Fix from $1,600 2025-11-04
Unclassified MEDIUM 6.1
CVE-2025-12403

The Associados Amazon Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.8. This is due …

Mitigation only
Fix from $1,600 2025-11-04
Unclassified MEDIUM 6.1
CVE-2025-12410

The SH Contextual Help plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.1. This is due to m…

Mitigation only
Fix from $1,600 2025-11-04