Vulnerability index

Browse CVEs

7,366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Unclassified MEDIUM 6.1
CVE-2025-12401

The Label Plugins plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5. This is due to missing …

Mitigation only
Fix from $1,600 2025-11-04
Bard MEDIUM 5.4
CVE-2025-64368

Cross-Site Request Forgery (CSRF) vulnerability in Mikado-Themes Bard bardwp allows Cross Site Request Forgery.This issue affects Bard: from n/a thro…

Fix: 1.7+
Fix from $1,600 2025-10-31
Nagios Xi MEDIUM 5.4
CVE-2023-53688

Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) and cross-site request forgery (CSRF) via the Hypermap Replay compone…

Fix: 5.11.3+
Fix from $1,600 2025-10-30
Unclassified MEDIUM 5.1
CVE-2025-10317

Quick.Cart is vulnerable to Cross-Site Request Forgery in product creation functionality. Malicious attacker can craft special website, which when vi…

Mitigation only
Fix from $1,600 2025-10-30
Unclassified HIGH 8.6
CVE-2025-62797

FluxCP is a web-based Control Panel for rAthena servers written in PHP. A critical Cross-Site Request Forgery (CSRF) vulnerability exists in the Flux…

Patch available
Fix from $1,950 2025-10-29
Blu Ic2 Firmware HIGH 8.8
CVE-2025-12479

Systemic Lack of Cross-Site Request Forgery (CSRF) Token Implementation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .

Fix: 1.20+
Fix from $1,950 2025-10-29
Publish To Bitbucket MEDIUM 5.4
CVE-2025-64149

A cross-site request forgery (CSRF) vulnerability in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers to connect to an attacker-s…

Fix: after 0.4
Fix from $1,600 2025-10-29
Extensible Choice Parameter MEDIUM 5.4
CVE-2025-64133

A cross-site request forgery (CSRF) vulnerability in Jenkins Extensible Choice Parameter Plugin 239.v5f5c278708cf and earlier allows attackers to exe…

Fix: after 239.v5f5c278708cf
Fix from $1,600 2025-10-29
Unclassified HIGH 7.1
CVE-2025-60075

Cross-Site Request Forgery (CSRF) vulnerability in Allegro Marketing hpb seo plugin for WordPress hpbseo allows Reflected XSS.This issue affects hpb …

Mitigation only
Fix from $1,950 2025-10-29
Unclassified MEDIUM 5.3
CVE-2025-57931

Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Popup box ays-popup-box allows Cross Site Request Forgery.This issue affects Popup box: fr…

Mitigation only
Fix from $1,600 2025-10-29
Unclassified MEDIUM 5.4
CVE-2025-55758

Multiple CSRF attack vectors in JDownloads component 1.0.0-4.0.47 for Joomla were discovered.

Mitigation only
Fix from $1,600 2025-10-28
Digital Experience Platform MEDIUM 6.5
CVE-2025-62258

CSRF vulnerability in Headless API in Liferay Portal 7.4.0 through 7.4.3.107, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, …

Fix: 7.4.3.108+
Fix from $1,600 2025-10-27
Socet Gxp MEDIUM 6.1
CVE-2025-54969

An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service does not implement CSRF protections. An attacker who social…

Fix: 4.6.0.2+
Fix from $1,600 2025-10-27
Unclassified HIGH 7.0
CVE-2025-34133

Wimi Teamwork versions prior to 7.38.17 contains a cross-site request forgery (CSRF) vulnerability in its API. The API accepts any authenticated requ…

Mitigation only
Fix from $1,950 2025-10-27
Idonate MEDIUM 5.4
CVE-2025-11154

The IDonate WordPress plugin before 2.1.13 does not have authorisation and CSRF when deleting users via an action handler, allowing unauthenticated …

Fix: 2.1.13+
Fix from $1,600 2025-10-27
Unclassified HIGH 7.1
CVE-2025-62986

Cross-Site Request Forgery (CSRF) vulnerability in FanBridge FanBridge signup fanbridge-signup allows Stored XSS.This issue affects FanBridge signup:…

Mitigation only
Fix from $1,950 2025-10-27
Unclassified HIGH 7.1
CVE-2025-62957

Cross-Site Request Forgery (CSRF) vulnerability in NikanWP NikanWP WooCommerce Reporting wc-reports-lite allows Stored XSS.This issue affects NikanWP…

Mitigation only
Fix from $1,950 2025-10-27
Unclassified HIGH 7.1
CVE-2025-62962

Cross-Site Request Forgery (CSRF) vulnerability in Andrea Landonio CloudSearch cloud-search allows Stored XSS.This issue affects CloudSearch: from n/…

Mitigation only
Fix from $1,950 2025-10-27
Unclassified HIGH 7.1
CVE-2025-62956

Cross-Site Request Forgery (CSRF) vulnerability in iseremet Reloadly reloadly-topup-widget allows Stored XSS.This issue affects Reloadly: from n/a th…

Mitigation only
Fix from $1,950 2025-10-27
Unclassified HIGH 7.1
CVE-2025-62945

Cross-Site Request Forgery (CSRF) vulnerability in Eduard Pinuaga Linares Did Prestashop Display did-prestashop-display allows Stored XSS.This issue …

Mitigation only
Fix from $1,950 2025-10-27
Unclassified HIGH 7.1
CVE-2025-62933

Cross-Site Request Forgery (CSRF) vulnerability in Prakash Awesome Testimonials awesome-testimonials allows Stored XSS.This issue affects Awesome Tes…

Mitigation only
Fix from $1,950 2025-10-27
Unclassified HIGH 7.1
CVE-2025-62934

Cross-Site Request Forgery (CSRF) vulnerability in Mejar WP Business Hours wp-business-hours allows Stored XSS.This issue affects WP Business Hours: …

Mitigation only
Fix from $1,950 2025-10-27
Unclassified HIGH 7.1
CVE-2025-62896

Cross-Site Request Forgery (CSRF) vulnerability in digitaldonkey Multilang Contact Form multilang-contact-form allows Stored XSS.This issue affects M…

Mitigation only
Fix from $1,950 2025-10-27
Unclassified HIGH 7.1
CVE-2025-62886

Cross-Site Request Forgery (CSRF) vulnerability in wpdevart Pricing Table builder wpdevart-pricing-table allows Stored XSS.This issue affects Pricing…

Mitigation only
Fix from $1,950 2025-10-27
Blu Ic2 Firmware HIGH 8.8
CVE-2025-12221

Busybox 1.31.1 - Multiple Known Vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

Fix: 1.20+
Fix from $1,950 2025-10-25
Unclassified HIGH 8.8
CVE-2025-12095

The Simple Registration for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.8.…

Mitigation only
Fix from $1,950 2025-10-25
Unclassified HIGH 8.8
CVE-2025-12028

The IndieAuth plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.4. This is due to missing no…

Mitigation only
Fix from $1,950 2025-10-24
Keeneticos MEDIUM 5.3
CVE-2025-56009

Cross site request forgery (CSRF) vulnerability in KeeneticOS before 4.3 at "/rci" API endpoint allows attackers to take over the device via adding a…

Fix: 4.3+
Fix from $1,600 2025-10-23
Unclassified HIGH 7.1
CVE-2025-62005

Cross-Site Request Forgery (CSRF) vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships allows Cross Site Request Forger…

Mitigation only
Fix from $1,950 2025-10-22
Unclassified HIGH 7.1
CVE-2025-60168

Cross-Site Request Forgery (CSRF) vulnerability in integrationshotelrunner HotelRunner Booking Widget hotelrunner allows Stored XSS.This issue affect…

Mitigation only
Fix from $1,950 2025-10-22