Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Wikipad MEDIUM 6.8
CVE-2011-5311

Cross-site request forgery (CSRF) vulnerability in pages.php in Wikipad 1.6.0 allows remote attackers to hijack the authentication of administrators …

No fix yet
Fix from $1,600 2015-01-01
Cosmoshop MEDIUM 6.8
CVE-2011-5306

Cross-site request forgery (CSRF) vulnerability in cgi-bin/admin/setup_edit.cgi in CosmoShop ePRO 10.05.00 allows remote attackers to hijack the auth…

No fix yet
Fix from $1,600 2015-01-01
Phpdug MEDIUM 6.8
CVE-2011-5302

Cross-site request forgery (CSRF) vulnerability in adm/admin_edit.php in PHPDug 2.0.0 allows remote attackers to hijack the authentication of adminis…

No fix yet
Fix from $1,600 2015-01-01
Pommo Ardvark MEDIUM 6.8
CVE-2011-5300

Cross-site request forgery (CSRF) vulnerability in admin/setup/config/users.php in poMMo Aardvark PR16.1 allows remote attackers to hijack the authen…

No fix yet
Fix from $1,600 2015-01-01
Argyle Social MEDIUM 6.8
CVE-2011-5298

Multiple cross-site request forgery (CSRF) vulnerabilities in Argyle Social 2011-04-26 allow remote attackers to hijack the authentication of adminis…

No fix yet
Fix from $1,600 2015-01-01
Smoothwall MEDIUM 6.8
CVE-2014-9431

Multiple cross-site request forgery (CSRF) vulnerabilities in Smoothwall Express 3.1 and 3.0 SP3 allow remote attackers to hijack the authentication …

No fix yet
Fix from $1,600 2014-12-31
Doorkeeper MEDIUM 6.8
CVE-2014-8144

Cross-site request forgery (CSRF) vulnerability in doorkeeper before 1.4.1 allows remote attackers to hijack the authentication of unspecified victim…

Fix: after 1.4.0
Fix from $1,600 2014-12-31
Smoothwall MEDIUM 6.8
CVE-2011-5284

Cross-site request forgery (CSRF) vulnerability in the web management interface in httpd/cgi-bin/shutdown.cgi in Smoothwall Express 3.1 and 3.0 SP3 a…

Fix: after 3.1
Fix from $1,600 2014-12-31
Wp Limit Posts Automatically MEDIUM 6.8
CVE-2014-9401

Cross-site request forgery (CSRF) vulnerability in the WP Limit Posts Automatically plugin 0.7 and earlier for WordPress allows remote attackers to h…

Fix: after 0.7
Fix from $1,600 2014-12-31
Wp Unique Article Header Image MEDIUM 6.8
CVE-2014-9400

Multiple cross-site request forgery (CSRF) vulnerabilities in the Wp Unique Article Header Image plugin 1.0 and earlier for WordPress allow remote at…

Fix: after 1.0
Fix from $1,600 2014-12-31
Tweetscribe MEDIUM 6.8
CVE-2014-9399

Cross-site request forgery (CSRF) vulnerability in the TweetScribe plugin 1.1 and earlier for WordPress allows remote attackers to hijack the authent…

Fix: after 1.1
Fix from $1,600 2014-12-31
Twitter Liveblog MEDIUM 6.8
CVE-2014-9398

Cross-site request forgery (CSRF) vulnerability in the Twitter LiveBlog plugin 1.1.2 and earlier for WordPress allows remote attackers to hijack the …

Fix: after 1.1.2
Fix from $1,600 2014-12-31
Twimp Wp MEDIUM 6.8
CVE-2014-9397

Cross-site request forgery (CSRF) vulnerability in the twimp-wp plugin for WordPress allows remote attackers to hijack the authentication of administ…

Fix: after 0.1
Fix from $1,600 2014-12-31
Simpleflickr MEDIUM 6.8
CVE-2014-9396

Multiple cross-site request forgery (CSRF) vulnerabilities in the SimpleFlickr plugin 3.0.3 and earlier for WordPress allow remote attackers to hijac…

Fix: after 3.0.3
Fix from $1,600 2014-12-31
Simplelife MEDIUM 6.8
CVE-2014-9395

Multiple cross-site request forgery (CSRF) vulnerabilities in the Simplelife plugin 1.2 and earlier for WordPress allow remote attackers to hijack th…

Fix: after 1.2
Fix from $1,600 2014-12-31
Pwgrandom MEDIUM 6.8
CVE-2014-9394

Multiple cross-site request forgery (CSRF) vulnerabilities in the PWGRandom plugin 1.11 and earlier for WordPress allow remote attackers to hijack th…

Fix: after 1.11
Fix from $1,600 2014-12-31
Post To Twitter MEDIUM 6.8
CVE-2014-9393

Multiple cross-site request forgery (CSRF) vulnerabilities in the Post to Twitter plugin 0.7 and earlier for WordPress allow remote attackers to hija…

Fix: after 0.7
Fix from $1,600 2014-12-31
Gslideshow MEDIUM 6.8
CVE-2014-9391

Multiple cross-site request forgery (CSRF) vulnerabilities in the gSlideShow plugin 0.1 and earlier for WordPress allow remote attackers to hijack th…

Fix: after 0.1
Fix from $1,600 2014-12-31
Pictobrowser MEDIUM 6.8
CVE-2014-9392

Cross-site request forgery (CSRF) vulnerability in the PictoBrowser (pictobrowser-gallery) plugin 0.3.1 and earlier for WordPress allows remote attac…

Fix: after 0.3.1
Fix from $1,600 2014-12-31
Security Identity Manager MEDIUM 6.0
CVE-2014-6168

Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager 5.1 before 5.1.0.15 IF0056 allows remote authenticated users to hija…

Mitigation only
Fix from $1,600 2014-12-29
Ptk MEDIUM 6.8
CVE-2012-1415

Cross-site request forgery (CSRF) vulnerability in lib/logout.php in DFLabs PTK 1.0.5 and earlier allows remote attackers to hijack the authenticatio…

Fix: after 1.0.5
Fix from $1,600 2014-12-28
Syndeocms MEDIUM 6.8
CVE-2012-1203

Cross-site request forgery (CSRF) vulnerability in starnet/index.php in SyndeoCMS 3.0 and earlier allows remote attackers to hijack the authenticatio…

Fix: after 3.0.00
Fix from $1,600 2014-12-28
W3 Total Cache MEDIUM 6.8
CVE-2014-9414

The W3 Total Cache plugin before 0.9.4.1 for WordPress does not properly handle empty nonces, which allows remote attackers to conduct cross-site req…

Fix: after 0.9.4
Fix from $1,600 2014-12-24
Ip Ban MEDIUM 6.8
CVE-2014-9413

Multiple cross-site request forgery (CSRF) vulnerabilities in the IP Ban (simple-ip-ban) plugin 1.2.3 for WordPress allow remote attackers to hijack …

Patch available
Fix from $1,600 2014-12-24
Bird Feeder MEDIUM 6.8
CVE-2014-9334

Multiple cross-site request forgery (CSRF) vulnerabilities in the Bird Feeder plugin 1.2.3 for WordPress allow remote attackers to hijack the authent…

No fix yet
Fix from $1,600 2014-12-24
Websphere Service Registry And Repository MEDIUM 6.0
CVE-2014-6187

Multiple cross-site request forgery (CSRF) vulnerabilities in IBM WebSphere Service Registry and Repository (WSRR) 6.3.x before 6.3.0.5, 7.0.x before…

Mitigation only
Fix from $1,600 2014-12-24
Access Manager MEDIUM 6.8
CVE-2014-5217

Cross-site request forgery (CSRF) vulnerability in nps/servlet/webacc in the Administration Console server in NetIQ Access Manager (NAM) 4.x before 4…

No fix yet
Fix from $1,600 2014-12-23
Revive Adserver MEDIUM 6.8
CVE-2014-9407

Multiple cross-site request forgery (CSRF) vulnerabilities in Revive Adserver before 3.0.5 allow remote attackers to hijack the authentication of adm…

Fix: after 3.0.4
Fix from $1,600 2014-12-19
Twitterdash MEDIUM 6.8
CVE-2014-9368

Cross-site request forgery (CSRF) vulnerability in the twitterDash plugin 2.1 and earlier for WordPress allows remote attackers to hijack the authent…

Fix: after 2.1
Fix from $1,600 2014-12-19
Yurl Retwitt MEDIUM 6.8
CVE-2014-9341

Multiple cross-site request forgery (CSRF) vulnerabilities in the yURL ReTwitt plugin 1.4 and earlier for WordPress allow remote attackers to hijack …

No fix yet
Fix from $1,600 2014-12-19