Vulnerability index

Browse CVEs

7,366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Unclassified HIGH 8.8
CVE-2025-60208

Cross-Site Request Forgery (CSRF) vulnerability in Tusko Trush Advanced Custom Fields : CPT Options Pages acf-cpt-options-pages allows Object Injecti…

Mitigation only
Fix from $1,950 2025-10-22
Unclassified HIGH 7.1
CVE-2025-60132

Cross-Site Request Forgery (CSRF) vulnerability in johnh10 Video Blogster Lite video-blogster-lite allows Stored XSS.This issue affects Video Blogste…

Mitigation only
Fix from $1,950 2025-10-22
Unclassified HIGH 7.5
CVE-2025-62771

Mercku M6a devices through 2.1.0 allow password changes via intranet CSRF attacks.

Mitigation only
Fix from $1,950 2025-10-22
Geode HIGH 8.8
CVE-2025-47410

Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could allow an attacker who has tricke…

Fix: 1.15.2+
Fix from $1,950 2025-10-18
Unclassified HIGH 8.8
CVE-2025-9890

The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0. This is due to missing o…

Mitigation only
Fix from $1,950 2025-10-18
Unclassified HIGH 7.3
CVE-2025-60535

A Cross-Site Request Forgery (CSRF) in the component /endpoints/currency/currency of Wallos v4.1.1 allows attackers to execute arbitrary operations v…

Mitigation only
Fix from $1,950 2025-10-14
Espocrm MEDIUM 5.4
CVE-2025-59428

EspoCRM is an open source customer relationship management application. In versions before 9.1.9, a vulnerability allows arbitrary user creation, inc…

Fix: 9.1.9+
Fix from $1,600 2025-10-14
1783 Natr Firmware MEDIUM 6.5
CVE-2025-7330

A cross-site request forgery security issue exists in the product and version listed. The vulnerability stems from missing CSRF checks on the impacte…

Fix: 1.007+
Fix from $1,600 2025-10-14
Unclassified MEDIUM 5.4
CVE-2025-42908

Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP NetWeaver Application Server for ABAP, an authenticated attacker could initiate trans…

Mitigation only
Fix from $1,600 2025-10-14
Emlog HIGH 8.8
CVE-2025-61930

Emlog is an open source website building system. Emlog Pro versions 2.5.19 and earlier are vulnerable to Cross‑Site Request Forgery (CSRF) on the pas…

Fix: after 2.5.19
Fix from $1,950 2025-10-10
macOS MEDIUM 5.5
CVE-2025-43296

A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26. An app may bypass Gatekeeper checks.

Fix: 26.0+
Fix from $1,600 2025-10-09
Unclassified MEDIUM 5.4
CVE-2025-11166

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to, and including…

Mitigation only
Fix from $1,600 2025-10-09
Sonoma D12 Firmware HIGH 8.0
CVE-2025-60956

Cross Site Request Forgery (CSRF) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attacke…

Mitigation only
Fix from $1,950 2025-10-06
Unclassified MEDIUM 5.3
CVE-2025-9892

The Restrict User Registration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is …

Mitigation only
Fix from $1,600 2025-10-03
Unclassified MEDIUM 6.1
CVE-2025-9884

The Mobile Site Redirect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to…

Mitigation only
Fix from $1,600 2025-10-03
Unclassified HIGH 8.8
CVE-2025-9213

The TextBuilder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 1.0.0 to 1.1.1. This is due to missing or incorrect nonc…

Mitigation only
Fix from $1,950 2025-10-03
Wegia HIGH 7.1
CVE-2025-61604

WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Cross-Site Request Forgery (CSRF) vu…

Fix: 3.5.0+
Fix from $1,950 2025-10-02
Lxd HIGH 8.8
CVE-2025-54286

Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and start container instances with…

Fix: 5.0.5 / 5.21.4+
Fix from $1,950 2025-10-02
Unclassified MEDIUM 6.1
CVE-2025-9946

The LockerPress – WordPress Security Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.…

Mitigation only
Fix from $1,600 2025-09-30
Unclassified HIGH 8.8
CVE-2025-7052

The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1.94. This is due to missing n…

Mitigation only
Fix from $1,950 2025-09-30
Enterprise Health HIGH 8.8
CVE-2025-35030

Medical Informatics Engineering Enterprise Health has a cross site request forgery vulnerability that allows an unauthenticated attacker to trick adm…

Mitigation only
Fix from $1,950 2025-09-29
Unclassified MEDIUM 6.1
CVE-2025-9899

The Trust Reviews plugin for Google, Tripadvisor, Yelp, Airbnb and other platforms plugin for WordPress is vulnerable to Cross-Site Request Forgery i…

Mitigation only
Fix from $1,600 2025-09-27
Pet Grooming Management Software MEDIUM 6.5
CVE-2025-11051

A vulnerability has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code. The manipulation lead…

No fix yet
Fix from $1,600 2025-09-27
Ninja Forms MEDIUM 5.4
CVE-2025-10498

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an…

Fix: 3.12.1+
Fix from $1,600 2025-09-27
Storage Ts4500 Library Firmware HIGH 8.8
CVE-2024-43192

IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and u…

Mitigation only
Fix from $1,950 2025-09-27
Unclassified HIGH 8.2
CVE-2025-59845

Apollo Studio Embeddable Explorer & Embeddable Sandbox are website embeddable software solutions from Apollo GraphQL. Prior to Apollo Sandbox version…

Mitigation only
Fix from $1,950 2025-09-26
Vvveb HIGH 8.8
CVE-2025-11029

A weakness has been identified in givanz Vvveb up to 1.0.7.2. This vulnerability affects unknown code. Executing manipulation can lead to cross-site …

Fix: after 1.0.7.2
Fix from $1,950 2025-09-26
Unclassified HIGH 7.1
CVE-2025-60171

Cross-Site Request Forgery (CSRF) vulnerability in yourplugins Conditional Cart Messages for WooCommerce – YourPlugins.com yourplugins-wc-conditional…

Mitigation only
Fix from $1,950 2025-09-26
Unclassified HIGH 7.1
CVE-2025-60172

Cross-Site Request Forgery (CSRF) vulnerability in flytedesk Flytedesk Digital flytedesk-digital allows Stored XSS.This issue affects Flytedesk Digit…

Mitigation only
Fix from $1,950 2025-09-26
Unclassified HIGH 7.1
CVE-2025-60173

Cross-Site Request Forgery (CSRF) vulnerability in Ashwani kumar GST for WooCommerce gst-for-woocommerce allows Stored XSS.This issue affects GST for…

Mitigation only
Fix from $1,950 2025-09-26