Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Pyforum MEDIUM 6.8
CVE-2009-4407

Multiple cross-site request forgery (CSRF) vulnerabilities in PyForum 1.0.3 and possibly earlier versions, and possibly zForum, allow remote attacker…

Fix: after 1.0.3
Fix from $1,600 2009-12-23
Sql Ledger MEDIUM 6.8
CVE-2009-3580

Cross-site request forgery (CSRF) vulnerability in am.pl in SQL-Ledger 2.8.24 allows remote attackers to hijack the authentication of arbitrary users…

Mitigation only
Fix from $1,600 2009-12-23
Ez Poll Hoster MEDIUM 6.8
CVE-2009-4385

Multiple cross-site request forgery (CSRF) vulnerabilities in Scriptsez.net Ez Poll Hoster (EPH) allow remote attackers to (1) hijack the authenticat…

No fix yet
Fix from $1,600 2009-12-22
Link Up Gold MEDIUM 6.8
CVE-2009-4349

Cross-site request forgery (CSRF) vulnerability in administration/administrators.php in Link Up Gold 5.0 allows remote attackers to hijack the authen…

No fix yet
Fix from $1,600 2009-12-17
Moodle MEDIUM 6.8
CVE-2009-4297

Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allow remote attackers to hijack the auth…

Patch available
Fix from $1,600 2009-12-16
Cutenews MEDIUM 6.8
CVE-2009-4173

Cross-site request forgery (CSRF) vulnerability in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote attackers to hijack the authenti…

No fix yet
Fix from $1,600 2009-12-02
Quick.cart MEDIUM 6.8
CVE-2009-4120

Multiple cross-site request forgery (CSRF) vulnerabilities in Quick.Cart 3.4 allow remote attackers to hijack the authentication of the administrator…

No fix yet
Fix from $1,600 2009-12-01
Quick.cms MEDIUM 6.8
CVE-2009-4121

Multiple cross-site request forgery (CSRF) vulnerabilities in Quick.CMS 2.4 and Quick.CMS.Lite 2.4 allow remote attackers to hijack the authenticatio…

No fix yet
Fix from $1,600 2009-12-01
Simplog MEDIUM 6.8
CVE-2009-4092EPSS 5%

Cross-site request forgery (CSRF) vulnerability in user.php in Simplog 0.9.3.2, and possibly earlier, allows remote attackers to hijack the authentic…

No fix yet
Fix from $1,600 2009-11-29
Webmail MEDIUM 6.8
CVE-2009-4076

Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and earlier allows remote attackers to hijack the authentication of unspec…

Fix: after 0.2.2
Fix from $1,600 2009-11-25
Webmail MEDIUM 6.8
CVE-2009-4077

Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and earlier allows remote attackers to hijack the authentication of unspec…

Fix: after 0.2.2
Fix from $1,600 2009-11-25
Redmine MEDIUM 6.8
CVE-2009-4079

Cross-site request forgery (CSRF) vulnerability in Redmine 0.8.5 and earlier allows remote attackers to hijack the authentication of users for reques…

Fix: after 0.8.5
Fix from $1,600 2009-11-25
Drupal MEDIUM 6.8
CVE-2009-4066

Multiple cross-site request forgery (CSRF) vulnerabilities in the "My Account" feature in PHPList Integration module 5 before 5.x-1.2 and 6 before 6.…

Patch available
Fix from $1,600 2009-11-24
Websphere Application Server MEDIUM 6.8
CVE-2009-2746

Cross-site request forgery (CSRF) vulnerability in the administrative console in the Security component in IBM WebSphere Application Server (WAS) 6.0…

Patch available
Fix from $1,600 2009-11-16
Safari MEDIUM 6.8
CVE-2009-2816

The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before 4.0.4 and Google Chrome before 3.0.195.33, inclu…

Fix: 3.0.195.33 / 4.0+
Fix from $1,600 2009-11-13
Userprotect MEDIUM 6.8
CVE-2009-3922

Multiple cross-site request forgery (CSRF) vulnerabilities in the User Protect module 5.x before 5.x-1.4 and 6.x before 6.x-1.3, a module for Drupal,…

Patch available
Fix from $1,600 2009-11-09
Simplenews Statistics MEDIUM 6.8
CVE-2009-3784

Open redirect vulnerability in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to redirect users to arbitrary …

Patch available
Fix from $1,600 2009-10-26
Simplenews Statistics MEDIUM 6.8
CVE-2009-3785

Multiple cross-site request forgery (CSRF) vulnerabilities in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allow remote attackers t…

Patch available
Fix from $1,600 2009-10-26
Xencenterweb HIGH 8.8
CVE-2009-3759

Multiple cross-site request forgery (CSRF) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers…

No fix yet
Fix from $1,950 2009-10-22
Shared Sign On MEDIUM 6.8
CVE-2009-3656

Cross-site request forgery (CSRF) vulnerability in Shared Sign-On 5.x and 6.x, a module for Drupal, allows remote attackers to hijack the authenticat…

Mitigation only
Fix from $1,600 2009-10-09
Cmsphp HIGH 8.8
CVE-2009-3520

Cross-site request forgery (CSRF) vulnerability in the Your_account module in CMSphp 0.21 allows remote attackers to hijack the authentication of adm…

No fix yet
Fix from $1,950 2009-10-01
Vtiger Crm MEDIUM 6.8
CVE-2009-3248

Cross-site request forgery (CSRF) vulnerability in the RSS module in vtiger CRM 5.0.4 allows remote attackers to hijack the authentication of Admin u…

No fix yet
Fix from $1,600 2009-09-18
Punbb MEDIUM 6.8
CVE-2008-7241

Cross-site request forgery (CSRF) vulnerability in PunBB before 1.2.17 allows remote attackers to hijack the authentication of unspecified users for …

Fix: after 1.2.16
Fix from $1,600 2009-09-17
Modxcms MEDIUM 6.8
CVE-2008-7243

Cross-site request forgery (CSRF) vulnerability in page 34 in MODx CMS 0.9.6.1 and 0.9.6.1p1 allows remote attackers to hijack the authentication of …

No fix yet
Fix from $1,600 2009-09-17
Runcms MEDIUM 6.8
CVE-2008-7221

Cross-site request forgery (CSRF) vulnerability in RunCMS 1.6.1 allows remote attackers to hijack the authentication of administrators for requests t…

Mitigation only
Fix from $1,600 2009-09-14
Virtuemart MEDIUM 6.8
CVE-2008-7204

Cross-site request forgery (CSRF) vulnerability in VirtueMart 1.0.13a and earlier allows remote attackers to hijack the authentication of administrat…

Fix: after 1.0.13
Fix from $1,600 2009-09-11
Mambo MEDIUM 6.8
CVE-2008-7214

Cross-site request forgery (CSRF) vulnerability in administrator/index2.php in MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote…

Fix: after 4.6.3
Fix from $1,600 2009-09-11
P 330w Router HIGH 9.3
CVE-2007-6730

Multiple cross-site request forgery (CSRF) vulnerabilities in the web management interface in the ZyXEL P-330W router allow remote attackers to hijac…

No fix yet
Fix from $1,950 2009-09-10
Burning Board MEDIUM 6.8
CVE-2008-7192

Cross-site request forgery (CSRF) vulnerability in index.php in WoltLab Burning Board (wBB) 3.0.1, and possibly other 3.x versions, allows remote att…

Mitigation only
Fix from $1,600 2009-09-09
Phpkit MEDIUM 6.8
CVE-2008-7193

PHPKIT 1.6.4 PL1 includes the session ID in the URL, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks by reading th…

Mitigation only
Fix from $1,600 2009-09-09