Vulnerability index

Browse CVEs

7,378 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Mybb MEDIUM 6.8
CVE-2008-0788

Multiple cross-site request forgery (CSRF) vulnerabilities in MyBB 1.2.11 and earlier allow remote attackers to (1) hijack the authentication of mode…

Fix: after 1.2.11
Fix from $1,600 2008-02-15
Permalinks Migration Plugin MEDIUM 6.8
CVE-2008-0508

Cross-site request forgery (CSRF) vulnerability in deans_permalinks_migration.php in the Dean's Permalinks Migration 1.0 plugin for WordPress allows …

Patch available
Fix from $1,600 2008-01-31
Rt107e HIGH 7.5
CVE-2008-0524

Cross-site request forgery (CSRF) vulnerability in the management interface in multiple Yamaha RT series routers allows remote attackers to change pa…

Mitigation only
Fix from $1,950 2008-01-31
Wrt54gl HIGH 9.3
CVE-2008-0228

Cross-site request forgery (CSRF) vulnerability in apply.cgi in the Linksys WRT54GL Wireless-G Broadband Router with firmware 4.30.9 allows remote at…

Mitigation only
Fix from $1,950 2008-01-10
Joomla MEDIUM 6.8
CVE-2007-6642

Multiple cross-site request forgery (CSRF) vulnerabilities in Joomla! before 1.5 RC4 allow remote attackers to (1) add a Super Admin, (2) upload an e…

Mitigation only
Fix from $1,600 2008-01-04
Fusion News MEDIUM 5.0
CVE-2007-6300

Cross-site request forgery (CSRF) vulnerability in Fusion News 3.9.0 allows remote attackers to perform unauthorized actions via unspecified vectors.

Mitigation only
Fix from $1,600 2007-12-10
Vigilecms MEDIUM 6.8
CVE-2007-6087

Cross-site request forgery (CSRF) vulnerability in index.php in VigileCMS 1.4 allows remote attackers to change the admin password via certain parame…

No fix yet
Fix from $1,600 2007-11-22
Skalinks MEDIUM 6.8
CVE-2007-5917

Cross-site request forgery (CSRF) vulnerability in admin/admin_account.php in Skalinks 1.5 and earlier allows remote attackers to add arbitrary privi…

Mitigation only
Fix from $1,600 2007-11-10
Ms Topsites MEDIUM 6.0
CVE-2007-5918

Cross-site request forgery (CSRF) vulnerability in edit.php in the MS TopSites add-on for PHP-Nuke does not verify that the uname parameter matches t…

Mitigation only
Fix from $1,600 2007-11-10
Django MEDIUM 6.8
CVE-2007-5828

Cross-site request forgery (CSRF) vulnerability in the admin panel in Django 0.96 allows remote attackers to change passwords of arbitrary users via …

Mitigation only
Fix from $1,600 2007-11-05
Sblog HIGH 7.6
CVE-2007-5818

Cross-site request forgery (CSRF) vulnerability in blocks_edit_do.php in sBlog 0.7.3 Beta allows remote attackers to change arbitrary blocks as admin…

Mitigation only
Fix from $1,950 2007-11-05
Feedsmith MEDIUM 6.4
CVE-2007-5229

Cross-site request forgery (CSRF) vulnerability in the FeedBurner FeedSmith 2.2 plugin for WordPress allows remote attackers to change settings and h…

Patch available
Fix from $1,600 2007-10-05
2100 Network Camera HIGH 9.3
CVE-2007-5213

Multiple cross-site request forgery (CSRF) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware 2.43 and earlier allow remote attackers…

Fix: after 2.42
Fix from $1,950 2007-10-04
Php Nuke MEDIUM 5.1
CVE-2007-5032

Cross-site request forgery (CSRF) vulnerability in admin.php in Francisco Burzi PHP-Nuke allows remote attackers to add administrative accounts via a…

Fix: after 5.2
Fix from $1,600 2007-09-21
Webapp MEDIUM 5.0
CVE-2007-3416

Multiple cross-site request forgery (CSRF) vulnerabilities in the administration of (1) polls, (2) profiles, (3) IP bans, and (4) forums in (a) web-a…

Fix: after 0.9.9.6
Fix from $1,600 2007-06-26
Squirrelmail MEDIUM 5.0
CVE-2007-2589

Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail 1.4.0 through 1.4.9a allows remote attackers to send e-mails from arbi…

Patch available
Fix from $1,600 2007-05-11
Php Nuke MEDIUM 6.8
CVE-2007-1520

The cross-site request forgery (CSRF) protection in PHP-Nuke 8.0 and earlier does not ensure the SERVER superglobal is an array before validating the…

Fix: after 8.0
Fix from $1,600 2007-03-20
Webapp MEDIUM 6.8
CVE-2007-1489

Unspecified vulnerability in web-app.org Web Automated Perl Portal (WebAPP) 0.9.9.4 to 0.9.9.6 allows remote attackers to obtain admin access by modi…

Patch available
Fix from $1,600 2007-03-16
Jboss HIGH 7.6
CVE-2007-1157

Cross-site request forgery (CSRF) vulnerability in jmx-console/HtmlAdaptor in JBoss allows remote attackers to perform privileged actions as administ…

Mitigation only
Fix from $1,950 2007-03-02
Mkportal MEDIUM 5.8
CVE-2006-6741

Cross-site request forgery (CSRF) vulnerability in urlobox in MKPortal allows remote attackers to delete arbitrary messages as an administrator via a…

Mitigation only
Fix from $1,600 2006-12-26
Atmail Webmail HIGH 7.5
CVE-2006-6701

Cross-site request forgery (CSRF) vulnerability in util.pl in @Mail WebMail 4.51, and util.php in 5.x before 5.03, allows remote attackers to modify …

Mitigation only
Fix from $1,950 2006-12-23
Terastation Hd Htgl Firmware HIGH 7.6
CVE-2006-5175

Cross-site request forgery (CSRF) vulnerability in the administrative interface for the TeraStation HD-HTGL firmware 2.05 beta 1 and earlier allows r…

Fix: 2.08+
Fix from $1,950 2006-10-10
Ubb.threads MEDIUM 6.5
CVE-2005-2059

Multiple cross-site request forgery (CSRF) vulnerabilities in (1) addaddress.php, (2) toggleignore.php, (3) removeignore.php, and (4) removeaddress.p…

Fix: after 6.5.1.1
Fix from $1,600 2005-06-29
Help Center Live MEDIUM 6.5
CVE-2005-1674

Cross-Site Request Forgery (CSRF) vulnerability in Help Center Live allows remote attackers to perform actions as the administrator via a link or IMG…

Patch available
Fix from $1,600 2005-05-19
Php Nuke HIGH 8.8
CVE-2004-1842

Cross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administrative privileges via an img ta…

Fix: after 7.1
Fix from $1,950 2004-12-31
Fusetalk MEDIUM 6.5
CVE-2004-1995

Cross-Site Request Forgery (CSRF) vulnerability in FuseTalk 2.0 allows remote attackers to create arbitrary accounts via a link to adduser.cfm.

No fix yet
Fix from $1,600 2004-12-31
Fusion News HIGH 8.8
CVE-2004-1703

Fusion News 3.6.1 allows remote attackers to add user accounts, if the administrator is logged in, via a comment that contains an img bbcode tag that…

No fix yet
Fix from $1,950 2004-07-30
Openbb HIGH 8.8
CVE-2004-1967

Cross-site request forgery (CSRF) vulnerabilities in (1) cp_forums.php, (2) cp_usergroup.php, (3) cp_ipbans.php, (4) myhome.php, (5) post.php, or (6)…

No fix yet
Fix from $1,950 2004-04-25