Vulnerability index

Browse CVEs

7,366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Unclassified MEDIUM 6.5
CVE-2025-57902

Cross-Site Request Forgery (CSRF) vulnerability in Md Taufiqur Rahman RIS Version Switcher – Downgrade or Upgrade WP Versions Easily ris-version-swit…

Mitigation only
Fix from $1,600 2025-09-22
Unclassified MEDIUM 5.4
CVE-2025-53451

Cross-Site Request Forgery (CSRF) vulnerability in mihdan Mihdan: No External Links mihdan-no-external-links allows Cross Site Request Forgery.This i…

Mitigation only
Fix from $1,600 2025-09-22
Qloapps MEDIUM 5.3
CVE-2025-10759

A vulnerability was detected in Webkul QloApps up to 1.7.0. This affects an unknown function of the component CSRF Token Handler. Performing manipula…

Fix: after 1.7.0
Fix from $1,600 2025-09-21
Unclassified MEDIUM 6.1
CVE-2025-9882

The osTicket WP Bridge plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.2. This is due to m…

Mitigation only
Fix from $1,600 2025-09-20
Unclassified MEDIUM 6.1
CVE-2025-9883

The Browser Sniff plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3. This is due to missing …

Mitigation only
Fix from $1,600 2025-09-20
Unclassified HIGH 7.8
CVE-2025-50255

Cross Site Request Forgery (CSRF) vulnerability in Smartvista BackOffice SmartVista Suite 2.2.22 via crafted GET request.

Mitigation only
Fix from $1,950 2025-09-18
Unclassified MEDIUM 6.3
CVE-2025-54390

A Cross-Site Request Forgery (CSRF) vulnerability exists in the ResetPasswordRequest operation of Zimbra Collaboration (ZCS) when the zimbraFeatureRe…

Mitigation only
Fix from $1,600 2025-09-17
Unclassified MEDIUM 5.4
CVE-2025-10188

The The Hack Repair Guy's Plugin Archiver plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.…

Mitigation only
Fix from $1,600 2025-09-17
Student Result Management System HIGH 7.3
CVE-2025-56710

A Cross-Site Request Forgery (CSRF) vulnerability was identified in the Profile Page of the PHPGurukul Student-Result-Management-System-Using-PHP-V2.…

No fix yet
Fix from $1,950 2025-09-15
Unclassified MEDIUM 6.1
CVE-2025-9880

The Side Slide Responsive Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is du…

Mitigation only
Fix from $1,600 2025-09-12
Unclassified MEDIUM 6.1
CVE-2025-9881

The Ultimate Blogroll plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to mi…

Mitigation only
Fix from $1,600 2025-09-12
Unclassified MEDIUM 5.3
CVE-2025-9617

The Publish approval plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missi…

Mitigation only
Fix from $1,600 2025-09-11
Unclassified MEDIUM 6.1
CVE-2025-9620

The Seo Monster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.3.3. This is due to missing …

Mitigation only
Fix from $1,600 2025-09-11
Listmonk MEDIUM 6.1
CVE-2025-58430

listmonk is a standalone, self-hosted, newsletter and mailing list manager. In versions up to and including 1.1.0, every http request in addition to …

Fix: after 1.1.0
Fix from $1,600 2025-09-09
Dreamweaver HIGH 8.6
CVE-2025-54256

Dreamweaver Desktop versions 21.5 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in arbitrary code e…

Fix: 21.6+
Fix from $1,950 2025-09-09
Unclassified HIGH 7.1
CVE-2025-58991

Cross-Site Request Forgery (CSRF) vulnerability in Cristiano Zanca WooCommerce Booking Bundle Hours allows Stored XSS. This issue affects WooCommerce…

Mitigation only
Fix from $1,950 2025-09-09
Unclassified CRITICAL 9.6
CVE-2025-58997

Cross-Site Request Forgery (CSRF) vulnerability in Frenify Mow mow allows Code Injection.This issue affects Mow: from n/a through <= 4.10.

Mitigation only
Fix from $2,300 2025-09-09
Connect Secure HIGH 8.8
CVE-2025-55147

CSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neuro…

Fix: 22.7 / 22.8+
Fix from $1,950 2025-09-09
Connect Secure MEDIUM 5.4
CVE-2025-8711

CSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neuro…

Fix: 22.7 / 22.8+
Fix from $1,600 2025-09-09
Unclassified HIGH 7.1
CVE-2025-48104

Cross-Site Request Forgery (CSRF) vulnerability in ericzane Floating Window Music Player floating-window-music-player allows Stored XSS.This issue af…

Mitigation only
Fix from $1,950 2025-09-05
Unclassified MEDIUM 6.5
CVE-2025-58878

Cross-Site Request Forgery (CSRF) vulnerability in usamafarooq Woocommerce Gifts Product woo-gift-product allows Cross Site Request Forgery.This issu…

Mitigation only
Fix from $1,600 2025-09-05
Unclassified MEDIUM 6.5
CVE-2025-58869

Cross-Site Request Forgery (CSRF) vulnerability in Simasicher SimaCookie simasicher-dsgvo-cookie allows Stored XSS.This issue affects SimaCookie: fro…

Mitigation only
Fix from $1,600 2025-09-05
Unclassified HIGH 7.1
CVE-2025-58859

Cross-Site Request Forgery (CSRF) vulnerability in David Merinas Add to Feedly add-to-feedly allows Stored XSS.This issue affects Add to Feedly: from…

Mitigation only
Fix from $1,950 2025-09-05
Unclassified HIGH 7.1
CVE-2025-58860

Cross-Site Request Forgery (CSRF) vulnerability in KaizenCoders Enable Latex enable-latex allows Stored XSS.This issue affects Enable Latex: from n/a…

Mitigation only
Fix from $1,950 2025-09-05
Unclassified HIGH 7.1
CVE-2025-58861

Cross-Site Request Forgery (CSRF) vulnerability in WP Corner Quick Event Calendar quick-event-calendar allows Stored XSS.This issue affects Quick Eve…

Mitigation only
Fix from $1,950 2025-09-05
Unclassified MEDIUM 6.5
CVE-2025-58856

Cross-Site Request Forgery (CSRF) vulnerability in ablancodev Woocommerce Notify Updated Product woocommerce-notify-updated-product allows Stored XSS…

Mitigation only
Fix from $1,600 2025-09-05
Unclassified HIGH 7.1
CVE-2025-58849

Cross-Site Request Forgery (CSRF) vulnerability in Deepak S Hide Real Download Path hide-real-download-path allows Stored XSS.This issue affects Hide…

Mitigation only
Fix from $1,950 2025-09-05
Unclassified HIGH 7.1
CVE-2025-58852

Cross-Site Request Forgery (CSRF) vulnerability in Mark O'Donnell MSTW League Manager mstw-league-manager allows Stored XSS.This issue affects MSTW L…

Mitigation only
Fix from $1,950 2025-09-05
Unclassified HIGH 7.1
CVE-2025-58853

Cross-Site Request Forgery (CSRF) vulnerability in OTWthemes Popping Sidebars and Widgets Light popping-sidebars-and-widgets-light allows Reflected X…

Mitigation only
Fix from $1,950 2025-09-05
Unclassified HIGH 7.1
CVE-2025-58854

Cross-Site Request Forgery (CSRF) vulnerability in Samer Bechara Ultimate AJAX Login ultimate-ajax-login allows Reflected XSS.This issue affects Ulti…

Mitigation only
Fix from $1,950 2025-09-05