Vulnerability index

Browse CVEs

7,366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Unclassified HIGH 7.1
CVE-2025-49044

Cross-Site Request Forgery (CSRF) vulnerability in tosend.it Simple Poll simple-poll allows Stored XSS.This issue affects Simple Poll: from n/a throu…

Mitigation only
Fix from $1,950 2025-08-14
Commerce HIGH 8.1
CVE-2025-49555

Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a Cross-Site Request Forgery (C…

Fix: 1.3.3 / 2.4.4+
Fix from $1,950 2025-08-12
Unclassified HIGH 8.8
CVE-2020-9322

The /users endpoint in Statamic Core before 2.11.8 allows XSS to add an administrator user. This can be exploited via CSRF. Stored XSS can occur via …

Mitigation only
Fix from $1,950 2025-08-08
Unclassified MEDIUM 5.1
CVE-2025-7202

A Cross-Site Request Forgery (CSRF) in Elgato's Key Lights and related light products allows an attacker to host a malicious webpage that remotely co…

Mitigation only
Fix from $1,600 2025-08-06
Unclassified MEDIUM 5.3
CVE-2025-5988

A flaw was found in the Ansible aap-gateway. Cross-site request forgery (CSRF) origin checking is not done on requests from the gateway to external c…

Mitigation only
Fix from $1,600 2025-08-04
Devtools Integration HIGH 8.8
CVE-2025-54782EPSS 48%

Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remote Code Execution (RCE) vulne…

Fix: 0.2.1+
Fix from $1,950 2025-08-02
Cs Cart MEDIUM 6.5
CVE-2025-50847

Cross Site Request Forgery (CSRF) vulnerability in CS Cart 4.18.3, allows attackers to add products to a user's comparison list via a crafted HTTP re…

Mitigation only
Fix from $1,600 2025-07-31
Teamcity HIGH 8.8
CVE-2025-54536

In JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpoint

Fix: 2025.07+
Fix from $1,950 2025-07-28
Teamcity HIGH 7.5
CVE-2025-54529

In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration

Fix: 2025.07+
Fix from $1,950 2025-07-28
Teamcity HIGH 8.8
CVE-2025-54528

In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow

Fix: 2025.07+
Fix from $1,950 2025-07-28
Simplehelp HIGH 8.8
CVE-2025-36728

Cross-Site Request Forgery (CSRF) vulnerability in Simplehelp.This issue affects Simplehelp: before 5.5.11.

Fix: 5.5.11+
Fix from $1,950 2025-07-25
Unclassified MEDIUM 6.1
CVE-2025-7690

The Affiliate Plus plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.2. This is due to missi…

Mitigation only
Fix from $1,600 2025-07-24
Unclassified MEDIUM 6.5
CVE-2025-6214

The Omnishop plugin for WordPress is vulnerable to Cross-Site Request Forgery on its /users/delete REST route in all versions up to, and including, 1…

Mitigation only
Fix from $1,600 2025-07-23
Unclassified MEDIUM 6.1
CVE-2025-6054

The YANewsflash plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to missing …

Mitigation only
Fix from $1,600 2025-07-23
Unclassified MEDIUM 6.1
CVE-2025-7685

The Like & Share My Site plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2. This is due to m…

Mitigation only
Fix from $1,600 2025-07-22
Unclassified MEDIUM 6.1
CVE-2025-7687

The Latest Post Accordian Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is …

Mitigation only
Fix from $1,600 2025-07-22
Unclassified MEDIUM 6.1
CVE-2025-7369

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,…

Mitigation only
Fix from $1,600 2025-07-21
Unclassified MEDIUM 6.1
CVE-2025-7669

The Avishi WP PayPal Payment Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0. This …

Mitigation only
Fix from $1,600 2025-07-19
Studentmanage MEDIUM 6.5
CVE-2025-50586

StudentManage v1.0 was discovered to contain Cross-Site Request Forgery (CSRF).

No fix yet
Fix from $1,600 2025-07-18
Unclassified MEDIUM 6.1
CVE-2025-6053

The Zuppler Online Ordering plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.0. This is due…

Mitigation only
Fix from $1,600 2025-07-18
Unclassified MEDIUM 5.4
CVE-2025-54038

Cross-Site Request Forgery (CSRF) vulnerability in jetmonsters Restaurant Menu by MotoPress mp-restaurant-menu allows Cross Site Request Forgery.This…

Mitigation only
Fix from $1,600 2025-07-16
Unclassified MEDIUM 6.5
CVE-2025-54033

Cross-Site Request Forgery (CSRF) vulnerability in BlocksWP Theme Builder For Elementor theme-builder-for-elementor allows Cross Site Request Forgery…

Mitigation only
Fix from $1,600 2025-07-16
Unclassified MEDIUM 5.4
CVE-2025-54020

Cross-Site Request Forgery (CSRF) vulnerability in Erik AntiSpam for Contact Form 7 cf7-antispam allows Cross Site Request Forgery.This issue affects…

Mitigation only
Fix from $1,600 2025-07-16
Unclassified MEDIUM 6.5
CVE-2025-54022

Cross-Site Request Forgery (CSRF) vulnerability in Elliot Sowersby / RelyWP Coupon Affiliates woo-coupon-usage allows Cross Site Request Forgery.This…

Mitigation only
Fix from $1,600 2025-07-16
Unclassified CRITICAL 9.6
CVE-2025-54010

Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel FluentSnippets easy-code-manager allows Cross Site Request Forgery.This issue affe…

Mitigation only
Fix from $2,300 2025-07-16
Unclassified HIGH 7.1
CVE-2025-48153

Cross-Site Request Forgery (CSRF) vulnerability in Atakan Au Import CDN-Remote Images import-cdn-remote-images allows Stored XSS.This issue affects I…

Mitigation only
Fix from $1,950 2025-07-16
E Business Suite MEDIUM 5.4
CVE-2025-50090

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affe…

Fix: after 12.2.14
Fix from $1,600 2025-07-15
Rest Data Services MEDIUM 6.1
CVE-2025-30756

Vulnerability in Oracle REST Data Services (component: General). The supported version that is affected is 24.2.0. Easily exploitable vulnerability…

Patch available
Fix from $1,600 2025-07-15
Mes For Process Manufacturing MEDIUM 6.1
CVE-2025-30745

Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Device Integration). Supported versions tha…

Patch available
Fix from $1,600 2025-07-15
Istore MEDIUM 6.1
CVE-2025-30746

Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12…

Fix: after 12.2.14
Fix from $1,600 2025-07-15