Vulnerability index

Browse CVEs

7,366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Unclassified HIGH 7.1
CVE-2025-49425

Cross-Site Request Forgery (CSRF) vulnerability in Adrian Hanft Konami Easter Egg konami-easter-egg allows Stored XSS.This issue affects Konami Easte…

Mitigation only
Fix from $1,950 2025-06-06
Calculated Fields Form HIGH 8.8
CVE-2025-49291

Cross-Site Request Forgery (CSRF) vulnerability in codepeople Calculated Fields Form calculated-fields-form allows Cross Site Request Forgery.This is…

Fix: 5.3.59+
Fix from $1,950 2025-06-06
Unclassified HIGH 7.4
CVE-2025-49237

Cross-Site Request Forgery (CSRF) vulnerability in POEditor POEditor poeditor allows Path Traversal.This issue affects POEditor: from n/a through <= …

Mitigation only
Fix from $1,950 2025-06-06
Unclassified MEDIUM 5.4
CVE-2025-49239

Cross-Site Request Forgery (CSRF) vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocommerce-delivery-notes allows Cr…

Mitigation only
Fix from $1,600 2025-06-06
Unclassified MEDIUM 5.4
CVE-2025-30986

Cross-Site Request Forgery (CSRF) vulnerability in _CreativeMedia_ Elite Video Player elite-video-player allows Cross Site Request Forgery.This issue…

Mitigation only
Fix from $1,600 2025-06-06
Unclassified HIGH 7.1
CVE-2025-30995

Cross-Site Request Forgery (CSRF) vulnerability in OTWthemes Widgetize Pages Light widgetize-pages-light allows Stored XSS.This issue affects Widgeti…

Mitigation only
Fix from $1,950 2025-06-06
Unclassified MEDIUM 5.4
CVE-2025-30968

Cross-Site Request Forgery (CSRF) vulnerability in jokerbr313 Advanced Post List advanced-post-list allows Cross Site Request Forgery.This issue affe…

Mitigation only
Fix from $1,600 2025-06-06
Unclassified MEDIUM 6.3
CVE-2025-30981

Cross-Site Request Forgery (CSRF) vulnerability in tggfref WP-Recall allows Privilege Escalation. This issue affects WP-Recall: from n/a through 16.2…

Mitigation only
Fix from $1,600 2025-06-06
Unclassified MEDIUM 5.4
CVE-2025-30632

Cross-Site Request Forgery (CSRF) vulnerability in pozzad Global Translator global-translator allows Cross Site Request Forgery.This issue affects Gl…

Mitigation only
Fix from $1,600 2025-06-06
Unclassified HIGH 8.2
CVE-2025-28986

Cross-Site Request Forgery (CSRF) vulnerability in Webaholicson Epicwin Plugin epicwin-subscribers allows SQL Injection.This issue affects Epicwin Pl…

Mitigation only
Fix from $1,950 2025-06-06
Unclassified HIGH 7.4
CVE-2025-28954

Cross-Site Request Forgery (CSRF) vulnerability in wphobby Backwp backwp allows Path Traversal.This issue affects Backwp: from n/a through <= 2.0.2.

Mitigation only
Fix from $1,950 2025-06-06
Unclassified HIGH 7.1
CVE-2025-28958

Cross-Site Request Forgery (CSRF) vulnerability in Vadim Bogaiskov Bg Orthodox Calendar bg-orthodox-calendar allows Stored XSS.This issue affects Bg …

Mitigation only
Fix from $1,950 2025-06-06
Unclassified HIGH 7.1
CVE-2025-28964

Cross-Site Request Forgery (CSRF) vulnerability in mangup Personal Favicon personal-favicon allows Stored XSS.This issue affects Personal Favicon: fr…

Mitigation only
Fix from $1,950 2025-06-06
Unclassified HIGH 7.1
CVE-2025-28966

Cross-Site Request Forgery (CSRF) vulnerability in dilemma123 Recent Posts Slider Responsive recent-posts-slider-responsive allows Stored XSS.This is…

Mitigation only
Fix from $1,950 2025-06-06
Unclassified HIGH 7.1
CVE-2025-28974

Cross-Site Request Forgery (CSRF) vulnerability in mail250 Free WP Mail SMTP free-wp-mail-smtp allows Stored XSS.This issue affects Free WP Mail SMTP…

Mitigation only
Fix from $1,950 2025-06-06
Unclassified HIGH 7.1
CVE-2025-28981

Cross-Site Request Forgery (CSRF) vulnerability in Soli WP Mail Options wp-mail-options allows Stored XSS.This issue affects WP Mail Options: from n/…

Mitigation only
Fix from $1,950 2025-06-06
Unclassified HIGH 7.1
CVE-2025-28948

Cross-Site Request Forgery (CSRF) vulnerability in codedraft Mediabay - WordPress Media Library Folders allows Reflected XSS. This issue affects Medi…

Mitigation only
Fix from $1,950 2025-06-06
Unclassified HIGH 7.1
CVE-2025-28950

Cross-Site Request Forgery (CSRF) vulnerability in David Shabtai Post Author post-author allows Stored XSS.This issue affects Post Author: from n/a t…

Mitigation only
Fix from $1,950 2025-06-06
Unclassified MEDIUM 5.4
CVE-2025-24772

Cross-Site Request Forgery (CSRF) vulnerability in cmsMinds Pay with Contact Form 7 pay-with-contact-form-7 allows Cross Site Request Forgery.This is…

Mitigation only
Fix from $1,600 2025-06-06
Traffic Offense Reporting System HIGH 8.8
CVE-2025-5732

A vulnerability, which was classified as problematic, was found in code-projects Traffic Offense Reporting System 1.0. This affects an unknown part. …

No fix yet
Fix from $1,950 2025-06-06
Unclassified MEDIUM 5.4
CVE-2025-5019

The Hive Support | AI-Powered Help Desk, Live Chat & AI Chat Bot Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forger…

Mitigation only
Fix from $1,600 2025-06-06
Wp Online Users Stats MEDIUM 6.1
CVE-2025-4966

The WP Online Users Stats plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due t…

Fix: after 1.0.0
Fix from $1,600 2025-06-06
Unclassified MEDIUM 5.4
CVE-2025-2935

The Anti-Spam: Spam Protection | Block Spam Users, Comments, Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u…

Mitigation only
Fix from $1,600 2025-06-06
Wukong Crm HIGH 8.8
CVE-2025-5521

A vulnerability was found in WuKongOpenSource WukongCRM 9.0. It has been declared as problematic. Affected by this vulnerability is an unknown functi…

No fix yet
Fix from $1,950 2025-06-03
Unclassified MEDIUM 5.7
CVE-2025-48885

application-urlshortener create shortened URLs for XWiki pages. Versions prior to 1.2.4 are vulnerable to users with view access being able to create…

Patch available
Fix from $1,600 2025-05-30
Simple Page Access Restriction MEDIUM 6.5
CVE-2025-5142

The Simple Page Access Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.31. Thi…

Fix: 1.0.32+
Fix from $1,600 2025-05-30
Freescout MEDIUM 5.4
CVE-2025-48483

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to Cross-Site Scripting (XSS) a…

Fix: 1.8.180+
Fix from $1,600 2025-05-30
Idna HIGH 8.8
CVE-2024-12224

Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one…

Fix: 1.0.0+
Fix from $1,950 2025-05-30
Gibbon HIGH 8.8
CVE-2025-26211

Gibbon before 29.0.00 allows CSRF.

Fix: 29.0.00+
Fix from $1,950 2025-05-27
Tmall Demo HIGH 8.8
CVE-2025-5132

A vulnerability was found in Tmall Demo up to 20250505. It has been rated as problematic. This issue affects some unknown processing of the file tmal…

Fix: after 2025-05-05
Fix from $1,950 2025-05-24