Vulnerability index

Browse CVEs

7,366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Unclassified MEDIUM 5.9
CVE-2025-48740

A Cross-Site Request Forgery (CSRF) vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, 5.4.0 before 5.4.10, and 5.5.0 befo…

Mitigation only
Fix from $1,600 2025-05-23
Unclassified HIGH 8.2
CVE-2025-46458

Cross-Site Request Forgery (CSRF) vulnerability in x000x occupancyplan occupancyplan allows SQL Injection.This issue affects occupancyplan: from n/a …

Mitigation only
Fix from $1,950 2025-05-23
Unclassified CRITICAL 9.8
CVE-2025-48340

Cross-Site Request Forgery (CSRF) vulnerability in Danny Vink User Profile Meta Manager user-profile-meta allows Privilege Escalation.This issue affe…

Mitigation only
Fix from $2,300 2025-05-19
Unclassified HIGH 7.1
CVE-2025-43840

Cross-Site Request Forgery (CSRF) vulnerability in ref CheckBot checkbot allows Stored XSS.This issue affects CheckBot: from n/a through <= 1.05.

Mitigation only
Fix from $1,950 2025-05-19
Unclassified MEDIUM 5.4
CVE-2025-47583

Cross-Site Request Forgery (CSRF) vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Cross Site Request Forgery.This is…

Mitigation only
Fix from $1,600 2025-05-19
Unclassified HIGH 7.1
CVE-2025-39374

Cross-Site Request Forgery (CSRF) vulnerability in aseem1234 Best Posts Summary best-posts-summary allows Stored XSS.This issue affects Best Posts Su…

Mitigation only
Fix from $1,950 2025-05-19
Unclassified MEDIUM 5.4
CVE-2025-48342

Cross-Site Request Forgery (CSRF) vulnerability in RedefiningTheWeb Dynamic Pricing & Discounts Lite for WooCommerce woo-dynamic-pricing-discounts-li…

Mitigation only
Fix from $1,600 2025-05-19
Unclassified MEDIUM 5.4
CVE-2025-48344

Cross-Site Request Forgery (CSRF) vulnerability in ed4becky Rootspersona rootspersona allows Cross Site Request Forgery.This issue affects Rootsperso…

Mitigation only
Fix from $1,600 2025-05-19
Unclassified MEDIUM 5.4
CVE-2025-48284

Cross-Site Request Forgery (CSRF) vulnerability in shohei.tanaka Japanized For WooCommerce woocommerce-for-japan allows Cross Site Request Forgery.Th…

Mitigation only
Fix from $1,600 2025-05-19
Videowhisper Live Streaming Integration HIGH 8.8
CVE-2025-48255

Cross-Site Request Forgery (CSRF) vulnerability in videowhisper Broadcast Live Video videowhisper-live-streaming-integration allows Cross Site Reques…

Fix: after 6.2.4
Fix from $1,950 2025-05-19
Unclassified HIGH 7.1
CVE-2025-48238

Cross-Site Request Forgery (CSRF) vulnerability in awcode AWcode Toolkit awcode-toolkit allows Stored XSS.This issue affects AWcode Toolkit: from n/a…

Mitigation only
Fix from $1,950 2025-05-19
Unclassified HIGH 7.1
CVE-2025-48233

Cross-Site Request Forgery (CSRF) vulnerability in affmngr Affiliates Manager Google reCAPTCHA Integration affiliates-manager-google-recaptcha-integr…

Mitigation only
Fix from $1,950 2025-05-19
Online Student Clearance System HIGH 8.8
CVE-2025-4887

A vulnerability, which was classified as problematic, has been found in SourceCodester Online Student Clearance System 1.0. Affected by this issue is…

No fix yet
Fix from $1,950 2025-05-18
Unclassified MEDIUM 6.1
CVE-2025-4194

The AlT Monitoring plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to missi…

Mitigation only
Fix from $1,600 2025-05-17
Unclassified MEDIUM 6.1
CVE-2025-4189

The Audio Comments Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. This is due t…

Mitigation only
Fix from $1,600 2025-05-17
Wholesale Market MEDIUM 6.5
CVE-2022-4363

The Wholesale Market WordPress plugin before 2.2.2, Wholesale Market for WooCommerce WordPress plugin before 2.0.1 have a flawed CSRF check when upda…

Fix: 2.0.1 / 2.2.2+
Fix from $1,600 2025-05-16
Seo Flow MEDIUM 6.1
CVE-2025-48146

Cross-Site Request Forgery (CSRF) vulnerability in Michael Lups SEO Flow by LupsOnline lupsonline-link-netwerk allows Stored XSS.This issue affects S…

Fix: after 2.2.0
Fix from $1,600 2025-05-16
Import Export For Woocommerce MEDIUM 6.1
CVE-2025-48144

Cross-Site Request Forgery (CSRF) vulnerability in sidngr Import Export For WooCommerce import-export-for-woocommerce allows Stored XSS.This issue af…

Fix: after 1.6.2
Fix from $1,600 2025-05-16
Unclassified HIGH 7.1
CVE-2025-48114

Cross-Site Request Forgery (CSRF) vulnerability in Shayan Farhang Pazhooh ShayanWeb Admin FontChanger shayanweb-admin-fontchanger allows Stored XSS.T…

Mitigation only
Fix from $1,950 2025-05-16
Unclassified HIGH 8.8
CVE-2025-32310

Cross-Site Request Forgery (CSRF) vulnerability in ThemeMove QuickCal - Appointment Booking Calendar for WordPress quickcal allows Privilege Escalati…

Mitigation only
Fix from $1,950 2025-05-16
Unclassified HIGH 7.1
CVE-2025-31922

Cross-Site Request Forgery (CSRF) vulnerability in QuanticaLabs CSS3 Accordions for WordPress css3_accordions allows Stored XSS.This issue affects CS…

Mitigation only
Fix from $1,950 2025-05-16
Unclassified MEDIUM 6.5
CVE-2025-32245

Cross-Site Request Forgery (CSRF) vulnerability in Chaser324 Featured Posts Scroll featured-posts-scroll allows Stored XSS.This issue affects Feature…

Mitigation only
Fix from $1,600 2025-05-16
Unclassified MEDIUM 5.4
CVE-2025-31915

Cross-Site Request Forgery (CSRF) vulnerability in kamleshyadav Pixel WordPress Form BuilderPlugin & Autoresponder pixel-formbuilder allows Cross Sit…

Mitigation only
Fix from $1,600 2025-05-16
Wp Pmanager MEDIUM 5.4
CVE-2025-2247

The WP-PManager WordPress plugin through 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logg…

Fix: after 1.2
Fix from $1,600 2025-05-15
Wooexim MEDIUM 6.1
CVE-2025-1288

The WOOEXIM WordPress plugin through 5.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could all…

Fix: after 5.0.0
Fix from $1,600 2025-05-15
Ekc Tournament Manager MEDIUM 5.4
CVE-2024-9709

The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to…

Fix: 2.2.2+
Fix from $1,600 2025-05-15
Ekc Tournament Manager MEDIUM 5.4
CVE-2024-9711

The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to…

Fix: 2.2.2+
Fix from $1,600 2025-05-15
Easync MEDIUM 6.5
CVE-2024-9450

The Free Booking Plugin for Hotels, Restaurants and Car Rentals WordPress plugin before 1.3.15 does not have CSRF check in place when updating its s…

Fix: 1.3.15+
Fix from $1,600 2025-05-15
Gdpr Cookie Consent MEDIUM 6.5
CVE-2024-8286

The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not have CSRF checks in some bulk actions, which could allow attackers to make l…

Fix: 2.6.1+
Fix from $1,600 2025-05-15
Smooth Gallery Replacement MEDIUM 6.1
CVE-2024-8032

The Smooth Gallery Replacement WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping,…

Fix: after 1.0
Fix from $1,600 2025-05-15