Vulnerability index

Browse CVEs

7,366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Peoplepond MEDIUM 6.1
CVE-2024-8085

The PeoplePond WordPress plugin through 1.1.9 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could a…

Fix: after 1.1.9
Fix from $1,600 2025-05-15
Javascript Logic MEDIUM 6.1
CVE-2024-8090

The JavaScript Logic WordPress plugin through 0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which cou…

No fix yet
Fix from $1,600 2025-05-15
Ntz Atispam MEDIUM 6.5
CVE-2024-8094

The Ntz Antispam WordPress plugin through 2.0e does not have CSRF check in place when updating its settings, which could allow attackers to make a lo…

Fix: after 2.0e
Fix from $1,600 2025-05-15
Offload Videos HIGH 8.1
CVE-2024-6719

The Offload Videos WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow low privilege users…

Fix: 1.0.1+
Fix from $1,950 2025-05-15
Tarteaucitron Wp MEDIUM 6.1
CVE-2024-11719

The tarteaucitron-wp WordPress plugin before 0.3.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which co…

Fix: 0.3.0+
Fix from $1,600 2025-05-15
Wp Connect MEDIUM 6.1
CVE-2024-12282

The WordPress连接微博 WordPress plugin through 2.5.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which …

Fix: after 2.5.6
Fix from $1,600 2025-05-15
Jsp Store Locator MEDIUM 6.5
CVE-2024-12301

The JSP Store Locator WordPress plugin through 1.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perf…

Fix: after 1.0
Fix from $1,600 2025-05-15
Abitgone Commentsafe HIGH 7.1
CVE-2023-7174

The aBitGone CommentSafe WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, whi…

Fix: after 1.0.0
Fix from $1,950 2025-05-15
Marketing Twitter Bot HIGH 7.1
CVE-2023-7197

The Marketing Twitter Bot WordPress plugin through 1.11 does not have CSRF check in some places, and is missing sanitisation as well as escaping, whi…

Fix: after 1.11
Fix from $1,950 2025-05-15
Illi Link Party\! MEDIUM 5.5
CVE-2023-7229

The illi Link Party! WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a…

Fix: after 1.0
Fix from $1,600 2025-05-15
Travelpayouts HIGH 7.3
CVE-2023-5934

The Travelpayouts: All Travel Brands in One Place WordPress plugin before 1.1.13 does not have CSRF check in place when importing settings from the v…

Fix: 1.1.13+
Fix from $1,950 2025-05-15
Easy Digital Downloads Google Sheet Connector MEDIUM 5.4
CVE-2023-2334

The edd-google-sheet-connector-pro WordPress plugin before 1.4, Easy Digital Downloads Google Sheet Connector WordPress plugin before 1.6.6 does not …

Fix: 1.4 / 1.6.6+
Fix from $1,600 2025-05-15
Unclassified HIGH 7.1
CVE-2025-32922

Cross-Site Request Forgery (CSRF) vulnerability in Saleswonder Team: Tobias WP2LEADS wp2leads allows Stored XSS.This issue affects WP2LEADS: from n/a…

Mitigation only
Fix from $1,950 2025-05-15
Best Employee Management System MEDIUM 5.4
CVE-2025-44185

SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/change_pass.php via the password par…

No fix yet
Fix from $1,600 2025-05-15
Miniorange 2fa HIGH 8.8
CVE-2025-47708

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Cross Site Request Forgery.This issue affects Enterp…

Fix: 5.2.0 / 8.x-4.7+
Fix from $1,950 2025-05-14
Best Employee Management System MEDIUM 5.4
CVE-2025-44186

SourceCodester Best Employee Management System 1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/Operation/User.php page.

No fix yet
Fix from $1,600 2025-05-14
Restrict Route By Ip HIGH 8.8
CVE-2025-47701

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Restrict route by IP allows Cross Site Request Forgery.This issue affects Restrict route by…

Fix: 1.3.0+
Fix from $1,950 2025-05-14
Nosurf MEDIUM 6.1
CVE-2025-46721

nosurf is cross-site request forgery (CSRF) protection middleware for Go. A vulnerability in versions prior to 1.2.0 allows an attacker who controls …

Fix: 1.2.0+
Fix from $1,600 2025-05-13
Bootstrap Multiselect MEDIUM 6.1
CVE-2025-47204

An issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Multiselect) 1.1.2. A PHP script in the source code echoes arbitrary POST…

Patch available
Fix from $1,600 2025-05-13
Safari MEDIUM 6.5
CVE-2025-31205

The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2…

Fix: 2.5 / 11.5+
Fix from $1,600 2025-05-12
Safari HIGH 8.0
CVE-2025-24223

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, v…

Fix: 2.5 / 11.5+
Fix from $1,950 2025-05-12
Unclassified MEDIUM 6.3
CVE-2025-46743

An authenticated user's token could be used by another source after the user had logged out prior to the token expiring.

Mitigation only
Fix from $1,600 2025-05-12
Enterprise Mail Archive HIGH 8.8
CVE-2025-46610

ARTEC EMA Mail 6.92 allows CSRF.

Mitigation only
Fix from $1,950 2025-05-12
Unclassified MEDIUM 6.9
CVE-2025-4375

Cross-Site Request Forgery (CSRF) vulnerability in Sparx Systems Pro Cloud Server allows Cross-Site Request Forgery to perform Session Hijacking. Cro…

Mitigation only
Fix from $1,600 2025-05-09
Unclassified MEDIUM 5.4
CVE-2025-47684

Cross-Site Request Forgery (CSRF) vulnerability in Smaily Smaily for WP smaily-for-wp allows Cross Site Request Forgery.This issue affects Smaily for…

Mitigation only
Fix from $1,600 2025-05-07
Unclassified HIGH 7.1
CVE-2025-47685

Cross-Site Request Forgery (CSRF) vulnerability in Moloni Contribuinte Checkout contribuinte-checkout allows Stored XSS.This issue affects Contribuin…

Mitigation only
Fix from $1,950 2025-05-07
Unclassified MEDIUM 5.4
CVE-2025-47667

Cross-Site Request Forgery (CSRF) vulnerability in qusupport LiveAgent liveagent allows Cross Site Request Forgery.This issue affects LiveAgent: from…

Mitigation only
Fix from $1,600 2025-05-07
Unclassified MEDIUM 5.4
CVE-2025-47661

Cross-Site Request Forgery (CSRF) vulnerability in codemstory 워드프레스 결제 심플페이 pgall-for-woocommerce allows Cross Site Request Forgery.This i…

Mitigation only
Fix from $1,600 2025-05-07
Unclassified HIGH 7.1
CVE-2025-47639

Cross-Site Request Forgery (CSRF) vulnerability in Supertext Supertext Translation and Proofreading polylang-supertext allows Stored XSS.This issue a…

Mitigation only
Fix from $1,950 2025-05-07
Unclassified HIGH 7.1
CVE-2025-47648

Cross-Site Request Forgery (CSRF) vulnerability in axima Pays – WooCommerce Payment Gateway axima-payment-gateway allows Stored XSS.This issue affect…

Mitigation only
Fix from $1,950 2025-05-07