Vulnerability index

Browse CVEs

7,366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Unclassified HIGH 7.1
CVE-2025-47655

Cross-Site Request Forgery (CSRF) vulnerability in themarketer2023 theMarketer themarketer allows Stored XSS.This issue affects theMarketer: from n/a…

Mitigation only
Fix from $1,950 2025-05-07
Awin Advertiser Tracking For Woocommerce HIGH 8.8
CVE-2025-47633

Cross-Site Request Forgery (CSRF) vulnerability in Awin Awin – Advertiser Tracking for WooCommerce awin-advertiser-tracking allows Cross Site Request…

Fix: after 2.0.0
Fix from $1,950 2025-05-07
Unclassified HIGH 7.1
CVE-2025-47620

Cross-Site Request Forgery (CSRF) vulnerability in bundgaard Martins Free Monetized Ad Exchange Network martins-free-and-easy-ad-network-get-more-vis…

Mitigation only
Fix from $1,950 2025-05-07
Dofollow Case By Case HIGH 8.8
CVE-2025-47624

Cross-Site Request Forgery (CSRF) vulnerability in apasionados DoFollow Case by Case dofollow-case-by-case allows Cross Site Request Forgery.This iss…

Fix: after 3.5.1
Fix from $1,950 2025-05-07
Wp Compress HIGH 8.8
CVE-2025-47546

Cross-Site Request Forgery (CSRF) vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Cross Site Request Forgery.This issue affect…

Fix: after 6.30.30
Fix from $1,950 2025-05-07
Unclassified HIGH 8.1
CVE-2025-47533

Cross-Site Request Forgery (CSRF) vulnerability in Iqonic Design Graphina graphina-elementor-charts-and-graphs allows PHP Local File Inclusion.This i…

Mitigation only
Fix from $1,950 2025-05-07
Accept Donations With Paypal MEDIUM 6.1
CVE-2025-47517

Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Accept Donations with PayPal & Stripe easy-paypal-donation allows Stored XSS.This i…

Fix: 1.5+
Fix from $1,600 2025-05-07
Unclassified HIGH 7.1
CVE-2025-47514

Cross-Site Request Forgery (CSRF) vulnerability in Eli ELI's Related Posts Footer Links and Widget spostarbust allows Stored XSS.This issue affects E…

Mitigation only
Fix from $1,950 2025-05-07
Unclassified HIGH 7.4
CVE-2025-47491

Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Contact Form Widget new-contact-form-widget allows Cross Site Request Forgery.This issue…

Mitigation only
Fix from $1,950 2025-05-07
Unclassified MEDIUM 5.4
CVE-2025-47473

Cross-Site Request Forgery (CSRF) vulnerability in pimwick PW WooCommerce Bulk Edit pw-bulk-edit allows Cross Site Request Forgery.This issue affects…

Mitigation only
Fix from $1,600 2025-05-07
Unclassified HIGH 8.8
CVE-2025-47462

Cross-Site Request Forgery (CSRF) vulnerability in WebAppick Challan webappick-pdf-invoice-for-woocommerce allows Privilege Escalation.This issue aff…

Mitigation only
Fix from $1,950 2025-05-07
Unclassified MEDIUM 5.4
CVE-2025-47466

Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Ultimate WP Mail ultimate-wp-mail allows Cross Site Request Forgery.This issue affects …

Mitigation only
Fix from $1,600 2025-05-07
Boinc Server HIGH 8.8
CVE-2025-0669

Cross-Site Request Forgery (CSRF) vulnerability in BOINC Server allows Cross Site Request Forgery.This issue affects BOINC Server: before 1.4.3.

Fix: 1.4.3+
Fix from $1,950 2025-05-07
Stock Management System HIGH 8.8
CVE-2025-4282

A vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as problematic. This vulnerability affects unkn…

No fix yet
Fix from $1,950 2025-05-05
Erpnext HIGH 8.1
CVE-2025-28062

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in ERPNEXT 14.82.1 and 14.74.3. The vulnerability allows an attacker to perform unau…

No fix yet
Fix from $1,950 2025-05-05
Unclassified MEDIUM 6.1
CVE-2025-4199

The Abundatrade Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.02. This is due to …

Mitigation only
Fix from $1,600 2025-05-03
Unclassified MEDIUM 6.1
CVE-2025-4188

The Advanced Reorder Image Text Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. Th…

Mitigation only
Fix from $1,600 2025-05-03
Unclassified MEDIUM 6.1
CVE-2025-4198

The Alink Tap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.1. This is due to missing or…

Mitigation only
Fix from $1,600 2025-05-03
Proticaret HIGH 8.8
CVE-2024-11142

Cross-Site Request Forgery (CSRF) vulnerability in Gosoft Software Proticaret E-Commerce allows Cross Site Request Forgery. This issue affects Proti…

Fix: 6.0+
Fix from $1,950 2025-05-02
Newsblogger HIGH 8.8
CVE-2025-1305

The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2.5.4. This is due to missing…

Fix: 0.2.5.5+
Fix from $1,950 2025-05-01
Zimbra Collaboration Suite HIGH 8.8
CVE-2025-32354

In Zimbra Collaboration (ZCS) 9.0 through 10.1, a Cross-Site Request Forgery (CSRF) vulnerability exists in the GraphQL endpoint (/service/extension/…

Fix: 10.1.4+
Fix from $1,950 2025-04-29
Firefox MEDIUM 6.5
CVE-2025-4088

A security vulnerability in Thunderbird allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site tha…

Fix: 138.0+
Fix from $1,600 2025-04-29
Lecms MEDIUM 6.5
CVE-2025-3979

A vulnerability classified as problematic has been found in dazhouda lecms 3.0.3. This affects an unknown part of the file /index.php?my-password-aja…

No fix yet
Fix from $1,600 2025-04-27
Order Delivery Date Pro For Woocommerce CRITICAL 9.8
CVE-2025-2907

The Order Delivery Date WordPress plugin before 12.3.1 does not have authorization and CSRF checks when importing settings. Furthermore it also lacks…

Fix: 12.3.1+
Fix from $2,300 2025-04-26
Moodle HIGH 8.8
CVE-2025-3638

A flaw was found in Moodle. The analysis request action in the Brickfield tool did not include the necessary token to prevent a Cross-site request fo…

Fix: 4.1.18 / 4.3.12+
Fix from $1,950 2025-04-25
Sherpa Orchestrator MEDIUM 6.1
CVE-2025-46547

In Sherpa Orchestrator 141851, the web application lacks protection against CSRF attacks, with resultant effects of an attacker conducting XSS attack…

Mitigation only
Fix from $1,600 2025-04-25
Unclassified HIGH 7.1
CVE-2025-46528

Cross-Site Request Forgery (CSRF) vulnerability in Steve Availability Calendar availability allows Stored XSS.This issue affects Availability Calenda…

Mitigation only
Fix from $1,950 2025-04-24
Unclassified HIGH 7.1
CVE-2025-46530

Cross-Site Request Forgery (CSRF) vulnerability in HuangYe WuDeng Hacklog Remote Attachment hacklog-remote-attachment allows Stored XSS.This issue af…

Mitigation only
Fix from $1,950 2025-04-24
Unclassified HIGH 7.1
CVE-2025-46520

Cross-Site Request Forgery (CSRF) vulnerability in alphasis Related Posts via Taxonomies related-posts-via-taxonomies allows Stored XSS.This issue af…

Mitigation only
Fix from $1,950 2025-04-24
Unclassified HIGH 7.1
CVE-2025-46522

Cross-Site Request Forgery (CSRF) vulnerability in Billy Bryant Tabs gt-tabs allows Stored XSS.This issue affects Tabs: from n/a through <= 4.0.3.

Mitigation only
Fix from $1,950 2025-04-24