Vulnerability index

Browse CVEs

7,366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Unclassified HIGH 7.4
CVE-2025-39544

Cross-Site Request Forgery (CSRF) vulnerability in sminozzi WP Tools wptools allows Path Traversal.This issue affects WP Tools: from n/a through <= 5…

Mitigation only
Fix from $1,950 2025-04-16
Unclassified HIGH 7.1
CVE-2025-39547

Cross-Site Request Forgery (CSRF) vulnerability in Toast Plugins Internal Link Optimiser internal-link-finder allows Stored XSS.This issue affects In…

Mitigation only
Fix from $1,950 2025-04-16
Unclassified HIGH 7.1
CVE-2025-39548

Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Right Click Disable OR Ban right-click-disable-or-ban allows Stored XSS.This issue affec…

Mitigation only
Fix from $1,950 2025-04-16
Unclassified HIGH 7.1
CVE-2025-39530

Cross-Site Request Forgery (CSRF) vulnerability in dsky Site Search 360 site-search-360 allows Stored XSS.This issue affects Site Search 360: from n/…

Mitigation only
Fix from $1,950 2025-04-16
Unclassified CRITICAL 9.6
CVE-2025-30967

Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Upload a Web Shell to a Web Server. This issue affects WPJobBoard: from…

Mitigation only
Fix from $2,300 2025-04-15
Unclassified HIGH 8.1
CVE-2025-26748

Cross-Site Request Forgery (CSRF) vulnerability in looswebstudio Arkhe arkhe allows PHP Local File Inclusion.This issue affects Arkhe: from n/a throu…

Mitigation only
Fix from $1,950 2025-04-15
Commerce Platform MEDIUM 5.4
CVE-2025-21576

Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Personalization Server). Supported versions that are aff…

Patch available
Fix from $1,600 2025-04-15
Unclassified MEDIUM 5.4
CVE-2025-24358

gorilla/csrf provides Cross Site Request Forgery (CSRF) prevention middleware for Go web applications & services. Prior to 1.7.2, gorilla/csrf does n…

Patch available
Fix from $1,600 2025-04-15
Unclassified HIGH 7.1
CVE-2025-27009

Cross-Site Request Forgery (CSRF) vulnerability in wphocus My auctions allegro my-auctions-allegro-free-edition allows Stored XSS.This issue affects …

Mitigation only
Fix from $1,950 2025-04-14
Uzy Ssm Mall MEDIUM 6.5
CVE-2025-3561

A vulnerability was found in ghostxbh uzy-ssm-mall 1.0.0. It has been classified as problematic. Affected is an unknown function. The manipulation le…

No fix yet
Fix from $1,600 2025-04-14
Brizy HIGH 8.8
CVE-2025-26902

Cross-Site Request Forgery (CSRF) vulnerability in Brizy Brizy Pro allows Cross Site Request Forgery.This issue affects Brizy Pro: from n/a through 2…

Fix: after 2.6.1
Fix from $1,950 2025-04-09
Eca\ MEDIUM 5.4
CVE-2025-3131

Cross-Site Request Forgery (CSRF) vulnerability in Drupal ECA: Event - Condition - Action allows Cross Site Request Forgery.This issue affects ECA: E…

Fix: 1.1.12 / 2.0.16+
Fix from $1,600 2025-04-09
Unclassified MEDIUM 5.4
CVE-2025-32679

Cross-Site Request Forgery (CSRF) vulnerability in ZealousWeb User Registration Using Contact Form 7 user-registration-using-contact-form-7 allows Cr…

Mitigation only
Fix from $1,600 2025-04-09
Unclassified HIGH 7.1
CVE-2025-32669

Cross-Site Request Forgery (CSRF) vulnerability in MERGADO Mergado Pack mergado-marketing-pack allows Stored XSS.This issue affects Mergado Pack: fro…

Mitigation only
Fix from $1,950 2025-04-09
Unclassified HIGH 7.1
CVE-2025-32673

Cross-Site Request Forgery (CSRF) vulnerability in epeken Epeken All Kurir epeken-all-kurir allows Stored XSS.This issue affects Epeken All Kurir: fr…

Mitigation only
Fix from $1,950 2025-04-09
Unclassified HIGH 7.1
CVE-2025-32645

Cross-Site Request Forgery (CSRF) vulnerability in Hiren Patel Custom Posts Order custom-posts-order allows Stored XSS.This issue affects Custom Post…

Mitigation only
Fix from $1,950 2025-04-09
Unclassified HIGH 7.1
CVE-2025-32659

Cross-Site Request Forgery (CSRF) vulnerability in fraudlabspro FraudLabs Pro for WooCommerce fraudlabs-pro-for-woocommerce allows Stored XSS.This is…

Mitigation only
Fix from $1,950 2025-04-09
Unclassified HIGH 7.1
CVE-2025-32661

Cross-Site Request Forgery (CSRF) vulnerability in WP Map Plugins Interactive US Map interactive-us-map allows Stored XSS.This issue affects Interact…

Mitigation only
Fix from $1,950 2025-04-09
Unclassified HIGH 7.1
CVE-2025-32664

Cross-Site Request Forgery (CSRF) vulnerability in ashokbasnet Nepali Date Utilities nepali-date-utilities allows Stored XSS.This issue affects Nepal…

Mitigation only
Fix from $1,950 2025-04-09
Unclassified HIGH 7.1
CVE-2025-32667

Cross-Site Request Forgery (CSRF) vulnerability in fromdoppler Doppler Forms doppler-form allows Stored XSS.This issue affects Doppler Forms: from n/…

Mitigation only
Fix from $1,950 2025-04-09
Unclassified HIGH 7.1
CVE-2025-32623

Cross-Site Request Forgery (CSRF) vulnerability in plainware PlainInventory z-inventory-manager allows Stored XSS.This issue affects PlainInventory: …

Mitigation only
Fix from $1,950 2025-04-09
Unclassified CRITICAL 9.6
CVE-2025-32641

Cross-Site Request Forgery (CSRF) vulnerability in anantaddons Anant Addons for Elementor anant-addons-for-elementor allows Cross Site Request Forger…

Mitigation only
Fix from $2,300 2025-04-09
Unclassified CRITICAL 10.0
CVE-2025-32642

Cross-Site Request Forgery (CSRF) vulnerability in appsbd Vite Coupon vite-coupon allows Remote Code Inclusion.This issue affects Vite Coupon: from n…

Mitigation only
Fix from $2,300 2025-04-09
Unclassified HIGH 7.1
CVE-2025-32644

Cross-Site Request Forgery (CSRF) vulnerability in IP2Location IP2Location World Clock ip2location-world-clock allows Stored XSS.This issue affects I…

Mitigation only
Fix from $1,950 2025-04-09
Unclassified HIGH 7.1
CVE-2025-32612

Cross-Site Request Forgery (CSRF) vulnerability in rafasashi User Session Synchronizer user-session-synchronizer allows Stored XSS.This issue affects…

Mitigation only
Fix from $1,950 2025-04-09
Unclassified HIGH 7.1
CVE-2025-32616

Cross-Site Request Forgery (CSRF) vulnerability in nimbata Nimbata Call Tracking nimbata-call-tracking allows Stored XSS.This issue affects Nimbata C…

Mitigation only
Fix from $1,950 2025-04-09
Unclassified HIGH 7.1
CVE-2025-32617

Cross-Site Request Forgery (CSRF) vulnerability in Ydesignservices Multiple Location Google Map multiple-location-google-map allows Stored XSS.This i…

Mitigation only
Fix from $1,950 2025-04-09
Unclassified HIGH 7.1
CVE-2025-32619

Cross-Site Request Forgery (CSRF) vulnerability in KeyCAPTCHA KeyCAPTCHA keycaptcha allows Stored XSS.This issue affects KeyCAPTCHA: from n/a through…

Mitigation only
Fix from $1,950 2025-04-09
Unclassified HIGH 7.1
CVE-2025-32621

Cross-Site Request Forgery (CSRF) vulnerability in Vsourz Digital WP Map Route Planner wp-map-route-planner allows Cross Site Request Forgery.This is…

Mitigation only
Fix from $1,950 2025-04-09
Unclassified HIGH 7.1
CVE-2025-32584

Cross-Site Request Forgery (CSRF) vulnerability in Chat2 Chat2 chat2 allows Cross Site Request Forgery.This issue affects Chat2: from n/a through <= …

No fix yet
Fix from $1,950 2025-04-09