Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Unclassified CRITICAL 9.3
CVE-2025-30528

Cross-Site Request Forgery (CSRF) vulnerability in wpshopee Awesome Logos awesome-logos allows SQL Injection.This issue affects Awesome Logos: from n…

Mitigation only
Fix from $2,300 2025-03-24
Unclassified HIGH 7.1
CVE-2025-30522

Cross-Site Request Forgery (CSRF) vulnerability in Damian Orzol Contact Form 7 Material Design cf7-material-design allows Stored XSS.This issue affec…

Mitigation only
Fix from $1,950 2025-03-24
Mlflow HIGH 7.1
CVE-2025-1473

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Signup feature of mlflow/mlflow versions 2.17.0 to 2.20.1. This vulnerability allows …

Fix: 2.20.1+
Fix from $1,950 2025-03-20
Flatpress HIGH 8.0
CVE-2024-9847

FlatPress CMS version latest is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow an attacker to enable or disable plugins on behalf…

Fix: 1.4+
Fix from $1,950 2025-03-20
Unclassified MEDIUM 6.5
CVE-2024-9365

A Cross-Site Request Forgery (CSRF) vulnerability in polyaxon/polyaxon v2.4.0 allows attackers to perform unauthorized actions in the context of the …

Mitigation only
Fix from $1,600 2025-03-20
Large Language And Vision Assistant MEDIUM 6.1
CVE-2024-9311

A Cross-Site Request Forgery (CSRF) vulnerability in haotian-liu/llava v1.2.0 (LLaVA-1.6) allows an attacker to upload files with malicious content w…

No fix yet
Fix from $1,600 2025-03-20
Lollms Web Ui MEDIUM 6.5
CVE-2024-8736

A Denial of Service (DoS) vulnerability exists in multiple file upload endpoints of parisneo/lollms-webui version V12 (Strawberry). The vulnerability…

No fix yet
Fix from $1,600 2025-03-20
Unclassified HIGH 8.8
CVE-2024-8489

A vulnerability in modelscope/agentscope, specifically in the AgentScope Studio backend server, allows for Cross-Site Request Forgery (CSRF) due to o…

Mitigation only
Fix from $1,950 2025-03-20
Unclassified HIGH 8.1
CVE-2024-8065

A Cross-Site Request Forgery (CSRF) vulnerability in version v1.4.1 of danswer-ai/danswer allows attackers to perform unauthorized actions in the con…

Mitigation only
Fix from $1,950 2025-03-20
Qanything HIGH 8.1
CVE-2024-8026

A Cross-Site Request Forgery (CSRF) vulnerability exists in the backend API of netease-youdao/qanything, as of commit d9ab8bc. The backend server has…

Fix: after 2024-06-24
Fix from $1,950 2025-03-20
Open Webui HIGH 8.8
CVE-2024-7806

A vulnerability in open-webui/open-webui versions <= 0.3.8 allows remote code execution by non-admin users via Cross-Site Request Forgery (CSRF). The…

Fix: after 0.3.8
Fix from $1,950 2025-03-20
Aim CRITICAL 9.6
CVE-2024-7760

aimhubio/aim version 3.22.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the tracking server. The vulnerability is due to overly per…

No fix yet
Fix from $2,300 2025-03-20
Open Webui MEDIUM 6.9
CVE-2024-7035

In version v0.3.8 of open-webui/open-webui, sensitive actions such as deleting and resetting are performed using the GET method. This vulnerability a…

No fix yet
Fix from $1,600 2025-03-20
Unclassified MEDIUM 6.5
CVE-2024-6841

A Cross-Site Request Forgery (CSRF) vulnerability exists in the latest commit (56b782bcefd2e59b19cd7ba7878b95f54884f502) of the vanna-ai/vanna reposi…

Mitigation only
Fix from $1,600 2025-03-20
Db Gpt HIGH 8.1
CVE-2024-10906

In version 0.6.0 of eosphoros-ai/db-gpt, the `uvicorn` app created by `dbgpt_server` uses an overly permissive instance of `CORSMiddleware` which set…

No fix yet
Fix from $1,950 2025-03-20
Gpt Academic HIGH 8.8
CVE-2024-10819

A Cross-Site Request Forgery (CSRF) vulnerability in version 3.83 of binary-husky/gpt_academic allows an attacker to trick a user into uploading file…

No fix yet
Fix from $1,950 2025-03-20
Comfyui MEDIUM 6.5
CVE-2024-10481

A CSRF vulnerability exists in comfyanonymous/comfyui versions up to v0.2.2. This vulnerability allows attackers to host malicious websites that, whe…

Fix: after 0.2.2
Fix from $1,600 2025-03-20
Unclassified HIGH 8.8
CVE-2024-13933

The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,…

Mitigation only
Fix from $1,950 2025-03-19
Unclassified MEDIUM 6.5
CVE-2025-26899

Cross-Site Request Forgery (CSRF) vulnerability in Recapture Cart Recovery and Email Marketing Recapture for WooCommerce recapture-for-woocommerce al…

Mitigation only
Fix from $1,600 2025-03-15
Zoorum Comments MEDIUM 5.4
CVE-2025-2163

The Zoorum Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9. This is due to missin…

Fix: after 0.9
Fix from $1,600 2025-03-15
Openadmin MEDIUM 5.5
CVE-2025-25873

Cross Site Request Forgery vulnerability in Open Panel OpenAdmin v.0.3.4 allows a remote attacker to escalate privileges via the Change Root Password…

No fix yet
Fix from $1,600 2025-03-14
Unclassified HIGH 8.8
CVE-2024-13913

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl…

Mitigation only
Fix from $1,950 2025-03-14
Unclassified HIGH 7.5
CVE-2025-1764

The LoginPress | wp-login Custom Login Page Customizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in…

Mitigation only
Fix from $1,950 2025-03-14
Limit Bio HIGH 7.1
CVE-2025-1436

The Limit Bio WordPress plugin through 1.0 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, whic…

No fix yet
Fix from $1,950 2025-03-13
Unclassified HIGH 7.7
CVE-2025-27792

Opal is OBiBa’s core database application for biobanks or epidemiological studies. Prior to version 5.1.1, the protections against cross-site request…

Mitigation only
Fix from $1,950 2025-03-11
Unclassified HIGH 7.1
CVE-2025-28931

Cross-Site Request Forgery (CSRF) vulnerability in DevriX Hashtags wp-hashtags allows Stored XSS.This issue affects Hashtags: from n/a through <= 0.3…

Mitigation only
Fix from $1,950 2025-03-11
Unclassified HIGH 7.1
CVE-2025-28932

Cross-Site Request Forgery (CSRF) vulnerability in BCS Website Solutions Insert Code insert-code allows Stored XSS.This issue affects Insert Code: fr…

Mitigation only
Fix from $1,950 2025-03-11
Unclassified HIGH 7.1
CVE-2025-28933

Cross-Site Request Forgery (CSRF) vulnerability in maxfoundry MaxA/B maxab allows Stored XSS.This issue affects MaxA/B: from n/a through <= 2.2.2.

Mitigation only
Fix from $1,950 2025-03-11
Unclassified HIGH 7.1
CVE-2025-28923

Cross-Site Request Forgery (CSRF) vulnerability in philippe No Disposable Email no-disposable-email allows Stored XSS.This issue affects No Disposabl…

Mitigation only
Fix from $1,950 2025-03-11
Unclassified HIGH 7.1
CVE-2025-28925

Cross-Site Request Forgery (CSRF) vulnerability in Hieu Nguyen WATI Chat and Notification wati-chat-and-notification allows Stored XSS.This issue aff…

Mitigation only
Fix from $1,950 2025-03-11