Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Unclassified HIGH 7.1
CVE-2025-28922

Cross-Site Request Forgery (CSRF) vulnerability in Terence D. Go To Top go-to-top allows Stored XSS.This issue affects Go To Top: from n/a through <=…

Mitigation only
Fix from $1,950 2025-03-11
Unclassified HIGH 7.1
CVE-2025-28897

Cross-Site Request Forgery (CSRF) vulnerability in Steveorevo Domain Theme domain-theme allows Stored XSS.This issue affects Domain Theme: from n/a t…

Mitigation only
Fix from $1,950 2025-03-11
Unclassified HIGH 7.1
CVE-2025-28900

Cross-Site Request Forgery (CSRF) vulnerability in webgarb TabGarb Pro tabgarb allows Stored XSS.This issue affects TabGarb Pro: from n/a through <= …

Mitigation only
Fix from $1,950 2025-03-11
Unclassified HIGH 7.1
CVE-2025-28901

Cross-Site Request Forgery (CSRF) vulnerability in Naren Members page only for logged in users members-page-only-for-logged-in-users allows Stored XS…

Mitigation only
Fix from $1,950 2025-03-11
Unclassified HIGH 7.1
CVE-2025-28891

Cross-Site Request Forgery (CSRF) vulnerability in jazzigor price-calc price-calc allows Stored XSS.This issue affects price-calc: from n/a through <…

Mitigation only
Fix from $1,950 2025-03-11
Unclassified HIGH 7.1
CVE-2025-28892

Cross-Site Request Forgery (CSRF) vulnerability in a2rocklobster FTP Sync ftp-sync allows Stored XSS.This issue affects FTP Sync: from n/a through <=…

Mitigation only
Fix from $1,950 2025-03-11
Unclassified HIGH 7.1
CVE-2025-28894

Cross-Site Request Forgery (CSRF) vulnerability in frucomerci List of Posts from each Category plugin for WordPress list-posts-by-category allows Sto…

Mitigation only
Fix from $1,950 2025-03-11
Skrill HIGH 8.8
CVE-2025-28876

Cross-Site Request Forgery (CSRF) vulnerability in Skrill_Team Skrill Official official-skrill-woocommerce allows Cross Site Request Forgery.This iss…

Fix: 1.0.67+
Fix from $1,950 2025-03-11
Unclassified HIGH 7.1
CVE-2025-28883

Cross-Site Request Forgery (CSRF) vulnerability in Martin WP Compare Tables wp-compare-tables allows Stored XSS.This issue affects WP Compare Tables:…

Mitigation only
Fix from $1,950 2025-03-11
Frontpage Category Filter HIGH 8.8
CVE-2025-28867

Cross-Site Request Forgery (CSRF) vulnerability in stesvis Frontpage category filter frontpage-category-filter allows Cross Site Request Forgery.This…

Fix: after 1.0.2
Fix from $1,950 2025-03-11
Ziplist Recipe HIGH 8.8
CVE-2025-28868

Cross-Site Request Forgery (CSRF) vulnerability in ZipList ZipList Recipe ziplist-recipe-plugin allows Cross Site Request Forgery.This issue affects …

Fix: after 3.1
Fix from $1,950 2025-03-11
Maintenance Notice HIGH 8.8
CVE-2025-28859

Cross-Site Request Forgery (CSRF) vulnerability in CodeVibrant Maintenance Notice maintenance-notice allows Cross Site Request Forgery.This issue aff…

Fix: after 1.0.5
Fix from $1,950 2025-03-11
Google News Editors Picks Feed Generator MEDIUM 6.1
CVE-2025-28860

Cross-Site Request Forgery (CSRF) vulnerability in PPDPurveyor Google News Editors Picks Feed Generator google-news-editors-picks-news-feeds allows S…

Fix: after 2.1
Fix from $1,600 2025-03-11
Wp Jquery Persian Datepicker MEDIUM 6.1
CVE-2025-28861

Cross-Site Request Forgery (CSRF) vulnerability in bhzad WP jQuery Persian Datepicker wpjqp-datepicker allows Stored XSS.This issue affects WP jQuery…

Fix: after 0.1.0
Fix from $1,600 2025-03-11
Comment Date And Gravatar Remover HIGH 8.8
CVE-2025-28862

Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Comment Date and Gravatar remover remove-date-and-gravatar-under-comment allows Cross Si…

Mitigation only
Fix from $1,950 2025-03-11
Delete Original Image HIGH 8.8
CVE-2025-28863

Cross-Site Request Forgery (CSRF) vulnerability in Carlos Minatti Delete Original Image delete-original-image allows Cross Site Request Forgery.This …

Fix: after 0.4
Fix from $1,950 2025-03-11
Builder For Contact Form 7 HIGH 8.8
CVE-2025-28864

Cross-Site Request Forgery (CSRF) vulnerability in planetstudio Builder for Contact Form 7 by Webconstruct cf7-builder allows Cross Site Request Forg…

Fix: after 1.2.2
Fix from $1,950 2025-03-11
Login Logger HIGH 8.8
CVE-2025-28866

Cross-Site Request Forgery (CSRF) vulnerability in smerriman Login Logger login-logger allows Cross Site Request Forgery.This issue affects Login Log…

Fix: after 1.2.1
Fix from $1,950 2025-03-11
W3counter HIGH 8.8
CVE-2025-28856

Cross-Site Request Forgery (CSRF) vulnerability in dangrossman W3Counter Free Real-Time Web Stats blog-stats-by-w3counter allows Cross Site Request F…

Fix: after 4.1
Fix from $1,950 2025-03-11
Rankchecker MEDIUM 6.1
CVE-2025-28857

Cross-Site Request Forgery (CSRF) vulnerability in rankchecker Rankchecker.io Integration rankchecker-io-integration allows Stored XSS.This issue aff…

Fix: after 1.0.9
Fix from $1,600 2025-03-11
Openmrs MEDIUM 6.8
CVE-2025-25927

A Cross-Site Request Forgery (CSRF) in Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary operations via a crafted GET request.

No fix yet
Fix from $1,600 2025-03-11
Openmrs HIGH 8.0
CVE-2025-25928

A Cross-Site Request Forgery (CSRF) in the component /admin/users/user.form of Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary opera…

No fix yet
Fix from $1,950 2025-03-11
Hoteldruid HIGH 7.3
CVE-2025-25748

A CSRF vulnerability in the gestione_utenti.php endpoint of HotelDruid 3.0.7 allows attackers to perform unauthorized actions (e.g., modifying user p…

Mitigation only
Fix from $1,950 2025-03-11
Fortindr HIGH 8.8
CVE-2023-48790

A cross site request forgery vulnerability [CWE-352] in Fortinet FortiNDR version 7.4.0, 7.2.0 through 7.2.1 and 7.1.0 through 7.1.1 and before 7.0.5…

Fix: 7.0.6 / 7.1.2+
Fix from $1,950 2025-03-11
Seq HIGH 8.8
CVE-2025-27912

An issue was discovered in Datalust Seq before 2024.3.13545. Missing Content-Type validation can lead to CSRF when (1) Entra ID or OpenID Connect aut…

Fix: 2024.3.13545+
Fix from $1,950 2025-03-11
Unclassified MEDIUM 6.1
CVE-2024-13436

The Appsero Helper plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.2. This is due to missi…

Mitigation only
Fix from $1,600 2025-03-11
Tianti HIGH 8.0
CVE-2025-27910

tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/upd/status. This vulnerability allows attacker…

No fix yet
Fix from $1,950 2025-03-10
Tianti HIGH 8.8
CVE-2025-25907

tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/save. This vulnerability allows attackers to e…

No fix yet
Fix from $1,950 2025-03-10
Wpbookit MEDIUM 6.1
CVE-2025-26910

Cross-Site Request Forgery (CSRF) vulnerability in Iqonic Design WPBookit wpbookit allows Stored XSS.This issue affects WPBookit: from n/a through <=…

Fix: 1.0.2+
Fix from $1,600 2025-03-10
Otrs MEDIUM 6.5
CVE-2025-24387

A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions. A req…

Fix: after 2025.1.2
Fix from $1,600 2025-03-10