Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Contact Us MEDIUM 6.1
CVE-2025-1382

The Contact Us By Lord Linus WordPress plugin through 2.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, w…

Fix: after 2.6
Fix from $1,600 2025-03-09
Vikrentcar HIGH 8.8
CVE-2024-11640

The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.…

Fix: 1.4.3+
Fix from $1,950 2025-03-08
Email Keep MEDIUM 5.4
CVE-2024-13826

The Email Keep WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logge…

Fix: after 1.1
Fix from $1,600 2025-03-08
Wishlist For Woocommerce MEDIUM 6.5
CVE-2024-13774

The Wishlist for WooCommerce: Multi Wishlists Per Customer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an…

Fix: 3.1.8+
Fix from $1,600 2025-03-08
Unclassified MEDIUM 6.1
CVE-2024-12634

The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress is vulnerable to Cross-Site Re…

Mitigation only
Fix from $1,600 2025-03-07
Student Manage MEDIUM 6.5
CVE-2025-2042

A vulnerability has been found in huang-yk student-manage 1.0 and classified as problematic. This vulnerability affects unknown code. The manipulatio…

Mitigation only
Fix from $1,600 2025-03-06
Jenkins MEDIUM 5.4
CVE-2025-27624

A cross-site request forgery (CSRF) vulnerability in Jenkins 2.499 and earlier, LTS 2.492.1 and earlier allows attackers to have users toggle their c…

Fix: 2.492.2 / 2.500+
Fix from $1,600 2025-03-05
Unclassified HIGH 8.8
CVE-2024-51144

Cross Site Request Forgery (CSRF) vulnerability exists in the 'pvmsg.php?action=add_message', pvmsg.php?action=confirm_delete , and ajax.server.php?p…

Mitigation only
Fix from $1,950 2025-03-05
Unclassified MEDIUM 6.3
CVE-2025-1435

The bbPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.11. This is due to missing or …

Mitigation only
Fix from $1,600 2025-03-05
Vasion Print HIGH 8.8
CVE-2025-27664

Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Insufficient CSRF Protection OVE-20230524-00…

Fix: 20.0.1923 / 22.0.843+
Fix from $1,950 2025-03-05
Tripleplay HIGH 7.1
CVE-2024-50705

Unauthenticated reflected cross-site scripting (XSS) vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary …

Fix: 24.1.2+
Fix from $1,950 2025-03-04
Newscrunch HIGH 8.8
CVE-2025-1306

The Newscrunch theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.4. This is due to missing or…

Fix: 1.8.4.1+
Fix from $1,950 2025-03-04
Acora Cms HIGH 8.8
CVE-2025-25967

Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF). This flaw enables attackers to trick authenticated users into performing…

Mitigation only
Fix from $1,950 2025-03-03
Storefront CRITICAL 9.0
CVE-2025-26206

Cross Site Request Forgery vulnerability in sell done storefront v.1.0 allows a remote attacker to escalate privileges via the index.html component

No fix yet
Fix from $2,300 2025-03-03
Hcl Sx MEDIUM 5.7
CVE-2024-30154

HCL SX is vulnerable to cross-site request forgery vulnerability which could allow an attacker to execute malicious and unauthorized actions transmit…

Mitigation only
Fix from $1,600 2025-03-03
Unclassified MEDIUM 6.5
CVE-2025-25137

Cross-Site Request Forgery (CSRF) vulnerability in kareemsultan Social Links social-links allows Cross Site Request Forgery. This issue affects Soci…

Mitigation only
Fix from $1,600 2025-03-03
Unclassified HIGH 7.1
CVE-2025-25121

Cross-Site Request Forgery (CSRF) vulnerability in shyammakwana Theme Options Z theme-options-z allows Cross Site Request Forgery.This issue affects …

Mitigation only
Fix from $1,950 2025-03-03
Unclassified HIGH 7.1
CVE-2025-23502

Cross-Site Request Forgery (CSRF) vulnerability in Ned Curated Search curated-search allows Stored XSS.This issue affects Curated Search: from n/a th…

Mitigation only
Fix from $1,950 2025-03-03
Unclassified HIGH 7.1
CVE-2025-23446

Cross-Site Request Forgery (CSRF) vulnerability in KokoenDE WP SpaceContent wp-spacecontent allows Stored XSS.This issue affects WP SpaceContent: fro…

Mitigation only
Fix from $1,950 2025-03-03
Unclassified MEDIUM 5.4
CVE-2025-27579

In Bitaxe ESP-Miner before 2.5.0 with AxeOS, one can use an /api/system CSRF attack to update the payout address (aka stratumUser) for a Bitaxe Bitco…

Patch available
Fix from $1,600 2025-03-03
Zz MEDIUM 6.5
CVE-2025-1813

A vulnerability classified as problematic was found in zj1983 zz up to 2024-08. Affected by this vulnerability is an unknown functionality. The manip…

Fix: after 2024-8
Fix from $1,600 2025-03-02
07flycms CRITICAL 9.6
CVE-2025-25379

Cross Site Request Forgery vulnerability in 07FLYCMS v.1.3.9 allows a remote attacker to execute arbitrary code via the id parameter of the del.html …

Mitigation only
Fix from $2,300 2025-02-28
Unclassified HIGH 8.8
CVE-2025-1687

The Cardealer theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.4. This is due to missing nonce v…

Mitigation only
Fix from $1,950 2025-02-28
Enterprise Integrator MEDIUM 5.4
CVE-2024-0392

A Cross-Site Request Forgery (CSRF) vulnerability exists in the management console of WSO2 Enterprise Integrator 6.6.0 due to the absence of CSRF tok…

Mitigation only
Fix from $1,600 2025-02-27
Clickwhale HIGH 8.8
CVE-2025-26963

Cross-Site Request Forgery (CSRF) vulnerability in ClickWhale ClickWhale clickwhale allows Cross Site Request Forgery.This issue affects ClickWhale: …

Fix: 2.4.4+
Fix from $1,950 2025-02-25
Unclassified HIGH 7.1
CVE-2025-26931

Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Software Tribulant Gallery Voting gallery-voting allows Stored XSS.This issue affects Tr…

Mitigation only
Fix from $1,950 2025-02-25
Modernanet MEDIUM 6.5
CVE-2025-1644

A vulnerability classified as problematic has been found in Benner ModernaNet up to 1.2.0. Affected is an unknown function of the file /DadosPessoais…

Fix: 1.2.1+
Fix from $1,600 2025-02-25
Modernanet HIGH 8.8
CVE-2025-1643

A vulnerability was found in Benner ModernaNet up to 1.1.0. It has been rated as problematic. This issue affects some unknown processing of the file …

Fix: 1.1.1+
Fix from $1,950 2025-02-25
Unclassified HIGH 7.1
CVE-2025-27355

Cross-Site Request Forgery (CSRF) vulnerability in Nicolas GRILLET Woocommerce – Loi Hamon loi-hamon allows Stored XSS.This issue affects Woocommerce…

Mitigation only
Fix from $1,950 2025-02-24
Unclassified MEDIUM 5.4
CVE-2025-27340

Cross-Site Request Forgery (CSRF) vulnerability in Forge12 Interactive GmbH F12-Profiler f12-profiler allows Cross Site Request Forgery.This issue af…

Mitigation only
Fix from $1,600 2025-02-24