Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Unclassified HIGH 7.1
CVE-2025-27332

Cross-Site Request Forgery (CSRF) vulnerability in gmnazmul Smart Maintenance & Countdown smart-maintenance-countdown allows Stored XSS.This issue af…

Mitigation only
Fix from $1,950 2025-02-24
Unclassified HIGH 7.1
CVE-2025-27321

Cross-Site Request Forgery (CSRF) vulnerability in Blighty Blightly Explorer blighty-explorer allows Stored XSS.This issue affects Blightly Explorer:…

Mitigation only
Fix from $1,950 2025-02-24
Unclassified HIGH 8.3
CVE-2025-27298

Cross-Site Request Forgery (CSRF) vulnerability in cmstactics WP Video Posts wp-video-posts allows OS Command Injection.This issue affects WP Video P…

Mitigation only
Fix from $1,950 2025-02-24
Unclassified HIGH 8.8
CVE-2025-27276

Cross-Site Request Forgery (CSRF) vulnerability in lizeipe Photo Gallery ( Responsive ) photo-gallery-pearlbells allows Privilege Escalation.This iss…

Mitigation only
Fix from $1,950 2025-02-24
Unclassified HIGH 7.1
CVE-2025-27277

Cross-Site Request Forgery (CSRF) vulnerability in tiefpunkt Add Linked Images To Gallery add-linked-images-to-gallery-v01 allows Cross Site Request …

Mitigation only
Fix from $1,950 2025-02-24
Unclassified HIGH 8.8
CVE-2025-27012

Cross-Site Request Forgery (CSRF) vulnerability in a1post A1POST.BG Shipping for Woo a1post-bg-shipping-for-woocommerce allows Privilege Escalation.T…

Mitigation only
Fix from $1,950 2025-02-22
Wangmarket HIGH 8.0
CVE-2025-25769

Wangmarket v4.10 to v5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /controller/UserController.java.

Fix: after 5.0
Fix from $1,950 2025-02-21
Wangmarket MEDIUM 6.8
CVE-2025-25770

Wangmarket v4.10 to v5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /agency/AgencyUserController.java.

Fix: after 5.0
Fix from $1,600 2025-02-21
Jspxcms MEDIUM 5.1
CVE-2025-25772

A Cross-Site Request Forgery (CSRF) in the component /back/UserController.java of Jspxcms v9.0 to v9.5 allows attackers to arbitrarily add Administra…

Fix: after 9.5.0
Fix from $1,600 2025-02-21
Unclassified MEDIUM 5.9
CVE-2024-7141

Versions of Gliffy Online prior to versions 4.14.0-7 contains a Cross Site Request Forgery (CSRF) flaw.

Mitigation only
Fix from $1,600 2025-02-20
Openpages With Watson HIGH 8.8
CVE-2024-49779

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to bypass security restrictions, caused by improper validation an…

Fix: 8.3.0.3 / 9.0.0.5+
Fix from $1,950 2025-02-20
Ultimate Classified Listings HIGH 8.8
CVE-2024-13753

The Ultimate Classified Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is …

Fix: after 1.4
Fix from $1,950 2025-02-20
Unclassified HIGH 8.1
CVE-2020-10095

Various Lexmark devices have CSRF that allows an attacker to modify the configuration of the device.

Mitigation only
Fix from $1,950 2025-02-19
Email Validator MEDIUM 5.4
CVE-2024-13339

The DeBounce Email Validator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.8.0. This is du…

Fix: after 5.6.6
Fix from $1,600 2025-02-19
Wp Media Category Management MEDIUM 6.5
CVE-2025-0865

The WP Media Category Management plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.0 to 2.3.3. This is due to missing or…

Fix: 2.4.0+
Fix from $1,600 2025-02-19
Royal Elementor Addons HIGH 8.8
CVE-2025-1441

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1…

Fix: after 1.7.1007
Fix from $1,950 2025-02-19
Memorialday MEDIUM 5.4
CVE-2024-13523

The MemorialDay plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. This is due to missing …

Fix: 1.1.0+
Fix from $1,600 2025-02-18
Shopwarden HIGH 8.8
CVE-2024-13315

The Shopwarden – Automated WooCommerce monitoring & testing plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a…

Fix: 1.0.12+
Fix from $1,950 2025-02-18
Option Editor HIGH 8.8
CVE-2024-13852

The Option Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing nonce validation on the plu…

Fix: after 1.0
Fix from $1,950 2025-02-18
Reset HIGH 8.1
CVE-2024-13684

The Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6. This is due to missing or incor…

Fix: after 1.6
Fix from $1,950 2025-02-18
Magayo Lottery Results MEDIUM 5.4
CVE-2024-13522

The magayo Lottery Results plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.12. This is due…

Fix: after 2.0.12
Fix from $1,600 2025-02-18
Unclassified HIGH 7.1
CVE-2025-26768

Cross-Site Request Forgery (CSRF) vulnerability in what3words what3words Address Field 3-word-address-validation-field allows Stored XSS.This issue a…

Mitigation only
Fix from $1,950 2025-02-16
Unclassified HIGH 7.1
CVE-2025-26759

Cross-Site Request Forgery (CSRF) vulnerability in alexvtn Content Snippet Manager content-snippet-manager allows Stored XSS.This issue affects Conte…

Mitigation only
Fix from $1,950 2025-02-16
Unclassified HIGH 7.1
CVE-2025-24699

Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company WP Coder wp-coder allows Cross-Site Scripting (XSS).This issue affects WP Coder: from …

Mitigation only
Fix from $1,950 2025-02-14
Unclassified HIGH 7.1
CVE-2025-22705

Cross-Site Request Forgery (CSRF) vulnerability in godthor Disqus Popular Posts disqus-popular-posts allows Reflected XSS.This issue affects Disqus P…

Mitigation only
Fix from $1,950 2025-02-14
Mypro MEDIUM 6.5
CVE-2025-23411

mySCADA myPRO Manager is vulnerable to cross-site request forgery (CSRF), which could allow an attacker to obtain sensitive information. An attacke…

Fix: 1.4+
Fix from $1,600 2025-02-13
Unclassified HIGH 7.1
CVE-2025-26580

Cross-Site Request Forgery (CSRF) vulnerability in Complete SEO Page/Post Specific Social Share Buttons pagepost-specific-social-share-buttons allows…

Mitigation only
Fix from $1,950 2025-02-13
Unclassified HIGH 7.1
CVE-2025-26582

Cross-Site Request Forgery (CSRF) vulnerability in Blackbam TinyMCE Advanced qTranslate fix editor problems tinymce-advanced-qtranslate-fix-editor-pr…

Mitigation only
Fix from $1,950 2025-02-13
Unclassified HIGH 7.1
CVE-2025-26569

Cross-Site Request Forgery (CSRF) vulnerability in Callmeforsox Post Thumbs allows Stored XSS. This issue affects Post Thumbs: from n/a through 1.5.

Mitigation only
Fix from $1,950 2025-02-13
Unclassified HIGH 7.1
CVE-2025-26570

Cross-Site Request Forgery (CSRF) vulnerability in uamv Glance That allows Cross Site Request Forgery. This issue affects Glance That: from n/a thro…

No fix yet
Fix from $1,950 2025-02-13