Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Unclassified HIGH 7.1
CVE-2025-26571

Cross-Site Request Forgery (CSRF) vulnerability in wibiya Wibiya Toolbar wibiya allows Cross Site Request Forgery.This issue affects Wibiya Toolbar: …

Mitigation only
Fix from $1,950 2025-02-13
Unclassified HIGH 7.1
CVE-2025-26572

Cross-Site Request Forgery (CSRF) vulnerability in jesseheap WP PHPList phplist-form-integration allows Cross Site Request Forgery.This issue affects…

Mitigation only
Fix from $1,950 2025-02-13
Unclassified HIGH 7.1
CVE-2025-26577

Cross-Site Request Forgery (CSRF) vulnerability in daxiawp DX-auto-publish dx-auto-publish allows Stored XSS.This issue affects DX-auto-publish: from…

Mitigation only
Fix from $1,950 2025-02-13
Unclassified HIGH 7.1
CVE-2025-26578

Cross-Site Request Forgery (CSRF) vulnerability in mathieuhays Simple Documentation client-documentation allows Stored XSS.This issue affects Simple …

Mitigation only
Fix from $1,950 2025-02-13
Unclassified HIGH 7.1
CVE-2025-26562

Cross-Site Request Forgery (CSRF) vulnerability in Shambhu Patnaik RSS Filter rss-filter allows Stored XSS.This issue affects RSS Filter: from n/a th…

Mitigation only
Fix from $1,950 2025-02-13
Unclassified HIGH 7.1
CVE-2025-26568

Cross-Site Request Forgery (CSRF) vulnerability in jensmueller Easy Amazon Product Information easy-amazon-product-information allows Stored XSS.This…

Mitigation only
Fix from $1,950 2025-02-13
Unclassified HIGH 7.1
CVE-2025-26545

Cross-Site Request Forgery (CSRF) vulnerability in shisuh Related Posts Line-up-Exactly by Milliard related-posts-line-up-exactry-by-milliard allows …

Mitigation only
Fix from $1,950 2025-02-13
Unclassified HIGH 7.1
CVE-2025-26547

Cross-Site Request Forgery (CSRF) vulnerability in nagarjunsonti My Login Logout Plugin my-loginlogout allows Stored XSS.This issue affects My Login …

Mitigation only
Fix from $1,950 2025-02-13
Unclassified HIGH 7.1
CVE-2025-26549

Cross-Site Request Forgery (CSRF) vulnerability in pa1 WP Html Page Sitemap wp-html-page-sitemap allows Stored XSS.This issue affects WP Html Page Si…

Mitigation only
Fix from $1,950 2025-02-13
Unclassified HIGH 7.1
CVE-2025-26550

Cross-Site Request Forgery (CSRF) vulnerability in Kunal Shivale Global Meta Keyword & Description global-meta-keyword-and-description allows Stored …

Mitigation only
Fix from $1,950 2025-02-13
Unclassified HIGH 7.1
CVE-2025-26543

Cross-Site Request Forgery (CSRF) vulnerability in Pukhraj Suthar Simple Responsive Menu simple-responsive-menu allows Stored XSS.This issue affects …

Mitigation only
Fix from $1,950 2025-02-13
Wp Abstracts MEDIUM 5.4
CVE-2024-12386

The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.3. This is due to missing…

Fix: 2.7.4+
Fix from $1,600 2025-02-12
Houzez Property Feed MEDIUM 5.4
CVE-2025-0808

The Houzez Property Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.21. This is due t…

Fix: 2.4.22+
Fix from $1,600 2025-02-12
Misskey HIGH 8.2
CVE-2025-24897

Misskey is an open source, federated social media platform. Starting in version 12.109.0 and prior to version 2025.2.0-alpha.0, due to a lack of CSRF…

Fix: 2025.2.0+
Fix from $1,950 2025-02-11
Unclassified HIGH 8.6
CVE-2025-24900

Concorde, formerly know as Nexkey, is a fork of the federated microblogging platform Misskey. Due to a lack of CSRF countermeasures and improper sett…

Patch available
Fix from $1,950 2025-02-11
Unclassified MEDIUM 6.8
CVE-2025-24875

SAP Commerce, by default, sets certain cookies with the SameSite attribute configured to None (SameSite=None). This includes authentication cookies u…

Mitigation only
Fix from $1,600 2025-02-11
Inlocation MEDIUM 6.1
CVE-2025-25166

Cross-Site Request Forgery (CSRF) vulnerability in gabrieldarezzo InLocation inlocation allows Stored XSS.This issue affects InLocation: from n/a thr…

Fix: after 1.8
Fix from $1,600 2025-02-07
Bookpress MEDIUM 6.1
CVE-2025-25168

Cross-Site Request Forgery (CSRF) vulnerability in Black and White BookPress – For Book Authors book-press allows Cross-Site Scripting (XSS).This iss…

Fix: after 1.2.7
Fix from $1,600 2025-02-07
Unclassified HIGH 7.1
CVE-2025-25154

Cross-Site Request Forgery (CSRF) vulnerability in scweber Custom Comment Notifications custom-comment-notifications allows Stored XSS.This issue aff…

Mitigation only
Fix from $1,950 2025-02-07
Unclassified HIGH 7.1
CVE-2025-25156

Cross-Site Request Forgery (CSRF) vulnerability in Stanko Metodiev Quote Comments quote-comments allows Stored XSS.This issue affects Quote Comments:…

Mitigation only
Fix from $1,950 2025-02-07
Style Tweaker MEDIUM 6.1
CVE-2025-25160

Cross-Site Request Forgery (CSRF) vulnerability in Mark Barnes Style Tweaker style-tweaker allows Stored XSS.This issue affects Style Tweaker: from n…

Fix: after 0.11
Fix from $1,600 2025-02-07
Unclassified HIGH 7.1
CVE-2025-25147

Cross-Site Request Forgery (CSRF) vulnerability in Phillip.Gooch Auto SEO auto-seo allows Stored XSS.This issue affects Auto SEO: from n/a through <=…

Mitigation only
Fix from $1,950 2025-02-07
Unclassified HIGH 7.1
CVE-2025-25148

Cross-Site Request Forgery (CSRF) vulnerability in ElbowRobo Read More Copy Link read-more-copy-link allows Stored XSS.This issue affects Read More C…

Mitigation only
Fix from $1,950 2025-02-07
Unclassified HIGH 7.1
CVE-2025-25149

Cross-Site Request Forgery (CSRF) vulnerability in Danillo Nunes Login-box login-box allows Stored XSS.This issue affects Login-box: from n/a through…

Mitigation only
Fix from $1,950 2025-02-07
Unclassified HIGH 7.1
CVE-2025-25152

Cross-Site Request Forgery (CSRF) vulnerability in LukaszWiecek Smart DoFollow smart-dofollow allows Stored XSS.This issue affects Smart DoFollow: fr…

Mitigation only
Fix from $1,950 2025-02-07
Unclassified HIGH 7.1
CVE-2025-25153

Cross-Site Request Forgery (CSRF) vulnerability in djjmz Simple Auto Tag simple-auto-tag allows Stored XSS.This issue affects Simple Auto Tag: from n…

Mitigation only
Fix from $1,950 2025-02-07
Unclassified HIGH 7.1
CVE-2025-25140

Cross-Site Request Forgery (CSRF) vulnerability in Scriptonite Simple User Profile simple-user-profile allows Stored XSS.This issue affects Simple Us…

Mitigation only
Fix from $1,950 2025-02-07
Unclassified MEDIUM 5.4
CVE-2025-25145

Cross-Site Request Forgery (CSRF) vulnerability in jordan.hatch Infusionsoft Analytics infusionsoft-web-tracker allows Cross Site Request Forgery.Thi…

Mitigation only
Fix from $1,600 2025-02-07
Unclassified HIGH 7.1
CVE-2025-25128

Cross-Site Request Forgery (CSRF) vulnerability in orlandolac Facilita Form Tracker facilita-form-tracker allows Stored XSS.This issue affects Facili…

Mitigation only
Fix from $1,950 2025-02-07
Unclassified HIGH 7.1
CVE-2025-25135

Cross-Site Request Forgery (CSRF) vulnerability in Victor Barkalov Custom Links On Admin Dashboard Toolbar customize-wpadmin allows Stored XSS.This i…

Mitigation only
Fix from $1,950 2025-02-07