Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Unclassified MEDIUM 5.4
CVE-2025-23985

Cross-Site Request Forgery (CSRF) vulnerability in brainvireinfo Dynamic URL SEO dynamic-url-seo allows Cross Site Request Forgery.This issue affects…

Mitigation only
Fix from $1,600 2025-01-31
Unclassified HIGH 7.1
CVE-2025-23989

Cross-Site Request Forgery (CSRF) vulnerability in Alessandro Piconi Internal Link Builder internal-link-builder allows Cross Site Request Forgery.Th…

Mitigation only
Fix from $1,950 2025-01-31
Unclassified HIGH 7.1
CVE-2025-23990

Cross-Site Request Forgery (CSRF) vulnerability in jablonczay Scroll Styler scroll-styler.This issue affects Scroll Styler: from n/a through <= 1.1.

Mitigation only
Fix from $1,950 2025-01-31
Unclassified HIGH 7.1
CVE-2025-23976

Cross-Site Request Forgery (CSRF) vulnerability in operationsissuu Issuu Panel issuu-panel allows Stored XSS.This issue affects Issuu Panel: from n/a…

Mitigation only
Fix from $1,950 2025-01-31
Unclassified HIGH 7.1
CVE-2025-23977

Cross-Site Request Forgery (CSRF) vulnerability in Bhaskar Dhote Post Carousel Slider post-carousel-slider allows Stored XSS.This issue affects Post …

Mitigation only
Fix from $1,950 2025-01-31
Unclassified HIGH 7.1
CVE-2025-23978

Cross-Site Request Forgery (CSRF) vulnerability in Ninos FlashCounter flashcounter allows Stored XSS.This issue affects FlashCounter: from n/a throug…

Mitigation only
Fix from $1,950 2025-01-31
Unclassified HIGH 7.1
CVE-2025-23980

Cross-Site Request Forgery (CSRF) vulnerability in James Andrews Full Circle full-circle allows Stored XSS.This issue affects Full Circle: from n/a t…

Mitigation only
Fix from $1,950 2025-01-31
GitLab HIGH 8.8
CVE-2024-1211

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.6 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and sta…

Fix: 16.9.7 / 16.10.5+
Fix from $1,950 2025-01-31
Wp Image Uploader HIGH 8.1
CVE-2024-13707

The WP Image Uploader plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to mi…

Fix: after 1.0.1
Fix from $1,950 2025-01-30
Wp Image Uploader CRITICAL 9.1
CVE-2024-13720

The WP Image Uploader plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the gky_image_uploade…

Fix: after 1.0.1
Fix from $2,300 2025-01-30
Wonder Fontawesome MEDIUM 5.4
CVE-2024-13512

The Wonder FontAwesome plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.8. This is due to mis…

Fix: after 0.8
Fix from $1,600 2025-01-30
Cp Contact Form MEDIUM 6.5
CVE-2024-13758

The CP Contact Form with PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.52. This i…

Fix: 1.3.53+
Fix from $1,600 2025-01-30
Teedy HIGH 8.8
CVE-2024-54851

Teedy <= 1.12 is vulnerable to Cross Site Request Forgery (CSRF), due to the lack of CSRF protection.

Fix: after 1.12
Fix from $1,950 2025-01-29
Mailup Auto Subscription MEDIUM 5.4
CVE-2024-13521

The MailUp Auto Subscription plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is du…

Fix: 1.2.0+
Fix from $1,600 2025-01-28
Unclassified HIGH 8.1
CVE-2024-57373

Cross Site Request Forgery (CSRF) vulnerability in LifestyleStore v1.0 allows a remote attacker to execute unauthorized actions on behalf of an authe…

Mitigation only
Fix from $1,950 2025-01-27
Br 6476ac Firmware HIGH 8.8
CVE-2024-48418

In Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06, the request /goform/fromSetDDNS does not properly handle special characters in any of user …

No fix yet
Fix from $1,950 2025-01-27
Wp Go Maps HIGH 8.8
CVE-2025-24742

Cross-Site Request Forgery (CSRF) vulnerability in WPGMaps WP Go Maps wp-google-maps.This issue affects WP Go Maps: from n/a through <= 9.0.40.

Fix: 9.0.41+
Fix from $1,950 2025-01-27
Unclassified MEDIUM 5.4
CVE-2025-24537

Cross-Site Request Forgery (CSRF) vulnerability in StellarWP The Events Calendar the-events-calendar allows Cross Site Request Forgery.This issue aff…

Mitigation only
Fix from $1,600 2025-01-27
Unclassified MEDIUM 5.4
CVE-2025-24538

Cross-Site Request Forgery (CSRF) vulnerability in Slava Abakumov BuddyPress Groups Extras buddypress-groups-extras allows Cross Site Request Forgery…

Mitigation only
Fix from $1,600 2025-01-27
Unclassified MEDIUM 5.4
CVE-2025-24533

Cross-Site Request Forgery (CSRF) vulnerability in MetaSlider Responsive Slider by MetaSlider ml-slider allows Cross Site Request Forgery.This issue …

Mitigation only
Fix from $1,600 2025-01-27
Dyn Business Panel HIGH 7.1
CVE-2024-13057

The Dyn Business Panel WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which…

No fix yet
Fix from $1,950 2025-01-27
Altra Side Menu MEDIUM 6.5
CVE-2024-12774

The Altra Side Menu WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins delet…

Fix: after 2.0
Fix from $1,600 2025-01-27
Vikbooking Hotel Booking Engine \& Pms HIGH 8.8
CVE-2024-11641

The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.…

Fix: 1.7.3+
Fix from $1,950 2025-01-26
Unclassified HIGH 7.1
CVE-2025-24756

Cross-Site Request Forgery (CSRF) vulnerability in mgplugin Roi Calculator roi-calculator allows Stored XSS.This issue affects Roi Calculator: from n…

Mitigation only
Fix from $1,950 2025-01-24
Unclassified MEDIUM 5.4
CVE-2025-24724

Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Side Menu Lite side-menu-lite allows Cross Site Request Forgery.This issue affects Sid…

Mitigation only
Fix from $1,600 2025-01-24
Unclassified MEDIUM 5.4
CVE-2025-24716

Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Herd Effects mwp-herd-effect allows Cross Site Request Forgery.This issue affects Herd…

Mitigation only
Fix from $1,600 2025-01-24
Modal Window HIGH 8.8
CVE-2025-24717

Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Modal Window modal-window allows Cross Site Request Forgery.This issue affects Modal W…

Fix: 6.1.5+
Fix from $1,950 2025-01-24
Unclassified MEDIUM 5.4
CVE-2025-24720

Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Sticky Buttons sticky-buttons allows Cross Site Request Forgery.This issue affects Sti…

Mitigation only
Fix from $1,600 2025-01-24
Unclassified MEDIUM 5.4
CVE-2025-24711

Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Popup Box popup-box allows Cross Site Request Forgery.This issue affects Popup Box: fr…

Mitigation only
Fix from $1,600 2025-01-24
Unclassified MEDIUM 5.4
CVE-2025-24712

Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme Radius Blocks radius-blocks allows Cross Site Request Forgery.This issue affects Radiu…

Mitigation only
Fix from $1,600 2025-01-24