Vulnerability index

Browse CVEs

7,362 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Unclassified CRITICAL 9.1
CVE-2026-26718

A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an attacker to perform unauthorized…

Mitigation only
Fix from $2,300 2026-07-15
Splunk HIGH 8.3
CVE-2026-20296

In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.7, 10.3.2512.…

Fix: 9.4.13 / 10.0.8+
Fix from $1,950 2026-07-15
Unclassified HIGH 8.3
CVE-2026-47158

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO authorization flow did not bind the OAuth state para…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified HIGH 7.5
CVE-2026-52100

Cross Site Request Forgery vulnerability in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to execute arbitrary code via the…

Mitigation only
Fix from $1,950 2026-07-14
Unclassified CRITICAL 9.1
CVE-2026-15747

Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle. _csrf_t…

Mitigation only
Fix from $2,300 2026-07-14
Sustainable Irrigation Platform HIGH 8.1
CVE-2026-58476

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a cross-site request forgery vulnerability that allows remote attackers to perf…

Fix: after 5.2.16
Fix from $1,950 2026-07-14
Unclassified MEDIUM 6.8
CVE-2026-58489

HedgeDoc is an open source, real-time collaborative markdown notes application. Prior to 1.11.0, the GitHub Gist export flow created an OAuth2  state…

Patch available
Fix from $1,600 2026-07-13
Unclassified HIGH 7.1
CVE-2026-61956

Cross-Site Request Forgery (CSRF) vulnerability in hamsalam ووسلام – همگام سازی ووکامرس و باسلام sync-basalam allows Cross Site Request Forgery…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified HIGH 8.8
CVE-2026-57786

Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core workscout-core allows Authentication Bypass.This issue affects WorkScout…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified HIGH 8.1
CVE-2026-38057

The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests …

Mitigation only
Fix from $1,950 2026-07-10
Unclassified HIGH 8.8
CVE-2026-15070

The Salon Booking System – Free Version plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 10.30.…

Mitigation only
Fix from $1,950 2026-07-10
New Api MEDIUM 5.3
CVE-2026-44342

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the email and WeCha…

Fix: 0.12.0+
Fix from $1,600 2026-07-09
Unclassified HIGH 8.8
CVE-2026-58143

Cotonti Siena 0.9.26 and earlier contains a cross-site request forgery vulnerability that allows unauthenticated attackers to modify administrator co…

Mitigation only
Fix from $1,950 2026-07-09
Unclassified HIGH 8.8
CVE-2026-59148

Mockoon provides way to design and run mock APIs. Prior to 9.7.0, Mockoon's admin API in commons-server/src/libs/server/admin-api.ts is mounted on th…

Patch available
Fix from $1,950 2026-07-09
Unclassified HIGH 8.8
CVE-2026-4275

The Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,…

Mitigation only
Fix from $1,950 2026-07-09
Unclassified MEDIUM 6.0
CVE-2026-5923

Malicious use of a stolen cookie might allow modifications to the contents of the IP phone’s webpage.

No fix yet
Fix from $1,600 2026-07-08
Serena HIGH 8.3
CVE-2026-49471

Serena is a powerful MCP toolkit for coding that provides semantic retrieval and editing capabilities. Prior to v1.5.2, Serena's built-in web dashboa…

Fix: 1.5.2+
Fix from $1,950 2026-07-07
Unclassified HIGH 8.0
CVE-2026-34171

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the GET /invitations/{uu…

Patch available
Fix from $1,950 2026-07-07
Unclassified HIGH 8.1
CVE-2026-59713

Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without validating state parameters.…

Patch available
Fix from $1,950 2026-07-06
Unclassified HIGH 8.1
CVE-2026-12740

Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter. RequestTokenV2 builds the provider authorizati…

Patch available
Fix from $1,950 2026-07-04
Unclassified HIGH 8.1
CVE-2026-12746

Dancer2::Plugin::Auth::OAuth::Provider versions before 0.23 for Perl do not support the OAuth 2.0 state parameter. The authentication_url method bui…

Patch available
Fix from $1,950 2026-07-04
Unclassified HIGH 7.1
CVE-2026-57761

Unauthenticated Cross Site Request Forgery (CSRF) in SEOWP <= 3.12.2 versions.

Mitigation only
Fix from $1,950 2026-07-02
Unclassified HIGH 8.8
CVE-2026-57766

Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor <= 3.5.6 versions.

Mitigation only
Fix from $1,950 2026-07-02
Unclassified HIGH 7.1
CVE-2026-57757

Unauthenticated Cross Site Request Forgery (CSRF) in pCloud WP Backup <= 2.0.2 versions.

Mitigation only
Fix from $1,950 2026-07-02
Unclassified HIGH 7.1
CVE-2026-57758

Unauthenticated Cross Site Request Forgery (CSRF) in Permalink Manager for WooCommerce <= 1.0.8.2 versions.

Mitigation only
Fix from $1,950 2026-07-02
Unclassified HIGH 8.8
CVE-2026-57759

Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid <= 5.9.9.7 versions.

Mitigation only
Fix from $1,950 2026-07-02
Unclassified MEDIUM 6.5
CVE-2026-57747

Unauthenticated Cross Site Request Forgery (CSRF) in Booked <= 3.0.0 versions.

Mitigation only
Fix from $1,600 2026-07-02
Unclassified HIGH 8.1
CVE-2026-57751

Unauthenticated Cross Site Request Forgery (CSRF) in Heateor Social Login <= 1.1.39 versions.

Mitigation only
Fix from $1,950 2026-07-02
Unclassified HIGH 7.4
CVE-2026-57723

Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Path Traversal. This issue affects VikBooki…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified HIGH 8.8
CVE-2026-12158

The RegistrationMagic – User Registration Forms Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in…

Mitigation only
Fix from $1,950 2026-07-01