Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Unclassified MEDIUM 5.4
CVE-2025-24713

Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Button Generator – easily Button Builder button-generation allows Cross Site Request F…

Mitigation only
Fix from $1,600 2025-01-24
Unclassified MEDIUM 5.4
CVE-2025-24714

Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Bubble Menu – circle floating menu bubble-menu allows Cross Site Request Forgery.This …

Mitigation only
Fix from $1,600 2025-01-24
Counter Box MEDIUM 5.4
CVE-2025-24715

Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Counter Box counter-box allows Cross Site Request Forgery.This issue affects Counter B…

Fix: 2.0.6+
Fix from $1,600 2025-01-24
Unclassified MEDIUM 5.4
CVE-2025-24647

Cross-Site Request Forgery (CSRF) vulnerability in datafeedr WooCommerce Cloak Affiliate Links woocommerce-cloak-affiliate-links allows Cross Site Re…

Mitigation only
Fix from $1,600 2025-01-24
Unclassified HIGH 7.1
CVE-2025-24636

Cross-Site Request Forgery (CSRF) vulnerability in Rick Laymance MachForm Shortcode machform-shortcode allows Stored XSS.This issue affects MachForm …

Mitigation only
Fix from $1,950 2025-01-24
Unclassified MEDIUM 5.4
CVE-2025-24622

Cross-Site Request Forgery (CSRF) vulnerability in PickPlugins Job Board Manager job-board-manager allows Cross Site Request Forgery.This issue affec…

Mitigation only
Fix from $1,600 2025-01-24
Unclassified MEDIUM 6.5
CVE-2025-24572

Cross-Site Request Forgery (CSRF) vulnerability in Epsiloncool WP Fast Total Search fulltext-search allows Cross Site Request Forgery.This issue affe…

Mitigation only
Fix from $1,600 2025-01-24
Unclassified HIGH 7.1
CVE-2025-24555

Cross-Site Request Forgery (CSRF) vulnerability in subscriptiondna Subscription DNA subscriptiondna allows Stored XSS.This issue affects Subscription…

Mitigation only
Fix from $1,950 2025-01-24
Unclassified HIGH 7.1
CVE-2025-24561

Cross-Site Request Forgery (CSRF) vulnerability in awcode ReviewsTap reviewstap allows Stored XSS.This issue affects ReviewsTap: from n/a through <= …

Mitigation only
Fix from $1,950 2025-01-24
Unclassified HIGH 7.1
CVE-2025-24562

Cross-Site Request Forgery (CSRF) vulnerability in Optimal Access KBucket kbucket allows Stored XSS.This issue affects KBucket: from n/a through <= 4…

Mitigation only
Fix from $1,950 2025-01-24
Ultimate Coming Soon \& Maintenance MEDIUM 5.4
CVE-2025-24546

Cross-Site Request Forgery (CSRF) vulnerability in RSTheme Ultimate Coming Soon & Maintenance ultimate-coming-soon allows Cross Site Request Forgery.…

Fix: 1.1.0+
Fix from $1,600 2025-01-24
Unclassified HIGH 7.1
CVE-2025-22768

Cross-Site Request Forgery (CSRF) vulnerability in JinHan Park Rocket Media Library Mime Type rocket-media-library-mime-type allows Stored XSS.This i…

Mitigation only
Fix from $1,950 2025-01-23
Internet Banking System HIGH 7.3
CVE-2024-56924

A Cross Site Request Forgery (CSRF) vulnerability in Code Astro Internet banking system 2.0.0 allows remote attackers to execute arbitrary JavaScript…

No fix yet
Fix from $1,950 2025-01-22
Bitbucket Server Integration HIGH 8.8
CVE-2025-24398

Jenkins Bitbucket Server Integration Plugin 2.1.0 through 4.1.3 (both inclusive) allows attackers to craft URLs that would bypass the CSRF protection…

Fix: 4.1.4+
Fix from $1,950 2025-01-22
Unclassified HIGH 7.1
CVE-2025-23803

Cross-Site Request Forgery (CSRF) vulnerability in Rik Schennink Snippy snippy allows Reflected XSS.This issue affects Snippy: from n/a through <= 1.…

Mitigation only
Fix from $1,950 2025-01-22
Unclassified HIGH 7.1
CVE-2025-23806

Cross-Site Request Forgery (CSRF) vulnerability in ThemeFarmer Ultimate Subscribe ultimate-subscribe allows Reflected XSS.This issue affects Ultimate…

Mitigation only
Fix from $1,950 2025-01-22
Financial Services Behavior Detection Platform MEDIUM 6.1
CVE-2025-21550

Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Web UI). Su…

Mitigation only
Fix from $1,600 2025-01-21
Jd Edwards Enterpriseone Tools MEDIUM 6.1
CVE-2025-21538

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected …

Fix: 9.2.9.2+
Fix from $1,600 2025-01-21
Primavera P6 Enterprise Project Portfolio Management MEDIUM 5.4
CVE-2025-21526

Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access). Su…

Fix: after 23.12.10.0
Fix from $1,600 2025-01-21
Jd Edwards Enterpriseone Tools MEDIUM 6.1
CVE-2025-21513

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected …

Fix: 9.2.9.0+
Fix from $1,600 2025-01-21
Jd Edwards Enterpriseone Tools MEDIUM 5.4
CVE-2025-21507

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected …

Fix: 9.2.9.0+
Fix from $1,600 2025-01-21
E Business Suite MEDIUM 6.1
CVE-2025-21489

Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Region Mapping). Supported versions that are …

Fix: after 12.2.10
Fix from $1,600 2025-01-21
Spagobi MEDIUM 6.1
CVE-2024-54792

A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel. An authenticated user can lead a…

No fix yet
Fix from $1,600 2025-01-21
Codechecker HIGH 8.2
CVE-2024-53829

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Cross-site request forgery al…

Fix: 6.24.5+
Fix from $1,950 2025-01-21
Unclassified HIGH 7.1
CVE-2025-24001

Cross-Site Request Forgery (CSRF) vulnerability in Ngô Thắng IT PPO Call To Actions ppo-call-to-actions allows Cross Site Request Forgery.This issue …

Mitigation only
Fix from $1,950 2025-01-21
Unclassified MEDIUM 6.1
CVE-2024-13444

The wp-greet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2. This is due to missing or in…

Mitigation only
Fix from $1,600 2025-01-21
Wp Bibtex MEDIUM 6.1
CVE-2024-12005

The WP-BibTeX plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1. This is due to missing or…

Fix: 3.0.2+
Fix from $1,600 2025-01-21
Pwndoc HIGH 8.1
CVE-2025-23044

PwnDoc is a penetration test report generator. There is no CSRF protection in pwndoc, allowing attackers to send requests on a logged-in user's behal…

Fix: 0.9.0+
Fix from $1,950 2025-01-20
Unclassified MEDIUM 6.1
CVE-2024-13432

The Webcamconsult plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.0. This is due to missin…

Mitigation only
Fix from $1,600 2025-01-18
Wp Abstracts MEDIUM 6.1
CVE-2024-12385

The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.2. This is due to missing…

Fix: 2.7.3+
Fix from $1,600 2025-01-18