Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Unclassified HIGH 7.1
CVE-2025-23455

Cross-Site Request Forgery (CSRF) vulnerability in Master Software Solutions WP VTiger Synchronization msstiger allows Stored XSS.This issue affects …

Mitigation only
Fix from $1,950 2025-01-16
Unclassified HIGH 7.1
CVE-2025-23456

Cross-Site Request Forgery (CSRF) vulnerability in Oddthinking EmailShroud emailshroud allows Reflected XSS.This issue affects EmailShroud: from n/a …

Mitigation only
Fix from $1,950 2025-01-16
Unclassified HIGH 7.1
CVE-2025-23463

Cross-Site Request Forgery (CSRF) vulnerability in Mukesh Dak MD Custom content after or before of post md-custom-content allows Stored XSS.This issu…

Mitigation only
Fix from $1,950 2025-01-16
Unclassified HIGH 7.1
CVE-2025-23467

Cross-Site Request Forgery (CSRF) vulnerability in vimal.ghorecha RSS News Scroller rss-news-scroller allows Stored XSS.This issue affects RSS News S…

Mitigation only
Fix from $1,950 2025-01-16
Unclassified HIGH 7.1
CVE-2025-23470

Cross-Site Request Forgery (CSRF) vulnerability in xavsio4 Visit Site Link enhanced visit-site-link-enhanced allows Stored XSS.This issue affects Vis…

Mitigation only
Fix from $1,950 2025-01-16
Unclassified HIGH 7.1
CVE-2025-23471

Cross-Site Request Forgery (CSRF) vulnerability in etemplates ECT Add to Cart Button ect-add-to-cart-button allows Stored XSS.This issue affects ECT …

Mitigation only
Fix from $1,950 2025-01-16
Unclassified HIGH 7.1
CVE-2025-23476

Cross-Site Request Forgery (CSRF) vulnerability in isnowfy my-related-posts my-related-posts allows Stored XSS.This issue affects my-related-posts: f…

Mitigation only
Fix from $1,950 2025-01-16
Unclassified HIGH 7.1
CVE-2025-23442

Cross-Site Request Forgery (CSRF) vulnerability in mschertel Shockingly Big IE6 Warning shockingly-big-ie6-warning allows Stored XSS.This issue affec…

Mitigation only
Fix from $1,950 2025-01-16
Unclassified HIGH 7.1
CVE-2025-23445

Cross-Site Request Forgery (CSRF) vulnerability in scottswezey Easy Tynt easy-tynt allows Cross Site Request Forgery.This issue affects Easy Tynt: fr…

Mitigation only
Fix from $1,950 2025-01-16
Unclassified HIGH 7.1
CVE-2025-23430

Cross-Site Request Forgery (CSRF) vulnerability in Oren Yomtov Mass Custom Fields Manager mass-custom-fields-manager allows Reflected XSS.This issue …

Mitigation only
Fix from $1,950 2025-01-16
Unclassified HIGH 7.1
CVE-2025-23435

Cross-Site Request Forgery (CSRF) vulnerability in marcucci Password Protect Plugin for WordPress password-protect-plugin-for-wordpress allows Stored…

Mitigation only
Fix from $1,950 2025-01-16
Unclassified HIGH 7.1
CVE-2025-23436

Cross-Site Request Forgery (CSRF) vulnerability in capa Wp-Scribd-List wp-scribd-list allows Stored XSS.This issue affects Wp-Scribd-List: from n/a t…

Mitigation only
Fix from $1,950 2025-01-16
Unclassified HIGH 7.1
CVE-2025-23424

Cross-Site Request Forgery (CSRF) vulnerability in bnovotny Marquee Style RSS News Ticker marquee-style-rss-news-ticker allows Cross Site Request For…

Mitigation only
Fix from $1,950 2025-01-16
Unclassified HIGH 7.1
CVE-2025-23426

Cross-Site Request Forgery (CSRF) vulnerability in Binesh Dobhal go Social go-social allows Stored XSS.This issue affects go Social: from n/a through…

Mitigation only
Fix from $1,950 2025-01-16
Unclassified HIGH 8.6
CVE-2025-22784

Cross-Site Request Forgery (CSRF) vulnerability in swedish boy Background Control background-control allows Path Traversal.This issue affects Backgro…

Mitigation only
Fix from $1,950 2025-01-15
Gestioip HIGH 8.8
CVE-2024-50858

Multiple endpoints in GestioIP v3.5.7 are vulnerable to Cross-Site Request Forgery (CSRF). An attacker can execute actions via the admin's browser by…

No fix yet
Fix from $1,950 2025-01-14
TYPO3 MEDIUM 5.4
CVE-2024-55922

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involvi…

Fix: 10.4.48 / 11.5.42+
Fix from $1,600 2025-01-14
TYPO3 HIGH 8.0
CVE-2024-55924

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involvi…

Fix: 11.5.42+
Fix from $1,950 2025-01-14
TYPO3 MEDIUM 6.5
CVE-2024-55945

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involvi…

Fix: 11.5.42+
Fix from $1,600 2025-01-14
TYPO3 MEDIUM 5.4
CVE-2024-55894

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involvi…

Fix: 10.4.48 / 11.5.42+
Fix from $1,600 2025-01-14
TYPO3 HIGH 8.8
CVE-2024-55921

TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involvi…

Fix: 10.4.48 / 11.5.42+
Fix from $1,950 2025-01-14
Windows Server 2016 MEDIUM 6.5
CVE-2025-21193

Active Directory Federation Server Spoofing Vulnerability

Fix: 10.0.14393.7699 / 10.0.17763.6775+
Fix from $1,600 2025-01-14
Unclassified MEDIUM 6.1
CVE-2025-23081

Cross-Site Request Forgery (CSRF), Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikim…

Mitigation only
Fix from $1,600 2025-01-14
Unclassified HIGH 7.1
CVE-2024-47100

A vulnerability has been identified in SIMATIC S7-1200 CPU 1211C AC/DC/Rly (6ES7211-1BE40-0XB0), SIMATIC S7-1200 CPU 1211C DC/DC/DC (6ES7211-1AE40-0X…

Mitigation only
Fix from $1,950 2025-01-14
Royal Elementor Addons MEDIUM 6.1
CVE-2025-0393

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1…

Fix: after 1.7.1006
Fix from $1,600 2025-01-14
Helpdeskadvanced MEDIUM 5.4
CVE-2023-42234

Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Request Forgery (CSRF) via the WSCView function.

Fix: after 11.0.33
Fix from $1,600 2025-01-13
Teedy HIGH 7.5
CVE-2025-22963

Teedy through 1.11 allows CSRF for account takeover via POST /api/user/admin.

Fix: after 1.11
Fix from $1,950 2025-01-13
Redcap HIGH 8.8
CVE-2025-23113

An issue was discovered in REDCap 14.9.6. It has an action=myprojects&logout=1 CSRF issue in the alert-title while performing an upload of a CSV file…

Mitigation only
Fix from $1,950 2025-01-10
Unclassified HIGH 8.7
CVE-2024-6662

Websites managed by MegaBIP in versions below 5.15 are vulnerable to Cross-Site Request Forgery (CSRF) as the form available under "/edytor/index.php…

Mitigation only
Fix from $1,950 2025-01-10
Gutenberg HIGH 8.8
CVE-2024-13284

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Gutenberg allows Cross Site Request Forgery.This issue affects Gutenberg: from 0.0.0 before…

Fix: 2.13.0 / 3.0.5+
Fix from $1,950 2025-01-09