Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Unclassified MEDIUM 6.1
CVE-2024-12557

The Transporters.io plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due to miss…

Mitigation only
Fix from $1,600 2025-01-07
Grocy HIGH 8.1
CVE-2024-55076

Grocy through 4.3.0 has no CSRF protection, as demonstrated by changing the Administrator's password.

Fix: after 4.3.0
Fix from $1,950 2025-01-06
Wp Social Autoconnect MEDIUM 6.1
CVE-2024-12279

The WP Social AutoConnect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6.2. This is due t…

Fix: 4.6.3+
Fix from $1,600 2025-01-04
Scratch \& Win MEDIUM 5.4
CVE-2024-12545

The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin for WordPress is vulnerable …

Fix: 2.8.0+
Fix from $1,600 2025-01-04
Unclassified MEDIUM 5.4
CVE-2024-37925

Cross-Site Request Forgery (CSRF) vulnerability in BUDDYBOSS LLC BuddyBoss Theme allows Cross Site Request Forgery.This issue affects BuddyBoss Theme…

Mitigation only
Fix from $1,600 2025-01-02
Unclassified MEDIUM 5.4
CVE-2024-37438

Cross-Site Request Forgery (CSRF) vulnerability in Uncanny Owl Uncanny Toolkit Pro for LearnDash allows Cross Site Request Forgery.This issue affects…

Mitigation only
Fix from $1,600 2025-01-02
Listingpro HIGH 8.8
CVE-2024-39623

Cross-Site Request Forgery (CSRF) vulnerability in CridioStudio ListingPro listingpro allows Authentication Bypass.This issue affects ListingPro: fro…

Fix: 2.9.5+
Fix from $1,950 2025-01-02
Unclassified MEDIUM 5.4
CVE-2024-38789

Cross-Site Request Forgery (CSRF) vulnerability in Marco Milesi Telegram Bot & Channel telegram-bot allows Cross Site Request Forgery.This issue affe…

Mitigation only
Fix from $1,600 2025-01-02
Unclassified MEDIUM 6.5
CVE-2024-38790

Cross-Site Request Forgery (CSRF) vulnerability in Smartsupp Smartsupp – live chat, chatbots, AI and lead generation smartsupp-live-chat allows Cross…

Mitigation only
Fix from $1,600 2025-01-02
Rara Business HIGH 8.8
CVE-2024-37937

Cross-Site Request Forgery (CSRF) vulnerability in raratheme Rara Business rara-business allows Cross Site Request Forgery.This issue affects Rara Bu…

Fix: 1.2.6+
Fix from $1,950 2025-01-02
Unclassified MEDIUM 5.4
CVE-2024-38729

Cross-Site Request Forgery (CSRF) vulnerability in mbeelink MBE eShip mail-boxes-etc allows Cross Site Request Forgery.This issue affects MBE eShip: …

Mitigation only
Fix from $1,600 2025-01-02
Lawyer Landing Page HIGH 8.8
CVE-2024-37503

Cross-Site Request Forgery (CSRF) vulnerability in raratheme Lawyer Landing Page lawyer-landing-page allows Cross Site Request Forgery.This issue aff…

Fix: 1.2.5+
Fix from $1,950 2025-01-02
Construction Landing Page HIGH 8.8
CVE-2024-37508

Cross-Site Request Forgery (CSRF) vulnerability in raratheme Construction Landing Page construction-landing-page allows Cross Site Request Forgery.Th…

Fix: 1.3.6+
Fix from $1,950 2025-01-02
Benevolent HIGH 8.8
CVE-2024-37450

Cross-Site Request Forgery (CSRF) vulnerability in raratheme Benevolent benevolent allows Cross Site Request Forgery.This issue affects Benevolent: f…

Fix: 1.3.5+
Fix from $1,950 2025-01-02
Travel Agency HIGH 8.8
CVE-2024-37451

Cross-Site Request Forgery (CSRF) vulnerability in raratheme Travel Agency travel-agency allows Cross Site Request Forgery.This issue affects Travel …

Fix: 1.5.0+
Fix from $1,950 2025-01-02
Blocksy HIGH 8.8
CVE-2024-37469

Cross-Site Request Forgery (CSRF) vulnerability in creativethemeshq Blocksy blocksy allows Cross Site Request Forgery.This issue affects Blocksy: fro…

Fix: 2.0.23+
Fix from $1,950 2025-01-02
Perfect Portfolio HIGH 8.8
CVE-2024-37435

Cross-Site Request Forgery (CSRF) vulnerability in raratheme Perfect Portfolio perfect-portfolio allows Cross Site Request Forgery.This issue affects…

Fix: 1.2.1+
Fix from $1,950 2025-01-02
Blossom Shop HIGH 8.8
CVE-2024-37412

Cross-Site Request Forgery (CSRF) vulnerability in blossomthemes Blossom Shop blossom-shop allows Cross Site Request Forgery.This issue affects Bloss…

Fix: 1.1.8+
Fix from $1,950 2025-01-02
Masterstudy Lms HIGH 8.8
CVE-2024-37093

Cross-Site Request Forgery (CSRF) vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Cross Site Request Forg…

Fix: 3.2.2+
Fix from $1,950 2025-01-02
Vilva HIGH 8.8
CVE-2024-37102

Cross-Site Request Forgery (CSRF) vulnerability in blossomthemes Vilva vilva allows Cross Site Request Forgery.This issue affects Vilva: from n/a thr…

Fix: 1.2.3+
Fix from $1,950 2025-01-02
Unclassified HIGH 8.8
CVE-2024-56203

Cross-Site Request Forgery (CSRF) vulnerability in gholme4 Wayne Audio Player wayne-audio-player allows Privilege Escalation.This issue affects Wayne…

Mitigation only
Fix from $1,950 2024-12-31
Unclassified HIGH 8.8
CVE-2024-56204

Cross-Site Request Forgery (CSRF) vulnerability in yonisink Sinking Dropdowns sinking-dropdowns allows Privilege Escalation.This issue affects Sinkin…

Mitigation only
Fix from $1,950 2024-12-31
Unclassified HIGH 8.8
CVE-2024-56206

Cross-Site Request Forgery (CSRF) vulnerability in krishankakkar gap-hub-user-role gap-hub-user-role allows Authentication Bypass.This issue affects …

Mitigation only
Fix from $1,950 2024-12-31
Unclassified HIGH 8.8
CVE-2024-56207

Cross-Site Request Forgery (CSRF) vulnerability in EditionGuard EditionGuard for WooCommerce – eBook Sales with DRM editionguard-for-woocommerce-eboo…

Mitigation only
Fix from $1,950 2024-12-31
Unclassified HIGH 7.1
CVE-2024-56232

Cross-Site Request Forgery (CSRF) vulnerability in Alex Volkov WP Nice Loader wp-nice-loader allows Stored XSS.This issue affects WP Nice Loader: fro…

Mitigation only
Fix from $1,950 2024-12-31
Codebard Help Desk MEDIUM 5.4
CVE-2024-56222

Cross-Site Request Forgery (CSRF) vulnerability in CodeBard CodeBard Help Desk codebard-help-desk allows Cross Site Request Forgery.This issue affect…

Fix: 1.1.2+
Fix from $1,600 2024-12-31
Redcap HIGH 8.8
CVE-2024-56310

REDCap through 14.9.6 has a security flaw in the Project Dashboards name, exposing users to a Cross-Site Request Forgery (CSRF) attack. An attacker c…

Fix: after 14.9.6
Fix from $1,950 2024-12-22
Redcap HIGH 8.8
CVE-2024-56311

REDCap through 14.9.6 has a security flaw in the Notes section of calendar events, exposing users to a Cross-Site Request Forgery (CSRF) attack. An a…

Fix: after 14.9.6
Fix from $1,950 2024-12-22
Unclassified HIGH 8.8
CVE-2024-12771

The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ…

Mitigation only
Fix from $1,950 2024-12-21
Gtpayment Donations MEDIUM 6.1
CVE-2024-11607

The GTPayment Donations WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, whic…

Fix: after 1.0.0
Fix from $1,600 2024-12-21