Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Unclassified HIGH 8.8
CVE-2024-37758

Improper access control in the endpoint /RoleMenuMapping/AddRoleMenu of Digiteam v4.21.0.0 allows authenticated attackers to escalate privileges.

Mitigation only
Fix from $1,950 2024-12-20
Unclassified MEDIUM 6.1
CVE-2024-11812

The Wtyczka SeoPilot dla WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.3.091. This is d…

Mitigation only
Fix from $1,600 2024-12-20
macOS MEDIUM 5.5
CVE-2024-44293

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.1. A user may be able to …

Mitigation only
Fix from $1,600 2024-12-20
Amiro.cms HIGH 8.8
CVE-2024-56116

A Cross-Site Request Forgery vulnerability in Amiro.CMS before 7.8.4 allows remote attackers to create an administrator account.

Fix: 7.8.4+
Fix from $1,950 2024-12-18
Astro MEDIUM 6.5
CVE-2024-56140

Astro is a web framework for content-driven websites. In affected versions a bug in Astro’s CSRF-protection middleware allows requests to bypass CSRF…

Fix: 4.16.17+
Fix from $1,600 2024-12-18
Getsimple Cms HIGH 8.8
CVE-2024-55088

GetSimple CMS CE 3.3.19 is vulnerable to Server-Side Request Forgery (SSRF) in the backend plugin module.

Mitigation only
Fix from $1,950 2024-12-18
Unclassified MEDIUM 6.1
CVE-2024-12454

The Affiliate Program Suite — SliceWP Affiliates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin…

Mitigation only
Fix from $1,600 2024-12-18
Unclassified MEDIUM 5.4
CVE-2024-12554

The Peter’s Custom Anti-Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.3. This is du…

Mitigation only
Fix from $1,600 2024-12-18
Cost Calculator Builder MEDIUM 5.4
CVE-2024-10892

The Cost Calculator Builder WordPress plugin before 3.2.43 does not have CSRF checks in some AJAX actions, which could allow attackers to make logged…

Fix: 3.2.43+
Fix from $1,600 2024-12-18
Unclassified HIGH 8.8
CVE-2024-12293

The User Role Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.64.3. This is due to mi…

Mitigation only
Fix from $1,950 2024-12-17
Unclassified MEDIUM 6.1
CVE-2024-12219

The Stop Registration Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.23. This is due t…

Mitigation only
Fix from $1,600 2024-12-17
Unclassified MEDIUM 6.1
CVE-2024-12220

The SMS for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.1. This is due to …

Mitigation only
Fix from $1,600 2024-12-17
Unclassified HIGH 7.1
CVE-2024-56017

Cross-Site Request Forgery (CSRF) vulnerability in Tom Royal Stop Registration Spam allows Stored XSS.This issue affects Stop Registration Spam: from…

Mitigation only
Fix from $1,950 2024-12-16
Dctrack HIGH 8.0
CVE-2024-37774

A Cross-Site Request Forgery (CSRF) in Sunbird DCIM dcTrack v9.1.2 allows authenticated attackers to escalate their privileges by forcing an Administ…

Mitigation only
Fix from $1,950 2024-12-16
Unclassified HIGH 7.1
CVE-2024-56015

Cross-Site Request Forgery (CSRF) vulnerability in John Godley Tidy Up allows Reflected XSS.This issue affects Tidy Up: from n/a through 1.3.

Mitigation only
Fix from $1,950 2024-12-16
Unclassified MEDIUM 6.5
CVE-2024-56005

Cross-Site Request Forgery (CSRF) vulnerability in Posti Posti Shipping posti-shipping allows Cross Site Request Forgery.This issue affects Posti Shi…

Mitigation only
Fix from $1,600 2024-12-16
Unclassified CRITICAL 9.8
CVE-2024-56012

Cross-Site Request Forgery (CSRF) vulnerability in lizeipe Flash News / Post (Responsive) flashnews-fading-effect-pearlbells allows Privilege Escalat…

Mitigation only
Fix from $2,300 2024-12-16
Unclassified HIGH 7.1
CVE-2024-54433

Cross-Site Request Forgery (CSRF) vulnerability in Marcel CL Simple Booking Widget simple-booking-widget allows Stored XSS.This issue affects Simple …

Mitigation only
Fix from $1,950 2024-12-16
Unclassified HIGH 7.1
CVE-2024-54434

Cross-Site Request Forgery (CSRF) vulnerability in BenJemin phZoom phzoom allows Stored XSS.This issue affects phZoom: from n/a through <= 1.2.92.

Mitigation only
Fix from $1,950 2024-12-16
Unclassified HIGH 7.1
CVE-2024-54435

Cross-Site Request Forgery (CSRF) vulnerability in Thomas Hoefter Onlywire Multi Autosubmitter onlywire-multi-autosubmitter allows Stored XSS.This is…

Mitigation only
Fix from $1,950 2024-12-16
Unclassified HIGH 7.1
CVE-2024-54436

Cross-Site Request Forgery (CSRF) vulnerability in milordk Jet Footer Code jet-footer-code allows Stored XSS.This issue affects Jet Footer Code: from…

Mitigation only
Fix from $1,950 2024-12-16
Unclassified HIGH 7.1
CVE-2024-54438

Cross-Site Request Forgery (CSRF) vulnerability in gaxx Gaxx Keywords gaxx-keywords allows Stored XSS.This issue affects Gaxx Keywords: from n/a thro…

Mitigation only
Fix from $1,950 2024-12-16
Unclassified HIGH 7.1
CVE-2024-54439

Cross-Site Request Forgery (CSRF) vulnerability in Alok Tiwari Amazon Product Price amazon-product-price allows Stored XSS.This issue affects Amazon …

Mitigation only
Fix from $1,950 2024-12-16
Unclassified HIGH 7.1
CVE-2024-54440

Cross-Site Request Forgery (CSRF) vulnerability in blueskyy WP-Ban-User wp-ban-user allows Stored XSS.This issue affects WP-Ban-User: from n/a throug…

Mitigation only
Fix from $1,950 2024-12-16
Unclassified HIGH 7.1
CVE-2024-54426

Cross-Site Request Forgery (CSRF) vulnerability in crossfitatgg LeaderBoard Plugin leaderboard-lite allows Stored XSS.This issue affects LeaderBoard …

Mitigation only
Fix from $1,950 2024-12-16
Unclassified HIGH 7.1
CVE-2024-54427

Cross-Site Request Forgery (CSRF) vulnerability in ljmacphee Category of Posts list-one-category-of-posts allows Stored XSS.This issue affects Catego…

Mitigation only
Fix from $1,950 2024-12-16
Unclassified HIGH 7.1
CVE-2024-54428

Cross-Site Request Forgery (CSRF) vulnerability in onigetoc Add image to Post add-image-to-post allows Stored XSS.This issue affects Add image to Pos…

Mitigation only
Fix from $1,950 2024-12-16
Unclassified HIGH 7.1
CVE-2024-54429

Cross-Site Request Forgery (CSRF) vulnerability in ivan-ovsyannikov Aphorismus aphorismus allows Stored XSS.This issue affects Aphorismus: from n/a t…

Mitigation only
Fix from $1,950 2024-12-16
Unclassified MEDIUM 5.4
CVE-2024-54430

Cross-Site Request Forgery (CSRF) vulnerability in Europe Ecologie Les Verts EELV Newsletter eelv-newsletter allows Cross Site Request Forgery.This i…

Mitigation only
Fix from $1,600 2024-12-16
Unclassified HIGH 7.1
CVE-2024-54431

Cross-Site Request Forgery (CSRF) vulnerability in phpdevp Admin Customization wpp-customization allows Stored XSS.This issue affects Admin Customiza…

Mitigation only
Fix from $1,950 2024-12-16