Vulnerability index

Browse CVEs

7,362 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Mediawiki MEDIUM 6.3
CVE-2026-58518

Cross-Site request forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - RedirectManager Extension allows Cross Site Request Forgery. …

Fix: 1.3.3+
Fix from $1,600 2026-07-01
Chrome MEDIUM 6.5
CVE-2026-14016

Inappropriate implementation in SVG in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML pa…

Fix: 150.0.7871.47+
Fix from $1,600 2026-06-30
Chrome MEDIUM 6.5
CVE-2026-13887

Inappropriate implementation in NFC in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer pro…

Fix: 150.0.7871.47+
Fix from $1,600 2026-06-30
Chrome MEDIUM 6.5
CVE-2026-13826

Inappropriate implementation in Autofill in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the rendere…

Fix: 150.0.7871.47+
Fix from $1,600 2026-06-30
Unclassified MEDIUM 5.1
CVE-2026-35096

KTM System e-BOK is vulnerable to Cross‑Site Request Forgery (CSRF) in both the email-change and password-change functionalities. An attacker can cra…

Mitigation only
Fix from $1,600 2026-06-30
Safari HIGH 8.1
CVE-2026-43735

The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, mac…

Fix: 26.5.2+
Fix from $1,950 2026-06-29
Unclassified MEDIUM 6.5
CVE-2026-31016

Cross Site Request Forgery vulnerability in Squidex.io Squidex CMS v.7.21.0 and before allows a remote attacker to escalate privileges via the Identi…

Mitigation only
Fix from $1,600 2026-06-29
Budibase HIGH 7.3
CVE-2026-50132

Budibase is an open-source low-code platform. Prior to 3.39.0, `GET /api/chat-links/:instance/:token/handoff` is a public endpoint (no auth required)…

Fix: 3.39.0+
Fix from $1,950 2026-06-26
Unclassified HIGH 8.8
CVE-2026-52784

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a CSRF on TARGET through /users/:id via POST …

Mitigation only
Fix from $1,950 2026-06-26
Unclassified HIGH 8.8
CVE-2026-57659

Unauthenticated Cross Site Request Forgery (CSRF) in Paid Memberships Pro - Add Member From Admin <= 0.7.2 versions.

Mitigation only
Fix from $1,950 2026-06-26
Unclassified HIGH 8.2
CVE-2026-57655

Unauthenticated Cross Site Request Forgery (CSRF) in Child Theme Wizard <= 1.4 versions.

Mitigation only
Fix from $1,950 2026-06-26
Unclassified MEDIUM 6.5
CVE-2026-57635

Unauthenticated Cross Site Request Forgery (CSRF) in FunnelKit Payment Gateway for Stripe WooCommerce <= 1.14.0.3 versions.

Mitigation only
Fix from $1,600 2026-06-26
Unclassified MEDIUM 6.5
CVE-2026-57641

Unauthenticated Cross Site Request Forgery (CSRF) in Real Estate 7 <= 3.5.9 versions.

Mitigation only
Fix from $1,600 2026-06-26
Unclassified HIGH 8.8
CVE-2025-68052

Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking <= 1.3.4.3 versions.

Mitigation only
Fix from $1,950 2026-06-26
Unclassified HIGH 8.8
CVE-2026-52800

Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization team member management can be performed via GET requests without CSRF p…

Patch available
Fix from $1,950 2026-06-24
Unclassified HIGH 7.3
CVE-2026-12986

A critical vulnerability in Admin GUI in Payara Server Full 4.x, 5.x, 6.x, 7.x, 7.2026.x, 6.2025.x, 6.2024.x on All platforms that allows the attacke…

Mitigation only
Fix from $1,950 2026-06-24
Assembla MEDIUM 5.4
CVE-2026-57305

A cross-site request forgery (CSRF) vulnerability in Jenkins Assembla Plugin 1.4 and earlier allows attackers to connect to an attacker-specified URL…

Fix: after 1.4
Fix from $1,600 2026-06-24
Unclassified MEDIUM 5.4
CVE-2026-57292

A cross-site request forgery (CSRF) vulnerability in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attackers to connect to an attacke…

Mitigation only
Fix from $1,600 2026-06-24
Ec2 Fleet MEDIUM 5.4
CVE-2026-57295

A cross-site request forgery (CSRF) vulnerability in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier allows attackers to connect to an …

Fix: after 4.2.3.539.v8fedff2a_81c3
Fix from $1,600 2026-06-24
Unclassified MEDIUM 5.4
CVE-2026-57298

A cross-site request forgery (CSRF) vulnerability in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allows attackers to hav…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified MEDIUM 6.1
CVE-2026-8905

The Osiris Signature Banner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5. This is due t…

Mitigation only
Fix from $1,600 2026-06-24
Apisix CRITICAL 9.3
CVE-2026-49871

Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. This defect allows a remote attacker that manag…

Fix: 3.17.0+
Fix from $2,300 2026-06-19
Unclassified MEDIUM 6.5
CVE-2026-56024

Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal WP EasyPay allows Cross Site Request Forgery. This issue affects WP EasyPay: from n/a …

Mitigation only
Fix from $1,600 2026-06-18
Unclassified HIGH 8.6
CVE-2026-54220

uBB.threads is vulnerable to a Cross-Site Request Forgery (CSRF) due to a lack of protective mechanisms. This allows an attacker to trick an authenti…

Mitigation only
Fix from $1,950 2026-06-18
Unclassified CRITICAL 9.6
CVE-2026-55742

Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration rights handler. In system/admin/admi…

Mitigation only
Fix from $2,300 2026-06-18
Unclassified HIGH 8.1
CVE-2026-55744

Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage (PFS) module. In modules/pfs/…

Mitigation only
Fix from $1,950 2026-06-18
Unclassified MEDIUM 5.4
CVE-2026-55745

Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage (PFS) module. In modules/pfs/…

Mitigation only
Fix from $1,600 2026-06-18
Unclassified HIGH 8.8
CVE-2026-55741

Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration configuration handler. In system/adm…

Mitigation only
Fix from $1,950 2026-06-18
Unclassified MEDIUM 6.9
CVE-2026-9591

Cross-site request forgery (CSRF) in NewsItemApiController in SimplCommerce prior to commit 6233d73e allows an unauthenticated remote attacker to cre…

Patch available
Fix from $1,600 2026-06-17
Unclassified HIGH 8.8
CVE-2026-22342

Unauthenticated Cross Site Request Forgery (CSRF) in WordPress Dating Theme <= 11.2.0 versions.

Mitigation only
Fix from $1,950 2026-06-17