Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Jatos HIGH 8.4
CVE-2024-51382

Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 allows an attacker to reset the administrator's password. This critical security flaw…

No fix yet
Fix from $1,950 2024-11-05
Woocommerce Report HIGH 8.8
CVE-2024-10711

The WooCommerce Report plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.1. This is due to m…

Fix: 1.5.2+
Fix from $1,950 2024-11-05
Itop HIGH 8.8
CVE-2024-31998

Combodo iTop is a simple, web based IT Service Management tool. A CSRF can be performed on CSV import simulation. This issue has been fixed in versio…

Fix: 3.1.2+
Fix from $1,950 2024-11-05
Localai MEDIUM 6.1
CVE-2024-48057

localai <=2.20.1 is vulnerable to Cross Site Scripting (XSS). When calling the delete model API and passing inappropriate parameters, it can cause a …

Fix: after 2.20.1
Fix from $1,600 2024-11-04
Chamilo Lms MEDIUM 5.4
CVE-2024-30617

A Cross-Site Request Forgery (CSRF) vulnerability in Chamilo LMS 1.11.26 "/main/social/home.php," allows attackers to initiate a request that posts a…

Patch available
Fix from $1,600 2024-11-04
Cics Tx HIGH 8.8
CVE-2024-41744

IBM CICS TX Standard 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions tra…

Mitigation only
Fix from $1,950 2024-11-01
Depicter CRITICAL 9.8
CVE-2024-47359

Cross-Site Request Forgery (CSRF) vulnerability in averta Depicter Slider depicter.This issue affects Depicter Slider: from n/a through <= 3.2.2.

Fix: 3.5.0+
Fix from $2,300 2024-11-01
Blood Bank Management System MEDIUM 6.5
CVE-2024-10605

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been classified as problematic. This affects an unknown part of t…

No fix yet
Fix from $1,600 2024-11-01
Podlove Podcast Publisher HIGH 8.8
CVE-2024-43984

Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher allows Code Injection.This issue affects Podlove Podcast Publish…

Fix: 4.1.14+
Fix from $1,950 2024-10-31
Unclassified CRITICAL 9.6
CVE-2024-49674

Cross-Site Request Forgery (CSRF) vulnerability in lukashuser EKC Tournament Manager ekc-tournament-manager allows Upload a Web Shell to a Web Server…

Mitigation only
Fix from $2,300 2024-10-31
Custom Twitter Feeds HIGH 8.8
CVE-2024-49685

Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Custom Twitter Feeds (Tweets Widget) custom-twitter-feeds allows Cross Site Request Fo…

Fix: 2.2.4+
Fix from $1,950 2024-10-31
Unclassified MEDIUM 6.1
CVE-2024-9434

The WPGlobus Translate Options plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is …

Mitigation only
Fix from $1,600 2024-10-31
Piwigo HIGH 8.8
CVE-2024-48311

Piwigo v14.5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit album function.

No fix yet
Fix from $1,950 2024-10-31
Blood Bank Management System MEDIUM 6.5
CVE-2024-10557

A vulnerability has been found in code-projects Blood Bank Management System 1.0 and classified as problematic. Affected by this vulnerability is an …

No fix yet
Fix from $1,600 2024-10-31
Wbr 6012 Firmware HIGH 8.8
CVE-2024-24777EPSS 8%

A cross-site request forgery (CSRF) vulnerability exists in the Web Application functionality of the LevelOne WBR-6012 R0.40e6. A specially crafted H…

No fix yet
Fix from $1,950 2024-10-30
Crypto Tool HIGH 8.8
CVE-2024-9990

The Crypto plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.15. This is due to missing nonce vali…

Fix: after 2.16
Fix from $1,950 2024-10-29
Darkmysite HIGH 8.8
CVE-2024-50466

Cross-Site Request Forgery (CSRF) vulnerability in DarkMySite DarkMySite – Advanced Dark Mode Plugin for WordPress darkmysite allows Cross Site Reque…

Fix: after 1.2.8
Fix from $1,950 2024-10-29
Lollms Web Ui MEDIUM 6.5
CVE-2024-6673

A Cross-Site Request Forgery (CSRF) vulnerability exists in the `install_comfyui` endpoint of the `lollms_comfyui.py` file in the parisneo/lollms-web…

Fix: 10+
Fix from $1,600 2024-10-29
Google Docs Rsvp MEDIUM 6.1
CVE-2024-49672

Cross-Site Request Forgery (CSRF) vulnerability in giffordcheung Google Docs RSVP google-docs-rsvp-guestlist allows Stored XSS.This issue affects Goo…

Fix: after 2.0.1
Fix from $1,600 2024-10-29
Dingfanzu Cms MEDIUM 6.3
CVE-2024-48291

dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=editAdmin&id=17

No fix yet
Fix from $1,600 2024-10-28
Blood Bank Management System MEDIUM 6.5
CVE-2024-10448

A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank Management System 1.0. Affected by this issue is som…

No fix yet
Fix from $1,600 2024-10-28
Dingfanzu Cms MEDIUM 6.3
CVE-2024-48191

dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=delAdmin&id=17

No fix yet
Fix from $1,600 2024-10-28
Ovaledge HIGH 8.8
CVE-2022-30357

OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfile via the userId and email p…

Fix: after 5.2.8
Fix from $1,950 2024-10-25
Unclassified MEDIUM 5.3
CVE-2023-26248

The Kademlia DHT (go-libp2p-kad-dht 0.20.0 and earlier) used in IPFS (0.18.1 and earlier) assigns routing information for content (i.e., information …

Mitigation only
Fix from $1,600 2024-10-25
Accelerated Mobile Pages HIGH 8.8
CVE-2024-9598

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.…

Fix: 1.0.99.2+
Fix from $1,950 2024-10-25
Openrefine HIGH 8.8
CVE-2024-47879

OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, lack of cross-site request forgery protection on the `pre…

Fix: 3.8.3+
Fix from $1,950 2024-10-24
Multivendorx MEDIUM 6.3
CVE-2024-9943

The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Cross-Site Request Forgery in all …

Fix: 4.2.5+
Fix from $1,600 2024-10-24
Digital Experience Platform MEDIUM 6.1
CVE-2024-8980

The Script Console in Liferay Portal 7.0.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through u…

Fix: 7.0.6 / 7.1.3+
Fix from $1,600 2024-10-22
Digital Experience Platform HIGH 8.8
CVE-2024-26271

Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75 through 7.4.3.111, and Liferay DXP 2023.Q4.0 thro…

Fix: 7.4.3.112 / 2023.q3.6+
Fix from $1,950 2024-10-22
Digital Experience Platform HIGH 8.8
CVE-2024-26272

Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.3.2 through 7.4.3.107, and Liferay DXP 2023.Q4.0 throu…

Fix: 7.4.3.108 / 2023.q3.6+
Fix from $1,950 2024-10-22