Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Frogcms HIGH 8.8
CVE-2024-46394

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/?/user/add

No fix yet
Fix from $1,950 2024-09-19
Frogcms HIGH 8.8
CVE-2024-46086

FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/delete/123

No fix yet
Fix from $1,950 2024-09-18
Like Button Rating MEDIUM 6.1
CVE-2024-44064

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LikeBtn Like Button Rating likebtn-like-button.…

Fix: 2.6.54+
Fix from $1,600 2024-09-17
Frogcms HIGH 8.8
CVE-2024-46085

FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/rename

Mitigation only
Fix from $1,950 2024-09-17
Frogcms HIGH 8.8
CVE-2024-46362

FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/create_directory

No fix yet
Fix from $1,950 2024-09-17
Propertyhive MEDIUM 6.5
CVE-2024-8490

The PropertyHive plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.19. This is due to missin…

Fix: 2.0.20+
Fix from $1,600 2024-09-17
Vikinghammer Tweet MEDIUM 5.4
CVE-2024-8043

The Vikinghammer Tweet WordPress plugin through 0.2.4 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which…

Fix: after 0.2.4
Fix from $1,600 2024-09-17
Infolinks Ad Wrap MEDIUM 6.5
CVE-2024-8044

The infolinks Ad Wrap WordPress plugin through 1.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to mak…

Fix: after 1.0.2
Fix from $1,600 2024-09-17
Visual Sound MEDIUM 6.5
CVE-2024-8047

The Visual Sound (old) WordPress plugin through 1.06 does not have CSRF check in place when updating its settings, which could allow attackers to mak…

Fix: after 1.06
Fix from $1,600 2024-09-17
Special Feed Items MEDIUM 5.4
CVE-2024-8051

The Special Feed Items WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which…

Fix: after 1.0.1
Fix from $1,600 2024-09-17
Review Ratings MEDIUM 6.1
CVE-2024-8052

The Review Ratings WordPress plugin through 1.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could…

Fix: after 1.6
Fix from $1,600 2024-09-17
Enhanced Search Box MEDIUM 6.5
CVE-2024-8091

The Enhanced Search Box WordPress plugin through 0.6.1 does not have CSRF check in place when updating its settings, which could allow attackers to m…

Fix: after 0.6.1
Fix from $1,600 2024-09-17
Accordion Image Menu MEDIUM 5.4
CVE-2024-8092

The Accordion Image Menu WordPress plugin through 3.1.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, whi…

Fix: after 3.1.3
Fix from $1,600 2024-09-17
Posts Reminder MEDIUM 6.5
CVE-2024-8093

The Posts reminder WordPress plugin through 0.20 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Fix: after 0.20
Fix from $1,600 2024-09-17
Lunary HIGH 8.1
CVE-2024-6862

A Cross-Site Request Forgery (CSRF) vulnerability exists in lunary-ai/lunary version 1.2.34 due to overly permissive CORS settings. This vulnerabilit…

Patch available
Fix from $1,950 2024-09-13
Stream HIGH 8.8
CVE-2024-7423

The Stream plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.1. This is due to missing or in…

Fix: 4.0.2+
Fix from $1,950 2024-09-13
Favicon Generator MEDIUM 6.8
CVE-2024-7863

The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not validate files to be uploaded and does not have CSRF checks, which could allow at…

Fix: 2.1+
Fix from $1,600 2024-09-13
Favicon Generator MEDIUM 6.5
CVE-2024-7864

The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not have CSRF and path validation in the output_sub_admin_page_0() function, allowing…

Fix: 2.1+
Fix from $1,600 2024-09-13
Blogintroduction Wordpress Plugin MEDIUM 6.5
CVE-2024-7862

The blogintroduction-wordpress-plugin WordPress plugin through 0.3.0 does not have CSRF check in place when updating its settings, which could allow …

Fix: after 0.3.0
Fix from $1,600 2024-09-12
Gixaw Chat MEDIUM 6.1
CVE-2024-7816

The Gixaw Chat WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could all…

Fix: after 1.0
Fix from $1,600 2024-09-12
Misiek Photo Album MEDIUM 6.5
CVE-2024-7817

The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF checks in some places, which could allow attackers to make logged in users d…

Fix: after 1.4.3
Fix from $1,600 2024-09-12
Ilc Thickbox MEDIUM 6.5
CVE-2024-7820

The ILC Thickbox WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a log…

Fix: after 1.0
Fix from $1,600 2024-09-12
Visual Sound MEDIUM 6.5
CVE-2024-7859

The Visual Sound WordPress plugin through 1.03 does not have CSRF check in place when updating its settings, which could allow attackers to make a lo…

Fix: after 1.03
Fix from $1,600 2024-09-12
Music Request Manager MEDIUM 6.1
CVE-2024-6017

The Music Request Manager WordPress plugin through 1.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, whic…

Fix: after 1.3
Fix from $1,600 2024-09-12
Eladmin CRITICAL 9.8
CVE-2024-44677

eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the DatabaseContro…

Fix: after 2.7
Fix from $2,300 2024-09-10
Unclassified MEDIUM 6.5
CVE-2024-45504

Cross-site request forgery (CSRF) vulnerability in multiple Alps System Integration products and the OEM products allow a remote unauthenticated atta…

Mitigation only
Fix from $1,600 2024-09-10
Azindex MEDIUM 6.5
CVE-2024-7688

The AZIndex WordPress plugin through 0.8.1 does not have CSRF checks in some places, which could allow attackers to make logged in admin delete arbit…

Fix: after 0.8.1
Fix from $1,600 2024-09-09
C Mor Video Surveillance MEDIUM 6.8
CVE-2024-45172

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to missing protection mechanisms, the C-MOR web interface is…

No fix yet
Fix from $1,600 2024-09-04
Redcap MEDIUM 6.1
CVE-2024-45527

REDCap 14.7.0 allows HTML injection via the project title of a New Project action. This can lead to resultant logout CSRF via index.php?logout=1, and…

No fix yet
Fix from $1,600 2024-09-02
Music Management System HIGH 8.0
CVE-2024-42793

A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via a crafted request to the /music/ajax.php?ac…

No fix yet
Fix from $1,950 2024-08-28