Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Arfa Cms HIGH 8.8
CVE-2024-45264

A cross-site request forgery (CSRF) vulnerability in the admin panel in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to add a new admin…

Fix: 5.1.3124+
Fix from $1,950 2024-08-27
Dark Mode For Wp Dashboard HIGH 8.8
CVE-2024-43325

Cross-Site Request Forgery (CSRF) vulnerability in Naiche Dark Mode for WP Dashboard.This issue affects Dark Mode for WP Dashboard: from n/a through …

Fix: 1.2.4+
Fix from $1,950 2024-08-26
Webinarpress MEDIUM 6.1
CVE-2024-43339

Cross-Site Request Forgery (CSRF) vulnerability in WebinarPress allows Cross-Site Scripting (XSS).This issue affects WebinarPress: from n/a through 1…

Fix: 1.33.21+
Fix from $1,600 2024-08-26
Newsletter\, Smtp\, Email Marketing And Subscribe HIGH 8.8
CVE-2024-43287

Cross-Site Request Forgery (CSRF) vulnerability in Brevo Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue.This issue affects Newsl…

Fix: 3.1.83+
Fix from $1,950 2024-08-26
Speedycache MEDIUM 5.4
CVE-2024-43299

Cross-Site Request Forgery (CSRF) vulnerability in Softaculous SpeedyCache speedycache.This issue affects SpeedyCache: from n/a through <= 1.1.8.

Fix: 1.1.9+
Fix from $1,600 2024-08-26
Fonts MEDIUM 5.4
CVE-2024-43301

Cross-Site Request Forgery (CSRF) vulnerability in Fonts Plugin Fonts allows Stored XSS.This issue affects Fonts: from n/a through 3.7.7.

Fix: 3.7.8+
Fix from $1,600 2024-08-26
Mybook Table Bookstore MEDIUM 6.1
CVE-2024-43255

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zookatron MyBookTable Bookstore mybooktable.Thi…

Fix: after 3.3.9
Fix from $1,600 2024-08-26
Sender HIGH 8.8
CVE-2024-39657

Cross-Site Request Forgery (CSRF) vulnerability in Sender Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce.This issue affects …

Fix: 2.6.19+
Fix from $1,950 2024-08-26
Simple Local Avatars HIGH 8.8
CVE-2024-43116

Cross-Site Request Forgery (CSRF) vulnerability in 10up Simple Local Avatars.This issue affects Simple Local Avatars: from n/a through 2.7.10.

Fix: 2.7.11+
Fix from $1,950 2024-08-26
Hummingbird HIGH 8.8
CVE-2024-43117

Cross-Site Request Forgery (CSRF) vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hummingbird hummingbird-performance.This issue affec…

Fix: 3.9.2+
Fix from $1,950 2024-08-26
Ninja Forms HIGH 8.8
CVE-2024-39628

Cross-Site Request Forgery (CSRF) vulnerability in Saturday Drive Ninja Forms allows Cross Site Request Forgery.This issue affects Ninja Forms: from …

Fix: 3.8.7+
Fix from $1,950 2024-08-26
Learnpress HIGH 8.8
CVE-2024-39641

Cross-Site Request Forgery (CSRF) vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.6.8.2.

Fix: 4.2.6.9+
Fix from $1,950 2024-08-26
Tutor Lms HIGH 8.8
CVE-2024-39645

Cross-Site Request Forgery (CSRF) vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.7.2.

Fix: 2.7.3+
Fix from $1,950 2024-08-26
Favicon Generator HIGH 8.1
CVE-2024-7568

The Favicon Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5. This is due to missing …

Fix: 2.1+
Fix from $1,950 2024-08-24
Bus Ticket Reservation System CRITICAL 9.4
CVE-2024-42764

Kashipara Bus Ticket Reservation System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via /deleteTicket.php.

No fix yet
Fix from $2,300 2024-08-23
Hotel Management System MEDIUM 6.8
CVE-2024-42768

A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Hotel Management System v1.0 via /admin/delete_room.php.

No fix yet
Fix from $1,600 2024-08-22
Hono MEDIUM 5.0
CVE-2024-43787

Hono is a Web application framework that provides support for any JavaScript runtime. Hono CSRF middleware can be bypassed using crafted Content-Type…

Fix: 4.5.8+
Fix from $1,600 2024-08-22
Mattermost HIGH 8.8
CVE-2024-40886

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to sanitize user inputs in the frontend that are used for r…

Fix: 9.5.8 / 9.8.3+
Fix from $1,950 2024-08-22
Retool MEDIUM 6.5
CVE-2024-42056

Retool (self-hosted enterprise) through 3.40.0 inserts resource authentication credentials into sent data. Credentials for users with "Use" permissio…

Fix: after 3.40.0
Fix from $1,600 2024-08-22
Identity Services Engine HIGH 8.8
CVE-2024-20486

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cond…

Fix: 3.1+
Fix from $1,950 2024-08-21
Ota Sync Booking Engine Widget MEDIUM 6.1
CVE-2024-7647

The OTA Sync Booking Engine Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.7. This…

Fix: after 1.2.7
Fix from $1,600 2024-08-21
Pligg Cms HIGH 8.8
CVE-2024-42619

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/domain_management.php?id=0&list=whitelist&rem…

No fix yet
Fix from $1,950 2024-08-20
Pligg Cms HIGH 8.8
CVE-2024-42612

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/domain_management.php?whitelist_add

No fix yet
Fix from $1,950 2024-08-20
Pligg Cms HIGH 8.8
CVE-2024-42605

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/edit_page.php?link_id=1

No fix yet
Fix from $1,950 2024-08-20
Pligg Cms HIGH 8.8
CVE-2024-42606

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_log.php?clear=1

No fix yet
Fix from $1,950 2024-08-20
Pligg Cms HIGH 8.8
CVE-2024-42607

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=database

No fix yet
Fix from $1,950 2024-08-20
Pligg Cms HIGH 8.8
CVE-2024-42609

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=avatars

No fix yet
Fix from $1,950 2024-08-20
Pligg Cms HIGH 8.8
CVE-2024-42610

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=files

No fix yet
Fix from $1,950 2024-08-20
Pligg Cms HIGH 8.8
CVE-2024-42611

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/admin_page.php?link_id=1&mode=delete

No fix yet
Fix from $1,950 2024-08-20
Pligg Cms HIGH 8.8
CVE-2024-42613

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_widgets.php?action=install&widget=akism…

No fix yet
Fix from $1,950 2024-08-20