Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Frogcms HIGH 8.8
CVE-2024-42623

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/delete/1

No fix yet
Fix from $1,950 2024-08-12
Frogcms HIGH 8.8
CVE-2024-42630

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/create_file.

No fix yet
Fix from $1,950 2024-08-12
Frogcms HIGH 8.8
CVE-2024-42631

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/edit/1.

No fix yet
Fix from $1,950 2024-08-12
Frogcms HIGH 8.8
CVE-2024-42632

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/add.

No fix yet
Fix from $1,950 2024-08-12
Frogcms HIGH 8.8
CVE-2024-42628

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/edit/3.

No fix yet
Fix from $1,950 2024-08-12
Frogcms HIGH 8.8
CVE-2024-42629

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/edit/10.

No fix yet
Fix from $1,950 2024-08-12
Car Driving School Management System HIGH 8.8
CVE-2024-7661

A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been classified as problematic. This affects the functio…

No fix yet
Fix from $1,950 2024-08-12
Car Driving School Management System MEDIUM 6.5
CVE-2024-7662

A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been declared as problematic. This vulnerability affects…

No fix yet
Fix from $1,600 2024-08-12
Clinic\'s Patient Management System MEDIUM 5.4
CVE-2024-7645

A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been declared as problematic. This vulnerability affects un…

No fix yet
Fix from $1,600 2024-08-12
Christmasify\! MEDIUM 6.1
CVE-2024-7574

The Christmasify! plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.5. This is due to missing no…

Fix: 1.5.6+
Fix from $1,600 2024-08-12
Wp Estore MEDIUM 5.4
CVE-2024-6136

The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not have CSRF checks in some places, which could allow attackers to make logged i…

Fix: 8.5.6+
Fix from $1,600 2024-08-12
Live Membership System HIGH 8.8
CVE-2024-40488

A Cross-Site Request Forgery (CSRF) vulnerability was found in the Kashipara Live Membership System v1.0. This could lead to an attacker tricking the…

No fix yet
Fix from $1,950 2024-08-12
Best House Rental Management HIGH 8.0
CVE-2024-40476

A Cross-Site Request Forgery (CSRF) vulnerability was found in SourceCodester Best House Rental Management System v1.0. This could lead to an attacke…

Mitigation only
Fix from $1,950 2024-08-12
Mainwp Child HIGH 8.8
CVE-2024-7492

The MainWP Child Reports plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2. This is due to m…

Fix: 2.2.1+
Fix from $1,950 2024-08-08
Light Poll HIGH 8.8
CVE-2024-6720

The Light Poll WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform u…

Fix: after 1.0.0
Fix from $1,950 2024-08-06
Wp Emember MEDIUM 6.1
CVE-2024-5081

The wp-eMember WordPress plugin before v10.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Fix: 10.7.0+
Fix from $1,600 2024-08-05
Himer HIGH 8.1
CVE-2024-2232

The lacks CSRF checks allowing a user to invite any user to any group (including private groups)

Fix: 2.1.3+
Fix from $1,950 2024-08-05
Warehouse Inventory System HIGH 8.8
CVE-2024-7460

A vulnerability was found in OSWAPP Warehouse Inventory System 1.0/2.0. It has been declared as problematic. Affected by this vulnerability is an unk…

No fix yet
Fix from $1,950 2024-08-04
Warehouse Inventory System HIGH 8.8
CVE-2024-7459

A vulnerability was found in OSWAPP Warehouse Inventory System 1.0/2.0. It has been classified as problematic. Affected is an unknown function of the…

No fix yet
Fix from $1,950 2024-08-04
Unclassified HIGH 7.1
CVE-2024-38776

Cross-Site Request Forgery (CSRF) vulnerability in Martin Gibson WP GoToWebinar allows Cross-Site Scripting (XSS).This issue affects WP GoToWebinar: …

Mitigation only
Fix from $1,950 2024-08-02
Unclassified HIGH 8.8
CVE-2024-3238

The WordPress Menu Plugin — Superfly Responsive Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl…

Mitigation only
Fix from $1,950 2024-08-02
Simple Realtime Quiz System HIGH 8.8
CVE-2024-7367

A vulnerability, which was classified as problematic, was found in SourceCodester Simple Realtime Quiz System 1.0. This affects an unknown part of th…

No fix yet
Fix from $1,950 2024-08-01
Exacqvision Web Service HIGH 8.8
CVE-2024-32863

Under certain circumstances the exacqVision Web Services may be susceptible to Cross-Site Request Forgery (CSRF)

Fix: after 24.03
Fix from $1,950 2024-08-01
Tracking Monitoring Management System HIGH 8.8
CVE-2024-7360

A vulnerability classified as problematic has been found in SourceCodester Tracking Monitoring Management System 1.0. This affects an unknown part of…

No fix yet
Fix from $1,950 2024-08-01
Lollms Web Ui HIGH 8.8
CVE-2024-6040

In parisneo/lollms-webui version v9.8, the lollms_binding_infos is missing the client_id parameter, which leads to multiple security vulnerabilities.…

No fix yet
Fix from $1,950 2024-08-01
Woocommerce Customers Manager MEDIUM 6.5
CVE-2024-2843

The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some places, which could allow attackers to make logged i…

Fix: 30.1+
Fix from $1,600 2024-08-01
Woocommerce Customers Manager HIGH 8.1
CVE-2024-3983

The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some bulk actions, which could allow attackers to make lo…

Fix: 30.1+
Fix from $1,950 2024-08-01
Light Poll MEDIUM 6.5
CVE-2024-6496

The Light Poll WordPress plugin through 1.0.0 does not have CSRF checks when deleting polls, which could allow attackers to make logged in users perf…

Fix: after 1.0.0
Fix from $1,600 2024-08-01
Woocommerce Customers Manager MEDIUM 6.5
CVE-2024-1747

The WooCommerce Customers Manager WordPress plugin before 30.2 does not have authorisation and CSRF in various AJAX actions, allowing any authenticat…

Fix: 30.2+
Fix from $1,600 2024-08-01
Wrc 2533gs2 B Firmware HIGH 8.8
CVE-2024-40883

Cross-site request forgery vulnerability exists in ELECOM wireless LAN routers. Viewing a malicious page while logging in to the affected product wit…

Fix: 1.12 / 1.69+
Fix from $1,950 2024-08-01