Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Cm Search And Replace MEDIUM 6.5
CVE-2024-5028

The CM WordPress Search And Replace Plugin WordPress plugin before 1.3.9 does not have CSRF checks in some places, which could allow attackers to mak…

Fix: 1.3.9+
Fix from $1,600 2024-07-13
Sully MEDIUM 5.9
CVE-2024-5033

The SULly WordPress plugin before 4.3.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow a…

Fix: 4.3.1+
Fix from $1,600 2024-07-13
Sully HIGH 8.8
CVE-2024-5034

The SULly WordPress plugin before 4.3.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwante…

Fix: 4.3.1+
Fix from $1,950 2024-07-13
Wp Emember HIGH 8.8
CVE-2024-5076

The wp-eMember WordPress plugin before 10.6.6 does not have CSRF checks in some places, which could allow attackers to make logged in users perform u…

Fix: 10.6.6+
Fix from $1,950 2024-07-13
Smart Image Gallery MEDIUM 6.8
CVE-2024-3632

The Smart Image Gallery WordPress plugin before 1.0.19 does not have CSRF check in place when updating its settings, which could allow attackers to m…

Fix: 1.0.19+
Fix from $1,600 2024-07-13
Unclassified HIGH 7.4
CVE-2024-37940

Cross-Site Request Forgery (CSRF) vulnerability in Seraphinite Solutions Seraphinite Accelerator (Full, premium).This issue affects Seraphinite Accel…

Mitigation only
Fix from $1,950 2024-07-12
Unclassified HIGH 7.1
CVE-2024-37213

Cross-Site Request Forgery (CSRF) vulnerability in guru-aliexpress AliNext ali2woo-lite allows Cross Site Request Forgery.This issue affects AliNext:…

Mitigation only
Fix from $1,950 2024-07-12
Unclassified HIGH 7.1
CVE-2024-35773

Cross-Site Request Forgery (CSRF) vulnerability in WPJohnny, zerOneIT Comment Reply Email allows Cross-Site Scripting (XSS).This issue affects Commen…

Mitigation only
Fix from $1,950 2024-07-12
Contentlock HIGH 8.8
CVE-2024-6023

The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when adding emails, which could allow attackers to make a logged in …

Fix: 1.0.4+
Fix from $1,950 2024-07-12
Contentlock HIGH 8.8
CVE-2024-6024

The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when deleting groups or emails, which could allow attackers to make …

Fix: 1.0.4+
Fix from $1,950 2024-07-12
Contentlock HIGH 8.8
CVE-2024-6022

The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a lo…

Fix: 1.0.4+
Fix from $1,950 2024-07-12
Vikrentcar HIGH 8.8
CVE-2024-1845

The VikRentCar Car Rental Management System WordPress plugin before 1.3.2 does not have CSRF checks in some places, which could allow attackers to ma…

Fix: 1.3.2+
Fix from $1,950 2024-07-11
Employee And Visitor Gate Pass Logging System MEDIUM 6.5
CVE-2024-6649

A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this vu…

No fix yet
Fix from $1,600 2024-07-10
Idccms HIGH 8.8
CVE-2024-40331

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/dbBakMySQL_deal.php?mudi=backup

No fix yet
Fix from $1,950 2024-07-10
Idccms HIGH 8.8
CVE-2024-40332

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/moneyRecord_deal.php?mudi=delRecord

Mitigation only
Fix from $1,950 2024-07-10
Checkmk HIGH 8.8
CVE-2024-28828

Cross-Site request forgery in Checkmk < 2.3.0p8, < 2.2.0p29, < 2.1.0p45, and <= 2.0.0p39 (EOL) could lead to 1-click compromize of the site.

Mitigation only
Fix from $1,950 2024-07-10
Idccms MEDIUM 6.3
CVE-2024-40328

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/memberOnline_deal.php?mudi=del&dataType=&dataID=6

No fix yet
Fix from $1,600 2024-07-10
Idccms HIGH 8.8
CVE-2024-40329

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/softBak_deal.php?mudi=backup

No fix yet
Fix from $1,950 2024-07-10
Idccms HIGH 8.8
CVE-2024-40334

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/serverFile_deal.php?mudi=upFileDel&dataID=3

No fix yet
Fix from $1,950 2024-07-10
Unclassified HIGH 8.7
CVE-2024-3798

Insecure handling of GET header parameter file included in requests being sent to an instance of the open-source project Phoniebox allows an attacker…

Mitigation only
Fix from $1,950 2024-07-10
Limesurvey HIGH 8.8
CVE-2024-39063

Lime Survey <= 6.5.12 is vulnerable to Cross Site Request Forgery (CSRF). The YII_CSRF_TOKEN is only checked when passed in the body of POST requests…

Fix: after 6.5.12
Fix from $1,950 2024-07-09
Idccms HIGH 8.8
CVE-2024-40034

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/userLevel_deal.php?mudi=del

No fix yet
Fix from $1,950 2024-07-09
Idccms MEDIUM 5.9
CVE-2024-40035

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/userLevel_deal.php?mudi=add.

No fix yet
Fix from $1,600 2024-07-09
Idccms HIGH 8.8
CVE-2024-40037

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/userScore_deal.php?mudi=del

No fix yet
Fix from $1,950 2024-07-09
Idccms MEDIUM 5.3
CVE-2024-40038

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/userScore_deal.php?mudi=rev

No fix yet
Fix from $1,600 2024-07-09
Idccms HIGH 8.8
CVE-2024-40039

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/userGroup_deal.php?mudi=del

No fix yet
Fix from $1,950 2024-07-09
Fortiaiops HIGH 8.8
CVE-2024-27783

Multiple cross-site request forgery (CSRF) weaknesses [CWE-352] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an unauthenticated remote attack…

Mitigation only
Fix from $1,950 2024-07-09
Unclassified MEDIUM 5.3
CVE-2024-4100

The Pricing Table plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.1. This is due to missin…

Mitigation only
Fix from $1,600 2024-07-09
Generate Pdf Using Contact Form 7 HIGH 8.8
CVE-2024-6316

The Generate PDF using Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, an…

Fix: 4.1.3+
Fix from $1,950 2024-07-09
Generate Pdf Using Contact Form 7 HIGH 8.8
CVE-2024-6317

The Generate PDF using Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, an…

Fix: 4.1.3+
Fix from $1,950 2024-07-09