Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Unclassified HIGH 8.8
CVE-2024-6320

The ScrollTo Top plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and including, 1.2.2. T…

Mitigation only
Fix from $1,950 2024-07-09
Unclassified HIGH 8.8
CVE-2024-6321

The ScrollTo Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and including, 1.1.1…

Mitigation only
Fix from $1,950 2024-07-09
Unclassified HIGH 8.8
CVE-2024-6309

The Attachment File Icons (AF Icons) plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and…

Mitigation only
Fix from $1,950 2024-07-09
Unclassified HIGH 8.8
CVE-2024-6310

The Advanced AJAX Page Loader plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up to, and includ…

Mitigation only
Fix from $1,950 2024-07-09
Unclassified MEDIUM 5.4
CVE-2024-37923

Cross-Site Request Forgery (CSRF) vulnerability in cliengo Cliengo – Chatbot cliengo allows Cross Site Request Forgery.This issue affects Cliengo – C…

Mitigation only
Fix from $1,600 2024-07-09
Rtl819x Jungle Software Development Kit HIGH 8.8
CVE-2023-47677

A cross-site request forgery (csrf) vulnerability exists in the boa CSRF protection functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially …

No fix yet
Fix from $1,950 2024-07-08
Mediawiki MEDIUM 6.5
CVE-2024-40601

An issue was discovered in the MediaWikiChat extension for MediaWiki through 1.42.1. CSRF can occur in API modules.

Fix: after 1.42.1
Fix from $1,600 2024-07-07
Idccms MEDIUM 5.4
CVE-2024-39021

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/vpsApiData_deal.php?mudi=del

No fix yet
Fix from $1,600 2024-07-05
Idccms HIGH 8.8
CVE-2024-39022

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/infoSys_deal.php?mudi=deal

No fix yet
Fix from $1,950 2024-07-05
Idccms HIGH 8.8
CVE-2024-39023

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via admin/info_deal.php?mudi=add&nohrefStr=close

No fix yet
Fix from $1,950 2024-07-05
Idccms MEDIUM 5.4
CVE-2024-39019

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/idcProData_deal.php?mudi=del

No fix yet
Fix from $1,600 2024-07-05
Idccms MEDIUM 6.3
CVE-2024-39020

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/vpsApiData_deal.php?mudi=rev&nohrefStr=close

No fix yet
Fix from $1,600 2024-07-05
Eskooly MEDIUM 6.5
CVE-2024-27717

Cross Site Request Forgery vulnerability in Eskooly Free Online School Management Software v.3.0 and before allows a remote attacker to escalate priv…

Fix: after 3.0
Fix from $1,600 2024-07-05
Nested Pages HIGH 8.8
CVE-2024-5943

The Nested Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.7. This is due to missing…

Fix: 3.2.8+
Fix from $1,950 2024-07-04
Unclassified MEDIUM 5.4
CVE-2024-38344

A cross-site request forgery vulnerability exists in WP Tweet Walls versions prior to 1.0.4. If this vulnerability is exploited, an attacker allows a…

Mitigation only
Fix from $1,600 2024-07-04
Unclassified HIGH 8.1
CVE-2024-38345

A cross-site request forgery vulnerability exists in Sola Testimonials versions prior to 3.0.0. If this vulnerability is exploited, an attacker allow…

Mitigation only
Fix from $1,950 2024-07-04
Wpqa Builder HIGH 8.8
CVE-2024-2376

The WPQA Builder WordPress plugin before 6.1.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform …

Fix: 6.1.1+
Fix from $1,950 2024-07-03
Idccms MEDIUM 5.4
CVE-2024-39119

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/info_deal.php?mudi=rev&nohrefStr=close.

No fix yet
Fix from $1,600 2024-07-02
Sitetweet HIGH 8.8
CVE-2024-5767

The sitetweet WordPress plugin through 0.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allo…

Fix: after 0.2
Fix from $1,950 2024-07-02
Unclassified HIGH 8.8
CVE-2024-23736

Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Confluence allows attackers to manipulate a user's S/MIME cert…

Mitigation only
Fix from $1,950 2024-07-01
S Notify MEDIUM 5.4
CVE-2024-23737

Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Jira allows attackers to allows attackers to manipulate a user…

Fix: 2.0.1 / 4.0.2+
Fix from $1,600 2024-07-01
Infosphere Information Server HIGH 8.8
CVE-2024-31902

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorize…

Mitigation only
Fix from $1,950 2024-06-30
Floating Social Buttons MEDIUM 5.4
CVE-2024-6405

The Floating Social Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due t…

Fix: after 1.5
Fix from $1,600 2024-06-29
Devika HIGH 8.1
CVE-2024-5712

A Cross-Site Request Forgery (CSRF) vulnerability was identified in the stitionai/devika application, affecting the latest version. This vulnerabilit…

No fix yet
Fix from $1,950 2024-06-28
Privategpt MEDIUM 5.4
CVE-2024-5935

A Cross-Site Request Forgery (CSRF) vulnerability in version 0.5.0 of imartinez/privategpt allows an attacker to delete all uploaded files on the ser…

No fix yet
Fix from $1,600 2024-06-27
Idccms HIGH 8.8
CVE-2024-39158

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/userSys_deal.php?mudi=infoSet.

No fix yet
Fix from $1,950 2024-06-27
Idccms HIGH 8.8
CVE-2024-39154

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/keyWord_deal.php?mudi=del&dataType=word&dataTypeC…

No fix yet
Fix from $1,950 2024-06-27
Idccms MEDIUM 6.8
CVE-2024-39155

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ipRecord_deal.php?mudi=add.

No fix yet
Fix from $1,600 2024-06-27
Muslim Prayer Time Bd HIGH 7.6
CVE-2024-4758

The Muslim Prayer Time BD WordPress plugin through 2.4 does not have CSRF check in place when reseting its settings, which could allow attackers to m…

Fix: 2.5+
Fix from $1,950 2024-06-26
Logo Manager For Enamad HIGH 8.1
CVE-2024-4757

The Logo Manager For Enamad WordPress plugin through 0.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, …

Fix: after 0.7
Fix from $1,950 2024-06-25