Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Trudesk MEDIUM 6.5
CVE-2021-45785

TruDesk Help Desk/Ticketing Solution v1.1.11 is vulnerable to a Cross-Site Request Forgery (CSRF) attack which would allow an attacker to restart the…

No fix yet
Fix from $1,600 2024-06-24
Lollms MEDIUM 6.3
CVE-2024-4499

A Cross-Site Request Forgery (CSRF) vulnerability exists in the XTTS server of parisneo/lollms version 9.6 due to a lax CORS policy. The vulnerabilit…

No fix yet
Fix from $1,600 2024-06-24
Unclassified MEDIUM 6.3
CVE-2024-5596

The ARMember Premium plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.7. This is due to incorrect…

Mitigation only
Fix from $1,600 2024-06-22
Ubermenu MEDIUM 5.4
CVE-2024-3593

The UberMenu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.3. This is due to missing or …

Fix: 3.8.4+
Fix from $1,600 2024-06-22
Newsletters HIGH 8.8
CVE-2024-37227

Cross Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a through 4.9.7.

Fix: 4.9.8+
Fix from $1,950 2024-06-21
Book Landing Page HIGH 8.8
CVE-2024-37230

Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Book Landing Page.This issue affects Book Landing Page: from n/a through 1.2.3.

Fix: 1.2.4+
Fix from $1,950 2024-06-21
Uncanny Automator HIGH 8.8
CVE-2024-37118

Cross Site Request Forgery (CSRF) vulnerability in Uncanny Owl Uncanny Automator Pro.This issue affects Uncanny Automator Pro: from n/a through 5.3.

Fix: after 5.3
Fix from $1,950 2024-06-21
Digital Newspaper HIGH 8.8
CVE-2024-37198

Cross-Site Request Forgery (CSRF) vulnerability in blazethemes Digital Newspaper.This issue affects Digital Newspaper: from n/a through 1.1.5.

Fix: 1.1.6+
Fix from $1,950 2024-06-21
Aliexpress Dropshipping With Alinext HIGH 8.8
CVE-2024-37212

Cross-Site Request Forgery (CSRF) vulnerability in Ali2Woo Ali2Woo Lite.This issue affects Ali2Woo Lite: from n/a through 3.3.5.

Fix: after 3.3.5
Fix from $1,950 2024-06-21
Hueman HIGH 8.8
CVE-2024-35772

Cross-Site Request Forgery (CSRF) vulnerability in presscustomizr Hueman.This issue affects Hueman: from n/a through 3.7.24.

Fix: 3.7.25+
Fix from $1,950 2024-06-21
Vimeography HIGH 8.8
CVE-2024-35770

Cross-Site Request Forgery (CSRF) vulnerability in Dave Kiss Vimeography: Vimeo Video Gallery WordPress Plugin.This issue affects Vimeography: Vimeo …

Fix: 2.4.2+
Fix from $1,950 2024-06-21
Customizr HIGH 8.8
CVE-2024-35771

Cross-Site Request Forgery (CSRF) vulnerability in presscustomizr Customizr.This issue affects Customizr: from n/a through 4.4.21.

Fix: 4.4.22+
Fix from $1,950 2024-06-21
Commonsbooking MEDIUM 6.5
CVE-2024-4382

The CB (legacy) WordPress plugin through 0.9.4.18 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admin…

Fix: after 0.9.4.18
Fix from $1,600 2024-06-21
Gamipress MEDIUM 6.3
CVE-2023-25697

Cross-Site Request Forgery (CSRF) vulnerability in GamiPress.This issue affects GamiPress: from n/a through 2.5.6.

Fix: 2.5.7+
Fix from $1,600 2024-06-19
Unclassified MEDIUM 6.8
CVE-2024-5676

The Paradox IP150 Internet Module in version 1.40.00 is vulnerable to Cross-Site Request Forgery (CSRF) attacks due to a lack of countermeasures and …

Mitigation only
Fix from $1,600 2024-06-19
Paid Memberships Pro MEDIUM 5.4
CVE-2024-1407

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forg…

Fix: 3.0+
Fix from $1,600 2024-06-19
Unclassified HIGH 8.8
CVE-2024-5343

The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in…

Mitigation only
Fix from $1,950 2024-06-19
Fedora HIGH 8.8
CVE-2024-38276

Incorrect CSRF token checks resulted in multiple CSRF risks.

Fix: 4.1.10 / 4.2.8+
Fix from $1,950 2024-06-18
Xenforo HIGH 8.8
CVE-2024-38457EPSS 7%

Xenforo before 2.2.16 allows CSRF.

Fix: 2.2.16+
Fix from $1,950 2024-06-16
Prayer MEDIUM 6.1
CVE-2024-4480

The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its email settings, which could allow attackers to ma…

Fix: after 2.4.7
Fix from $1,600 2024-06-14
Inquiry Cart MEDIUM 6.1
CVE-2024-5155

The Inquiry cart WordPress plugin through 3.4.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could…

No fix yet
Fix from $1,600 2024-06-14
Wp Staging HIGH 8.8
CVE-2024-5551

The WP STAGING Pro WordPress Backup Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.6…

Fix: 5.6.1+
Fix from $1,950 2024-06-14
Pray For Me MEDIUM 5.4
CVE-2024-3965

The Pray For Me WordPress plugin through 1.0.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a lo…

Fix: after 1.0.4
Fix from $1,600 2024-06-14
Computer Vision Annotation Tool HIGH 7.1
CVE-2024-37306

Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. Starting in version 2.2.0 and prior to …

Fix: 2.14.3+
Fix from $1,950 2024-06-13
Alcasar CRITICAL 9.6
CVE-2024-38293

ALCASAR before 3.6.1 allows CSRF and remote code execution in activity.php.

Fix: 3.6.1+
Fix from $2,300 2024-06-13
Sinec Traffic Analyzer HIGH 7.8
CVE-2024-35207

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The web interface of the affected devices a…

Fix: 1.2+
Fix from $1,950 2024-06-11
Emlog MEDIUM 6.5
CVE-2024-31612

Emlog pro2.3 is vulnerable to Cross Site Request Forgery (CSRF) via twitter.php which can be used with a XSS vulnerability to access administrator in…

No fix yet
Fix from $1,600 2024-06-10
Bosscms MEDIUM 5.4
CVE-2024-31613

BOSSCMS v3.10 is vulnerable to Cross Site Request Forgery (CSRF) in name="head_code" or name="foot_code."

No fix yet
Fix from $1,600 2024-06-10
Lollms Webui HIGH 8.8
CVE-2024-4403

A Cross-Site Request Forgery (CSRF) vulnerability exists in the restart_program function of the parisneo/lollms-webui v9.6. This vulnerability allows…

No fix yet
Fix from $1,950 2024-06-10
Unclassified MEDIUM 6.5
CVE-2024-5786

Cross-Site Request Forgery vulnerability in Comtrend router WLD71-T1_v2.0.201820, affecting the GRG-4280us version. This vulnerability allows an atta…

Mitigation only
Fix from $1,600 2024-06-10