Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Lollms Web Ui HIGH 8.1
CVE-2024-4328

A Cross-Site Request Forgery (CSRF) vulnerability exists in the clear_personality_files_list function of the parisneo/lollms-webui v9.6. The vulnerab…

No fix yet
Fix from $1,950 2024-06-10
Unclassified MEDIUM 5.4
CVE-2024-35657

Cross-Site Request Forgery (CSRF) vulnerability in Plechev Andrey WP-Recall.This issue affects WP-Recall: from n/a through 16.26.6.

Mitigation only
Fix from $1,600 2024-06-08
Analytify Google Analytics Dashboard HIGH 8.8
CVE-2024-35689

Cross-Site Request Forgery (CSRF) vulnerability in Analytify.This issue affects Analytify: from n/a through 5.2.3.

Fix: 5.2.4+
Fix from $1,950 2024-06-08
Wp Stacker MEDIUM 5.4
CVE-2024-5003

The WP Stacker WordPress plugin through 1.8.5 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could a…

Fix: after 1.8.5
Fix from $1,600 2024-06-07
Lollms Web Ui HIGH 8.3
CVE-2024-2288

A Cross-Site Request Forgery (CSRF) vulnerability exists in the profile picture upload functionality of the Lollms application, specifically in the p…

Fix: 9.3+
Fix from $1,950 2024-06-06
Autogpt Classic HIGH 8.8
CVE-2024-1879

A Cross-Site Request Forgery (CSRF) vulnerability in significant-gravitas/autogpt version v0.5.0 allows attackers to execute arbitrary commands on th…

Patch available
Fix from $1,950 2024-06-06
The Moneytizer MEDIUM 5.4
CVE-2023-6968

The The Moneytizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.6.3. This is due to missi…

Fix: 10.0.1+
Fix from $1,600 2024-06-06
Idccms HIGH 8.8
CVE-2024-36667

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/idcProType_deal.php?mudi=add&nohrefStr=close

No fix yet
Fix from $1,950 2024-06-05
Idccms HIGH 8.8
CVE-2024-36668

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/type_deal.php?mudi=del

No fix yet
Fix from $1,950 2024-06-05
Idccms HIGH 8.8
CVE-2024-36669

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/type_deal.php?mudi=add.

No fix yet
Fix from $1,950 2024-06-05
Idccms HIGH 8.8
CVE-2024-36670

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/vpsClass_deal.php?mudi=del

No fix yet
Fix from $1,950 2024-06-05
Idccms HIGH 8.8
CVE-2024-36547

idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/vpsClass_deal.php?mudi=add

No fix yet
Fix from $1,950 2024-06-04
Idccms HIGH 8.8
CVE-2024-36548

idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/vpsCompany_deal.php?mudi=del

No fix yet
Fix from $1,950 2024-06-04
Idccms HIGH 8.8
CVE-2024-36549

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/vpsCompany_deal.php?mudi=rev&nohrefStr=close

No fix yet
Fix from $1,950 2024-06-04
Idccms HIGH 8.8
CVE-2024-36550

idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/vpsCompany_deal.php?mudi=add&nohrefStr=close

No fix yet
Fix from $1,950 2024-06-04
Moodle HIGH 8.8
CVE-2024-34007

The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged out via CSRF.

Fix: 4.3.4+
Fix from $1,950 2024-05-31
Moodle HIGH 8.8
CVE-2024-34008

Actions in the admin management of analytics models did not include the necessary token to prevent a CSRF risk.

Fix: 4.1.10 / 4.2.7+
Fix from $1,950 2024-05-31
Moodle HIGH 8.4
CVE-2024-34001

Actions in the admin preset tool did not include the necessary token to prevent a CSRF risk.

Fix: 4.1.10 / 4.2.7+
Fix from $1,950 2024-05-31
Unclassified MEDIUM 6.5
CVE-2024-4218

The AffiEasy plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.6. This is due to plugin impr…

Mitigation only
Fix from $1,600 2024-05-30
Unclassified HIGH 7.3
CVE-2024-5185

The EmbedAI application is susceptible to security issues that enable Data Poisoning attacks. This weakness could result in the application becoming …

Mitigation only
Fix from $1,950 2024-05-29
Imanager HIGH 7.4
CVE-2024-4429

Cross-Site Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to sensitive information disclosure.

Fix: 3.2.6+
Fix from $1,950 2024-05-28
Business Card HIGH 7.1
CVE-2024-4531

The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perfor…

No fix yet
Fix from $1,950 2024-05-27
Business Card MEDIUM 6.4
CVE-2024-4532

The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perfor…

No fix yet
Fix from $1,600 2024-05-27
Kkprogressbar2 MEDIUM 6.1
CVE-2024-4534

The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, w…

No fix yet
Fix from $1,600 2024-05-27
Kkprogressbar2 HIGH 8.8
CVE-2024-4535

The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not have CSRF checks in some places, which could allow attackers to make logged in use…

No fix yet
Fix from $1,950 2024-05-27
Business Card MEDIUM 5.0
CVE-2024-4529

The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perfor…

No fix yet
Fix from $1,600 2024-05-27
Business Card MEDIUM 6.3
CVE-2024-4530

The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perfor…

No fix yet
Fix from $1,600 2024-05-27
Mattermost Server MEDIUM 5.7
CVE-2024-36255

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper input validation on post actions which allows an attack…

Fix: 8.1.13 / 9.5.4+
Fix from $1,600 2024-05-26
GitLab MEDIUM 6.1
CVE-2023-7045

A CSRF vulnerability exists within GitLab CE/EE from versions 13.11 before 16.10.6, from 16.11 before 16.11.3, from 17.0 before 17.0.1. By leveraging…

Fix: 16.10.6 / 16.11.3+
Fix from $1,600 2024-05-23
Idccms HIGH 8.8
CVE-2024-35552

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=del&dataType=logo&dataType…

No fix yet
Fix from $1,950 2024-05-22