Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
GitLab MEDIUM 6.5
CVE-2024-4597

An issue has been discovered in GitLab EE affecting all versions from 16.7 before 16.9.7, all versions starting from 16.10 before 16.10.5, all versio…

Fix: 16.9.7 / 16.10.5+
Fix from $1,600 2024-05-14
Recaptcha Jetpack HIGH 8.8
CVE-2024-3940

The reCAPTCHA Jetpack WordPress plugin through 0.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to mak…

Fix: after 0.2.2
Fix from $1,950 2024-05-14
Add Custom Css And Js HIGH 7.1
CVE-2024-3903

The Add Custom CSS and JS WordPress plugin through 1.20 does not have CSRF check in some places, and is missing sanitisation as well as escaping, whi…

Fix: after 1.20
Fix from $1,950 2024-05-14
Letterpress MEDIUM 6.1
CVE-2024-3590

The LetterPress WordPress plugin through 1.2.2 does not have CSRF checks in some places, which could allow attackers to make logged in users perform…

Fix: after 1.2.2
Fix from $1,600 2024-05-14
Unclassified HIGH 7.1
CVE-2024-34818

Cross-Site Request Forgery (CSRF) vulnerability in WebinarPress.This issue affects WebinarPress: from n/a through 1.33.17.

Mitigation only
Fix from $1,950 2024-05-14
Unclassified MEDIUM 5.4
CVE-2024-34816

Cross-Site Request Forgery (CSRF) vulnerability in Revmakx WPCal.Io – Easy Meeting Scheduler.This issue affects WPCal.Io – Easy Meeting Scheduler: fr…

Mitigation only
Fix from $1,600 2024-05-14
Unyson MEDIUM 5.4
CVE-2024-34814

Cross-Site Request Forgery (CSRF) vulnerability in Unyson Unyson unyson.This issue affects Unyson: from n/a through <= 2.7.29.

Fix: 2.7.31+
Fix from $1,600 2024-05-14
Easy Digital Downloads HIGH 8.8
CVE-2024-31113

Cross-Site Request Forgery (CSRF) vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.11.

Fix: 3.2.12+
Fix from $1,950 2024-05-14
Unclassified HIGH 7.1
CVE-2024-4600

Cross-Site Request Forgery vulnerability in Socomec Net Vision, version 7.20. This vulnerability could allow an attacker to trick registered users in…

Mitigation only
Fix from $1,950 2024-05-07
Unclassified HIGH 7.1
CVE-2024-34367

Cross-Site Request Forgery (CSRF) vulnerability in Popup Box Team Popup box allows Cross-Site Scripting (XSS).This issue affects Popup box: from n/a …

Mitigation only
Fix from $1,950 2024-05-06
Debian Linux HIGH 7.5
CVE-2024-34069

Werkzeug is a comprehensive WSGI web application library. The debugger in affected versions of Werkzeug can allow an attacker to execute code on a de…

Fix: 3.0.3+
Fix from $1,950 2024-05-06
Idccms MEDIUM 5.4
CVE-2024-33829

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/readDeal.php?mudi=updateWebCache.

No fix yet
Fix from $1,600 2024-05-06
Idccms HIGH 8.1
CVE-2024-33830

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/readDeal.php?mudi=clearWebCache.

No fix yet
Fix from $1,950 2024-05-06
Mf Gig Calendar HIGH 7.5
CVE-2024-3756

The MF Gig Calendar WordPress plugin through 1.2.1 does not have CSRF checks in some places, which could allow attackers to make logged in Contributo…

Fix: after 1.2.1
Fix from $1,950 2024-05-06
Fedora CRITICAL 9.8
CVE-2024-34502

An issue was discovered in WikibaseLexeme in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. Loading Special:MergeLexemes wi…

Fix: 1.39.6 / 1.40.2+
Fix from $2,300 2024-05-05
Unclassified MEDIUM 5.4
CVE-2023-7065

The Stop Spammers Security | Block Spam Users, Comments, Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to…

Mitigation only
Fix from $1,600 2024-05-04
Unclassified MEDIUM 6.1
CVE-2024-0613

The Delete Custom Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.3.1. This is due to…

Mitigation only
Fix from $1,600 2024-05-02
Unclassified CRITICAL 9.6
CVE-2024-33913

Cross-Site Request Forgery (CSRF) vulnerability leading to Arbitrary File Upload in Xserver Migrator.This issue affects Xserver Migrator: from n/a th…

Mitigation only
Fix from $2,300 2024-05-02
Herd Effects MEDIUM 6.1
CVE-2024-3478

The Herd Effects WordPress plugin before 5.2.7 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins …

Fix: 5.2.7+
Fix from $1,600 2024-05-02
Counter Box MEDIUM 5.2
CVE-2024-3481

The Counter Box WordPress plugin before 1.2.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins p…

Fix: 1.2.4+
Fix from $1,600 2024-05-02
Modal Window MEDIUM 5.9
CVE-2024-3472

The Modal Window WordPress plugin before 5.3.10 does not have CSRF check in place when bulk deleting modals, which could allow attackers to make a l…

Fix: 5.3.10+
Fix from $1,600 2024-05-02
Wow Skype Buttons HIGH 8.8
CVE-2024-3474

The Wow Skype Buttons WordPress plugin before 4.0.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in adm…

Fix: 4.0.4+
Fix from $1,950 2024-05-02
Sticky Buttons HIGH 7.5
CVE-2024-3475

The Sticky Buttons WordPress plugin before 3.2.4 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admin…

Fix: 3.2.4+
Fix from $1,950 2024-05-02
Side Menu Lite HIGH 8.8
CVE-2024-3476

The Side Menu Lite WordPress plugin before 4.2.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admin…

Fix: 4.2.1+
Fix from $1,950 2024-05-02
Unclassified CRITICAL 9.8
CVE-2024-33449

An SSRF issue in the PDFMyURL service allows a remote attacker to obtain sensitive information and execute arbitrary code via a POST request in the u…

Mitigation only
Fix from $2,300 2024-04-29
Unclassified HIGH 7.1
CVE-2024-33681

Cross-Site Request Forgery (CSRF) vulnerability in Sandor Kovacs Regenerate post permalink allows Cross-Site Scripting (XSS).This issue affects Regen…

Mitigation only
Fix from $1,950 2024-04-29
Unclassified MEDIUM 5.4
CVE-2024-33632

Cross-Site Request Forgery (CSRF) vulnerability in Piotnet Piotnet Addons For Elementor Pro.This issue affects Piotnet Addons For Elementor Pro: from…

Mitigation only
Fix from $1,600 2024-04-29
Unclassified HIGH 7.1
CVE-2024-33646

Cross-Site Request Forgery (CSRF) vulnerability in Toast Plugins Sticky Anything allows Cross-Site Scripting (XSS).This issue affects Sticky Anything…

Mitigation only
Fix from $1,950 2024-04-29
Teluro HIGH 8.8
CVE-2024-33688

Cross-Site Request Forgery (CSRF) vulnerability in Extend Themes Teluro.This issue affects Teluro: from n/a through 1.0.31.

Fix: 1.0.36+
Fix from $1,950 2024-04-26
Unclassified MEDIUM 5.4
CVE-2024-33682

Cross-Site Request Forgery (CSRF) vulnerability in Cookie Information A/S WP GDPR Compliance.This issue affects WP GDPR Compliance: from n/a through …

Mitigation only
Fix from $1,600 2024-04-26