Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Mainwp Child Reports MEDIUM 5.4
CVE-2024-33680

Cross-Site Request Forgery (CSRF) vulnerability in MainWP MainWP Child Reports.This issue affects MainWP Child Reports: from n/a through 2.1.1.

Fix: 2.2+
Fix from $1,600 2024-04-26
Mf Gig Calendar HIGH 8.8
CVE-2024-33651

Cross-Site Request Forgery (CSRF) vulnerability in Matthew Fries MF Gig Calendar.This issue affects MF Gig Calendar : from n/a through 1.2.1.

Fix: after 1.2.1
Fix from $1,950 2024-04-26
Unclassified MEDIUM 5.4
CVE-2024-33638

Cross-Site Request Forgery (CSRF) vulnerability in Brijesh Kothari Smart Maintenance Mode.This issue affects Smart Maintenance Mode: from n/a through…

Mitigation only
Fix from $1,600 2024-04-26
Enl Newsletter MEDIUM 5.4
CVE-2024-3058

The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which cou…

Fix: after 1.0.1
Fix from $1,600 2024-04-26
Enl Newsletter MEDIUM 5.7
CVE-2024-3059

The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF checks in some places, which could allow attackers to make logged in admins dele…

Fix: after 1.0.1
Fix from $1,600 2024-04-26
Unclassified CRITICAL 9.6
CVE-2024-30560

Cross-Site Request Forgery (CSRF) vulnerability in 大侠WP DX-Watermark.This issue affects DX-Watermark: from n/a through 1.0.4.

Mitigation only
Fix from $2,300 2024-04-25
Unclassified HIGH 7.1
CVE-2024-32958

Cross-Site Request Forgery (CSRF) vulnerability in Giorgos Sarigiannidis Slash Admin allows Cross-Site Scripting (XSS).This issue affects Slash Admin…

Mitigation only
Fix from $1,950 2024-04-24
Paid Memberships Pro HIGH 8.8
CVE-2024-32793

Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10.

Fix: 3.0+
Fix from $1,950 2024-04-24
Paid Memberships Pro HIGH 8.8
CVE-2024-32794

Cross-Site Request Forgery (CSRF) vulnerability in Paid Memberships Pro.This issue affects Paid Memberships Pro: from n/a through 2.12.10.

Fix: 3.0+
Fix from $1,950 2024-04-24
The Pack Elementor Addons MEDIUM 6.1
CVE-2024-32785

Cross-Site Request Forgery (CSRF) vulnerability in Webangon The Pack Elementor addons allows Cross-Site Scripting (XSS).This issue affects The Pack E…

Fix: 2.0.8.4+
Fix from $1,600 2024-04-24
Unclassified HIGH 7.1
CVE-2024-32789

Cross-Site Request Forgery (CSRF) vulnerability in Seers allows Cross-Site Scripting (XSS).This issue affects Seers: from n/a through 8.1.0.

Mitigation only
Fix from $1,950 2024-04-24
Woocommerce Customers Manager MEDIUM 6.5
CVE-2024-1756

The WooCommerce Customers Manager WordPress plugin before 29.8 does not have authorisation and CSRF in an AJAX action, allowing any authenticated use…

Fix: 29.8+
Fix from $1,600 2024-04-24
Unclassified HIGH 7.6
CVE-2024-32693

Cross-Site Request Forgery (CSRF) vulnerability in ValvePress Automatic.This issue affects Automatic: from n/a before 3.93.0.

Mitigation only
Fix from $1,950 2024-04-22
Unclassified MEDIUM 6.5
CVE-2024-32538

Cross-Site Request Forgery (CSRF) vulnerability in Joshua Eldridge Easy CountDowner allows Stored XSS.This issue affects Easy CountDowner: from n/a t…

Mitigation only
Fix from $1,600 2024-04-17
Unclassified HIGH 7.1
CVE-2024-32550

Cross-Site Request Forgery (CSRF) vulnerability in BMI Adult & Kid Calculator allows Stored XSS.This issue affects BMI Adult & Kid Calculator: from n…

Mitigation only
Fix from $1,950 2024-04-17
Unclassified HIGH 7.1
CVE-2024-32549

Cross-Site Request Forgery (CSRF) vulnerability in Microkid Related Posts for WordPress allows Cross-Site Scripting (XSS).This issue affects Related …

Mitigation only
Fix from $1,950 2024-04-17
Dolibarr Erp\/crm HIGH 7.5
CVE-2024-31503

Incorrect access control in Dolibarr ERP CRM versions 19.0.0 and before, allows authenticated attackers to steal victim users' session cookies and CS…

Fix: 19.0.1+
Fix from $1,950 2024-04-17
Complex Maintenance Repair And Overhaul MEDIUM 6.1
CVE-2024-21044

Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that a…

Fix: after 12.2.13
Fix from $1,600 2024-04-16
Complex Maintenance Repair And Overhaul MEDIUM 6.1
CVE-2024-21043

Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that a…

Fix: after 12.2.13
Fix from $1,600 2024-04-16
Complex Maintenance Repair And Overhaul MEDIUM 6.1
CVE-2024-21032

Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that a…

Fix: after 12.2.13
Fix from $1,600 2024-04-16
Complex Maintenance Repair And Overhaul MEDIUM 6.1
CVE-2024-21020

Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle E-Business Suite (component: LOV). Supported versions that a…

Fix: after 12.2.13
Fix from $1,600 2024-04-16
Wbsairback HIGH 8.8
CVE-2024-3782

Cross-Site Request Forgery vulnerability in WBSAirback 21.02.04, which could allow an attacker to create a manipulated HTML form to perform privilege…

Mitigation only
Fix from $1,950 2024-04-15
Unclassified MEDIUM 5.4
CVE-2024-31389

Cross-Site Request Forgery (CSRF) vulnerability in Ertano MihanPanel.This issue affects MihanPanel: from n/a before 12.7.

Mitigation only
Fix from $1,600 2024-04-15
Apppresser HIGH 8.8
CVE-2024-31374

Cross-Site Request Forgery (CSRF) vulnerability in Scott Bolinger AppPresser apppresser allows Cross Site Request Forgery.This issue affects AppPress…

Fix: 4.3.1+
Fix from $1,950 2024-04-15
Mailchimp Forms HIGH 8.8
CVE-2024-31378

Cross-Site Request Forgery (CSRF) vulnerability in MailMunch MailChimp Forms by MailMunch.This issue affects MailChimp Forms by MailMunch: from n/a t…

Fix: 3.2.2+
Fix from $1,950 2024-04-15
Blocksy HIGH 8.8
CVE-2024-31382

Cross-Site Request Forgery (CSRF) vulnerability in creativethemeshq Blocksy blocksy.This issue affects Blocksy: from n/a through <= 2.0.22.

Fix: 2.0.23+
Fix from $1,950 2024-04-15
E2pdf MEDIUM 5.4
CVE-2024-31373

Cross-Site Request Forgery (CSRF) vulnerability in E2Pdf e2pdf e2pdf.This issue affects e2pdf: from n/a through <= 1.20.27.

Fix: 1.23.00+
Fix from $1,600 2024-04-15
Unclassified MEDIUM 5.4
CVE-2024-31933

Cross-Site Request Forgery (CSRF) vulnerability in Live Composer Team Page Builder: Live Composer.This issue affects Page Builder: Live Composer: fro…

Mitigation only
Fix from $1,600 2024-04-15
Sarada HIGH 8.8
CVE-2024-31429

Cross-Site Request Forgery (CSRF) vulnerability in Blossom Themes Sarada Lite.This issue affects Sarada Lite: from n/a through 1.1.2.

Fix: 1.1.3+
Fix from $1,950 2024-04-15
Unclassified MEDIUM 5.4
CVE-2024-31434

Cross-Site Request Forgery (CSRF) vulnerability in Stefano Lissa & The Newsletter Team Newsletter.This issue affects Newsletter: from n/a through 8.0…

Mitigation only
Fix from $1,600 2024-04-15