Vulnerability index

Browse CVEs

7,362 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Openclaude MEDIUM 6.5
CVE-2026-42073

OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the OpenClaude MCP auth…

Fix: 0.5.1+
Fix from $1,600 2026-06-02
Unclassified MEDIUM 5.4
CVE-2026-34460

NamelessMC is website software for Minecraft servers. In versions 2.2.4 and prior, the OAuth callback handling does not validate the state parameter …

Mitigation only
Fix from $1,600 2026-06-02
Unclassified MEDIUM 5.3
CVE-2018-25435

ZeusCart 4.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of victims by crafti…

No fix yet
Fix from $1,600 2026-06-01
Unclassified MEDIUM 5.0
CVE-2026-49433

The DeepAI endpoint 'https://api.deepai.org/change_user_email' accepts POST requests without any CSRF protection. If an attacker can trick a logged-i…

Mitigation only
Fix from $1,600 2026-06-01
Unclassified MEDIUM 5.1
CVE-2026-40549

SOPlanning is vulnerable to Cross‑Site Request Forgery (CSRF) in groupe_save create, modify and delete endpoints. An attacker can craft a malicious w…

Mitigation only
Fix from $1,600 2026-06-01
Unclassified MEDIUM 5.3
CVE-2018-25397

PHP-SHOP 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to add administrative users by crafting malici…

No fix yet
Fix from $1,600 2026-05-29
Unclassified MEDIUM 5.3
CVE-2018-25387

HaPe PKH 1.1 contains a cross-site request forgery vulnerability that allows attackers to change administrator passwords by submitting forged request…

No fix yet
Fix from $1,600 2026-05-29
Avideo MEDIUM 6.5
CVE-2026-45610

WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cross-site request forgery vulnerability on the 2FA toggle. plugin/Logi…

Fix: after 29.0
Fix from $1,600 2026-05-29
Unclassified HIGH 8.1
CVE-2026-6075

The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.35 This is due to mi…

Mitigation only
Fix from $1,950 2026-05-29
Rest Data Services HIGH 7.9
CVE-2026-35266

Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Difficult to exploit vulnerabi…

Fix: after 26.1.0
Fix from $1,950 2026-05-28
Unclassified HIGH 8.1
CVE-2026-6455

The WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Deletion via SQL Injectio…

Mitigation only
Fix from $1,950 2026-05-28
Unclassified MEDIUM 6.5
CVE-2026-48147

Budibase is an open-source low-code platform. Prior to 3.35.4, the buildMatcherRegex() / matches() functions in packages/backend-core/src/middleware/…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 6.3
CVE-2026-30498

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the delete.php endpoint of Jason2605 AdminPanel 4.0.

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 6.1
CVE-2026-8906

The WP Promoter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing or…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 5.3
CVE-2026-49001

Cross-site request forgery (CSRF) vulnerabilities allow attackers to exploit a user's authenticated session to forge cross-site requests, inducing th…

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 6.1
CVE-2026-8911

The WP AutoBuzz plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.1. This is due to missing …

Mitigation only
Fix from $1,600 2026-05-27
Unclassified MEDIUM 6.5
CVE-2026-46620

e107 is a content management system (CMS). Prior to 2.3.5, e107 CMS does not properly enforce CSRF token validation on comment moderation actions. Th…

Mitigation only
Fix from $1,600 2026-05-26
Unclassified MEDIUM 5.7
CVE-2026-8174

Zohocorp Zoho Mail wordpress plugin is vulnerable to Cross-Site request forgery (CSRF). This issue affects Zoho Mail wordpress plugin versions befor…

Mitigation only
Fix from $1,600 2026-05-26
Unclassified HIGH 7.1
CVE-2026-39436

Cross-Site Request Forgery (CSRF) vulnerability in bgermann CformsII allows Cross Site Request Forgery. This issue affects CformsII: from n/a throug…

Mitigation only
Fix from $1,950 2026-05-25
Unclassified MEDIUM 6.5
CVE-2026-24574

Cross-Site Request Forgery (CSRF) vulnerability in Recorp Export WP Page to Static HTML/CSS allows Cross Site Request Forgery. This issue affects Ex…

Mitigation only
Fix from $1,600 2026-05-25
Unclassified MEDIUM 5.3
CVE-2018-25370

Admidio 3.3.5 contains a cross-site request forgery vulnerability that allows low-privilege users to increase their permissions by exploiting imprope…

No fix yet
Fix from $1,600 2026-05-25
Unclassified HIGH 7.1
CVE-2026-41074

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 through 6.0.2 contain a Cross-Site Request Forgery (CSRF) vul…

Mitigation only
Fix from $1,950 2026-05-22
Concrete Cms MEDIUM 6.5
CVE-2026-8435

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file approveVersion(). The Concrete CM…

Fix: 9.5.1+
Fix from $1,600 2026-05-21
Concrete Cms HIGH 8.8
CVE-2026-8413

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design. The Concrete CMS secu…

Fix: 9.5.1+
Fix from $1,950 2026-05-21
Concrete Cms HIGH 8.8
CVE-2026-8414

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/duplicate. The Concrete CMS secur…

Fix: 9.5.1+
Fix from $1,950 2026-05-21
Concrete Cms HIGH 8.8
CVE-2026-8415

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/association/reorder. The Concre…

Fix: 9.5.1+
Fix from $1,950 2026-05-21
Concrete Cms HIGH 8.8
CVE-2026-8416

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addFavoriteFolder($id). The Concr…

Fix: 9.5.1+
Fix from $1,950 2026-05-21
Concrete Cms HIGH 8.8
CVE-2026-8427

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file removeFavoriteFolder($id). The Co…

Fix: 9.5.1+
Fix from $1,950 2026-05-21
Concrete Cms HIGH 8.8
CVE-2026-8432

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star(). The Concrete CMS security…

Fix: 9.5.1+
Fix from $1,950 2026-05-21
Concrete Cms HIGH 8.8
CVE-2026-8433

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescan(). The Concrete CMS securi…

Fix: 9.5.1+
Fix from $1,950 2026-05-21