Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Easy Digital Downloads HIGH 8.8
CVE-2024-31293

Cross-Site Request Forgery (CSRF) vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.6.

Fix: 3.2.7+
Fix from $1,950 2024-04-12
Multiple Page Generator HIGH 8.8
CVE-2024-31301

Cross-Site Request Forgery (CSRF) vulnerability in Themeisle Multiple Page Generator Plugin – MPG.This issue affects Multiple Page Generator Plugin –…

Fix: 3.4.1+
Fix from $1,950 2024-04-12
Apppresser HIGH 8.8
CVE-2024-31268

Cross-Site Request Forgery (CSRF) vulnerability in AppPresser Team AppPresser.This issue affects AppPresser: from n/a through 4.3.0.

Fix: 4.3.1+
Fix from $1,950 2024-04-12
Easy Google Maps HIGH 8.8
CVE-2024-31269

Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Easy Google Maps.This issue affects Easy Google Maps: from n/a through 1.11.11.

Fix: 1.11.12+
Fix from $1,950 2024-04-12
Arforms Form Builder MEDIUM 6.3
CVE-2024-31272

Cross-Site Request Forgery (CSRF) vulnerability in Repute InfoSystems ARForms Form Builder.This issue affects ARForms Form Builder: from n/a through …

Fix: 1.6.2+
Fix from $1,600 2024-04-12
Unclassified MEDIUM 5.4
CVE-2024-31262

Cross-Site Request Forgery (CSRF) vulnerability in Jcodex WooCommerce Checkout Field Editor (Checkout Manager).This issue affects WooCommerce Checkou…

Mitigation only
Fix from $1,600 2024-04-12
Unclassified MEDIUM 5.4
CVE-2024-31263

Cross-Site Request Forgery (CSRF) vulnerability in aerin Loan Repayment Calculator and Application Form.This issue affects Loan Repayment Calculator …

Mitigation only
Fix from $1,600 2024-04-12
Smart Online Order For Clover HIGH 8.8
CVE-2024-31238

Cross-Site Request Forgery (CSRF) vulnerability in Zaytech Smart Online Order for Clover.This issue affects Smart Online Order for Clover: from n/a t…

Fix: 1.5.6+
Fix from $1,950 2024-04-12
Form Tools MEDIUM 6.3
CVE-2024-22721

Cross Site Request Forgery (CSRF) vulnerability in Form Tools 3.1.1 allows attackers to manipulate sensitive user data via crafted link.

No fix yet
Fix from $1,600 2024-04-11
Unclassified MEDIUM 5.4
CVE-2024-31936

Cross-Site Request Forgery (CSRF) vulnerability in AyeCode Ltd UsersWP.This issue affects UsersWP: from n/a before 1.2.6.

Mitigation only
Fix from $1,600 2024-04-11
Wp Compress HIGH 8.8
CVE-2024-32106

Cross-Site Request Forgery (CSRF) vulnerability in WP Compress WP Compress – Image Optimizer [All-In-One].This issue affects WP Compress – Image Opti…

Fix: 6.11.01+
Fix from $1,950 2024-04-11
Blocksy Companion HIGH 8.8
CVE-2024-31932

Cross-Site Request Forgery (CSRF) vulnerability in CreativeThemes Blocksy Companion.This issue affects Blocksy Companion: from n/a through 2.0.28.

Fix: 2.0.29+
Fix from $1,950 2024-04-11
Unclassified HIGH 7.1
CVE-2024-31285

Cross-Site Request Forgery (CSRF) vulnerability in Tooltip WordPress Tooltips allows Stored XSS.This issue affects WordPress Tooltips: from n/a throu…

Mitigation only
Fix from $1,950 2024-04-11
Ninja Forms HIGH 8.8
CVE-2024-25572

Cross-site request forgery (CSRF) vulnerability exists in Ninja Forms prior to 3.4.31. If a website administrator views a malicious page while loggin…

Fix: 3.4.31+
Fix from $1,950 2024-04-11
Unclassified HIGH 7.1
CVE-2024-2741

Cross-Site Request Forgery (CSRF) vulnerability in Planet IGS-4215-16T2S, affecting firmware version 1.305b210528. This vulnerability could allow a r…

Mitigation only
Fix from $1,950 2024-04-11
Unclassified HIGH 8.1
CVE-2024-29019

ESPHome is a system to control microcontrollers remotely through Home Automation systems. API endpoints in dashboard component of ESPHome version 202…

No fix yet
Fix from $1,950 2024-04-11
Dsgvo All In One For Wp HIGH 8.8
CVE-2024-27967

Cross-Site Request Forgery (CSRF) vulnerability in Michael Leithold DSGVO All in one for WP.This issue affects DSGVO All in one for WP: from n/a thro…

Fix: 4.4+
Fix from $1,950 2024-04-11
Xwiki HIGH 8.8
CVE-2024-31988

XWiki Platform is a generic wiki platform. Starting in version 13.9-rc-1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, when the realtime edi…

Fix: 14.10.19 / 15.5.4+
Fix from $1,950 2024-04-10
Xwiki MEDIUM 5.4
CVE-2024-31985

XWiki Platform is a generic wiki platform. Starting in version 3.1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, it is possible to schedule/…

Fix: 14.10.19 / 15.5.4+
Fix from $1,600 2024-04-10
Xwiki HIGH 8.8
CVE-2024-31986

XWiki Platform is a generic wiki platform. Starting in version 3.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, by creating a document with…

Fix: 14.10.19 / 15.5.4+
Fix from $1,950 2024-04-10
Bear Woocommerce Bulk Editor And Products Manager Professional HIGH 8.8
CVE-2024-31430

Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional, realmag777 BEAR – Bulk Edi…

Fix: 1.0.8.2 / 1.1.4.2+
Fix from $1,950 2024-04-10
Unclassified HIGH 7.1
CVE-2024-31299

Cross-Site Request Forgery (CSRF) vulnerability in Reservation Diary ReDi Restaurant Reservation allows Cross-Site Scripting (XSS).This issue affects…

Mitigation only
Fix from $1,950 2024-04-10
Aim HIGH 8.8
CVE-2024-2196

aimhubio/aim is vulnerable to Cross-Site Request Forgery (CSRF), allowing attackers to perform actions such as deleting runs, updating data, and stea…

No fix yet
Fix from $1,950 2024-04-10
S Notify MEDIUM 5.2
CVE-2024-23734

Cross Site Request Forgery vulnerability in in the upload functionality of the User Profile pages in savignano S/Notify before 2.0.1 for Bitbucket al…

Fix: 2.0.1+
Fix from $1,600 2024-04-10
Leantime HIGH 8.8
CVE-2024-27474

Leantime 3.0.6 is vulnerable to Cross Site Request Forgery (CSRF). This vulnerability allows malicious actors to perform unauthorized actions on beha…

No fix yet
Fix from $1,950 2024-04-10
Envialosimple HIGH 8.8
CVE-2024-2125

The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin…

Fix: 2.4+
Fix from $1,950 2024-04-09
Classified Listing HIGH 8.8
CVE-2024-1315

The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions …

Fix: 3.0.5+
Fix from $1,950 2024-04-09
Zeppelin MEDIUM 5.4
CVE-2021-28656

Cross-Site Request Forgery (CSRF) vulnerability in Credential page of Apache Zeppelin allows an attacker to submit malicious request. This issue aff…

Fix: after 0.9.0
Fix from $1,600 2024-04-09
Soledad MEDIUM 5.4
CVE-2024-31369

Cross-Site Request Forgery (CSRF) vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2.

Fix: 8.4.6+
Fix from $1,600 2024-04-09
Savane MEDIUM 6.0
CVE-2024-27631

Cross Site Request Forgery vulnerability in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via siteadmin/usergroup.php

Fix: 3.13+
Fix from $1,600 2024-04-08