Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Dont Muck My Markup HIGH 8.8
CVE-2024-23510

Cross-Site Request Forgery (CSRF) vulnerability in Martyn Chamberlin Don't Muck My Markup.This issue affects Don't Muck My Markup: from n/a through 1…

Fix: after 1.8
Fix from $1,950 2024-03-27
Unclassified MEDIUM 5.4
CVE-2024-23515

Cross-Site Request Forgery (CSRF) vulnerability in Cincopa Post Video Players.This issue affects Post Video Players: from n/a through 1.159.

Mitigation only
Fix from $1,600 2024-03-27
Countdown Widget MEDIUM 6.1
CVE-2022-45847

Cross-Site Request Forgery (CSRF) vulnerability in WPAssist.Me WordPress Countdown Widget allows Cross-Site Scripting (XSS).This issue affects WordPr…

Fix: after 3.1.9.1
Fix from $1,600 2024-03-27
Dedecms CRITICAL 9.8
CVE-2024-29684

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /src/dede/makehtml_homepage.php allowing a remote attack…

No fix yet
Fix from $2,300 2024-03-26
Calliope HIGH 8.8
CVE-2024-2904

Cross-Site Request Forgery (CSRF) vulnerability in Extend Themes Calliope.This issue affects Calliope: from n/a through 1.0.33.

Fix: 1.0.35+
Fix from $1,950 2024-03-26
Unclassified MEDIUM 6.5
CVE-2023-51416

Cross-Site Request Forgery (CSRF) vulnerability in EnvialoSimple EnvíaloSimple.This issue affects EnvíaloSimple: from n/a through 2.2.

Mitigation only
Fix from $1,600 2024-03-26
Cm Download Manager MEDIUM 6.8
CVE-2024-1231

The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins…

Fix: 2.9.0+
Fix from $1,600 2024-03-25
Cm Download Manager HIGH 8.8
CVE-2024-1962

The CM Download Manager WordPress plugin before 2.9.1 does not have CSRF checks in some places, which could allow attackers to make logged in admins…

Fix: 2.9.1+
Fix from $1,950 2024-03-25
Unclassified MEDIUM 6.1
CVE-2024-29009

Cross-site request forgery (CSRF) vulnerability in easy-popup-show all versions allows a remote unauthenticated attacker to hijack the authentication…

Mitigation only
Fix from $1,600 2024-03-25
Anchor Cms HIGH 7.4
CVE-2024-29499

Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via /anchor/admin/users/delete/2.

No fix yet
Fix from $1,950 2024-03-22
Loadmaster HIGH 7.5
CVE-2024-2449EPSS 13%

A cross-site request forgery vulnerability has been identified in LoadMaster.  It is possible for a malicious actor, who has prior knowledge of the I…

Fix: 7.2.54.9 / 7.2.59.3+
Fix from $1,950 2024-03-22
Ac15 Firmware MEDIUM 6.5
CVE-2024-2816

A vulnerability classified as problematic was found in Tenda AC15 15.03.05.18. Affected by this vulnerability is the function fromSysToolReboot of th…

No fix yet
Fix from $1,600 2024-03-22
Ac15 Firmware MEDIUM 6.5
CVE-2024-2817

A vulnerability, which was classified as problematic, has been found in Tenda AC15 15.03.05.18. Affected by this issue is the function fromSysToolRes…

No fix yet
Fix from $1,600 2024-03-22
Lychee HIGH 8.3
CVE-2024-25808

Cross-site Request Forgery (CSRF) vulnerability in Lychee version 3.1.6, allows remote attackers to execute arbitrary code via the create new album f…

No fix yet
Fix from $1,950 2024-03-22
Super Page Cache MEDIUM 6.1
CVE-2024-27968

Cross-Site Request Forgery (CSRF) vulnerability in Optimole Super Page Cache for Cloudflare allows Stored XSS.This issue affects Super Page Cache for…

Fix: after 4.7.5
Fix from $1,600 2024-03-21
File Manager HIGH 8.8
CVE-2024-1538EPSS 11%

The File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.4. This is due to missing…

Fix: 7.2.5+
Fix from $1,950 2024-03-21
Owncast CRITICAL 9.1
CVE-2024-29026

Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. In versions 0.1.2 and prior, a lenient CORS …

Fix: after 0.1.2
Fix from $2,300 2024-03-20
Appointment Booking Calendar HIGH 8.8
CVE-2024-0856

The Appointment Booking Calendar WordPress plugin before 1.3.83 does not have CSRF checks in some places, which could allow attackers to make logged …

Fix: 1.3.83+
Fix from $1,950 2024-03-20
Unclassified MEDIUM 5.4
CVE-2024-1785

The Contests by Rewards Fuel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.62. This is d…

Mitigation only
Fix from $1,600 2024-03-20
Unclassified HIGH 8.1
CVE-2024-24336

A multiple Cross-site scripting (XSS) vulnerability in the '/members/moremember.pl', and ‘/members/members-home.pl’ endpoints within Koha Library Man…

Mitigation only
Fix from $1,950 2024-03-19
Wicket MEDIUM 6.5
CVE-2024-27439

An error in the evaluation of the fetch metadata headers could allow a bypass of the CSRF protection in Apache Wicket. This issue affects Apache Wick…

Fix: 9.17.0+
Fix from $1,600 2024-03-19
Enjoy Social Feed HIGH 8.8
CVE-2024-0779

The Enjoy Social Feed plugin for WordPress website WordPress plugin through 6.2.2 does not have authorisation and CSRF in various function hooked to …

Fix: after 6.2.2
Fix from $1,950 2024-03-18
Innovs Hr HIGH 8.8
CVE-2024-0858

The Innovs HR WordPress plugin through 1.0.3.4 does not have CSRF checks in some places, which could allow attackers to make logged in users perform …

Fix: after 1.0.3.4
Fix from $1,950 2024-03-18
Unclassified MEDIUM 6.1
CVE-2024-22475

Cross-site request forgery vulnerability in multiple printers and scanners which implement Web Based Management provided by BROTHER INDUSTRIES, LTD. …

Mitigation only
Fix from $1,600 2024-03-18
Unclassified MEDIUM 6.3
CVE-2024-27974

Cross-site request forgery vulnerability in FUJIFILM printers which implement CentreWare Internet Services or Internet Services allows a remote unaut…

Mitigation only
Fix from $1,600 2024-03-18
Ac18 Firmware MEDIUM 6.5
CVE-2024-2559

A vulnerability classified as problematic has been found in Tenda AC18 15.03.05.05. Affected is the function fromSysToolReboot of the file /goform/Sy…

Mitigation only
Fix from $1,600 2024-03-17
Fontific MEDIUM 6.1
CVE-2024-27194

Cross-Site Request Forgery (CSRF) vulnerability in Andrei Ivasiuc Fontific | Google Fonts allows Stored XSS.This issue affects Fontific | Google Font…

Fix: after 0.1.6
Fix from $1,600 2024-03-16
Unclassified HIGH 7.1
CVE-2024-27195

Cross-Site Request Forgery (CSRF) vulnerability in sverde1 Watermark RELOADED watermark-reloaded allows Cross Site Request Forgery.This issue affects…

Mitigation only
Fix from $1,950 2024-03-16
Unclassified HIGH 7.1
CVE-2024-27197

Cross-Site Request Forgery (CSRF) vulnerability in Bee BeePress allows Stored XSS.This issue affects BeePress: from n/a through 6.9.8.

Mitigation only
Fix from $1,950 2024-03-16
Unclassified HIGH 8.8
CVE-2023-51474

Cross-Site Request Forgery (CSRF) vulnerability in Pixelemu TerraClassifieds.This issue affects TerraClassifieds: from n/a through 2.0.3.

Mitigation only
Fix from $1,950 2024-03-16