Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Dedecms HIGH 8.8
CVE-2024-28431

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/catalog_del.php.

No fix yet
Fix from $1,950 2024-03-13
Dedecms HIGH 8.8
CVE-2024-28432

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/article_edit.php.

No fix yet
Fix from $1,950 2024-03-13
Unclassified MEDIUM 6.5
CVE-2024-2416

Cross-Site Request Forgery vulnerability in Movistar's 4G router affecting version ES_WLD71-T1_v2.0.201820. This vulnerability allows an attacker to …

Mitigation only
Fix from $1,600 2024-03-13
Dreamer Cms MEDIUM 6.5
CVE-2024-2354

A vulnerability, which was classified as problematic, was found in Dreamer CMS 4.1.3. Affected is an unknown function of the file /admin/menu/toEdit.…

Mitigation only
Fix from $1,600 2024-03-10
Digits HIGH 8.8
CVE-2024-0203

The Digits plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.4.1. This is due to missing nonce val…

Fix: after 8.4.2
Fix from $1,950 2024-03-07
Docker Build Step MEDIUM 6.1
CVE-2024-2215

A cross-site request forgery (CSRF) vulnerability in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers to connect to an attacker-spe…

Fix: after 2.11
Fix from $1,600 2024-03-06
Flycms HIGH 7.4
CVE-2024-27694

FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the /system/share/ztree_category_edit.

No fix yet
Fix from $1,950 2024-03-04
Product Designer HIGH 8.1
CVE-2024-26469

Server-Side Request Forgery (SSRF) vulnerability in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, al…

Fix: 1.178.36+
Fix from $1,950 2024-03-03
Hospital Automanager MEDIUM 6.5
CVE-2024-2134

A vulnerability has been found in Bdtask Hospita AutoManager up to 20240223 and classified as problematic. This vulnerability affects unknown code of…

Fix: after 2024-02-23
Fix from $1,600 2024-03-03
Stupid Simple Cms MEDIUM 6.3
CVE-2024-27559

Stupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /save_settings.php

Fix: after 1.2.4
Fix from $1,600 2024-03-01
Stupid Simple Cms HIGH 8.8
CVE-2024-27689

Stupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via /update-article.php.

Fix: after 1.2.4
Fix from $1,950 2024-03-01
Mongo Express MEDIUM 6.1
CVE-2023-52555

In mongo-express 1.0.2, /admin allows CSRF, as demonstrated by deletion of a Collection.

No fix yet
Fix from $1,600 2024-03-01
Engineering Requirements Management Doors MEDIUM 6.5
CVE-2023-28949

IBM Engineering Requirements Management DOORS 9.7.2.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious …

Mitigation only
Fix from $1,600 2024-03-01
Ajax Search MEDIUM 6.1
CVE-2024-21752

Cross-Site Request Forgery (CSRF) vulnerability in Ernest Marcinko Ajax Search Lite allows Reflected XSS.This issue affects Ajax Search Lite: from n/…

Fix: 4.11.5+
Fix from $1,600 2024-02-29
Thrive Automator HIGH 8.8
CVE-2023-51531

Cross-Site Request Forgery (CSRF) vulnerability in Thrive Themes Thrive Automator.This issue affects Thrive Automator: from n/a through 1.17.

Fix: 1.17.1+
Fix from $1,950 2024-02-29
Anti Spam HIGH 8.8
CVE-2023-51696

Cross-Site Request Forgery (CSRF) vulnerability in СleanTalk - Anti-Spam Protection Spam protection, Anti-Spam, FireWall by CleanTalk.This issue affe…

Fix: 6.21+
Fix from $1,950 2024-02-29
Aipower HIGH 8.8
CVE-2023-51528

Cross-Site Request Forgery (CSRF) vulnerability in Senol Sahin AI Power: Complete AI Pack – Powered by GPT-4.This issue affects AI Power: Complete AI…

Fix: 1.8.13+
Fix from $1,950 2024-02-29
Ht Mega HIGH 8.8
CVE-2023-51529

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Mega – Absolute Addons For Elementor.This issue affects HT Mega – Absolute Addons For…

Fix: 2.3.4+
Fix from $1,950 2024-02-29
Logo Slider HIGH 8.8
CVE-2023-51530

Cross-Site Request Forgery (CSRF) vulnerability in GS Plugins Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation.T…

Fix: 3.5.2+
Fix from $1,950 2024-02-29
Custom Order Status Manager For Woocommerce HIGH 8.8
CVE-2024-25930

Cross-Site Request Forgery (CSRF) vulnerability in Nuggethon Custom Order Statuses for WooCommerce.This issue affects Custom Order Statuses for WooCo…

Fix: after 1.5.2
Fix from $1,950 2024-02-29
Heureka HIGH 8.8
CVE-2024-25931

Cross-Site Request Forgery (CSRF) vulnerability in Heureka Group Heureka.This issue affects Heureka: from n/a through 1.0.8.

Fix: 1.1.0+
Fix from $1,950 2024-02-29
Change Table Prefix HIGH 8.8
CVE-2024-25932

Cross-Site Request Forgery (CSRF) vulnerability in Manish Kumar Agarwal Change Table Prefix change-table-prefix allows Cross Site Request Forgery.Thi…

Fix: after 2.0
Fix from $1,950 2024-02-29
Setka Workflow HIGH 8.8
CVE-2024-24701

Cross-Site Request Forgery (CSRF) vulnerability in Native Grid LLC A no-code page builder for beautiful performance-based content.This issue affects …

Fix: after 2.1.20
Fix from $1,950 2024-02-29
Email Before Download HIGH 8.8
CVE-2024-23519

Cross-Site Request Forgery (CSRF) vulnerability in M&S Consulting Email Before Download.This issue affects Email Before Download: from n/a through 6.…

Fix: after 6.9.7
Fix from $1,950 2024-02-29
Flycms HIGH 8.8
CVE-2024-22939

Cross Site Request Forgery vulnerability in FlyCms v.1.0 allows a remote attacker to execute arbitrary code via the system/article/category_edit comp…

No fix yet
Fix from $1,950 2024-02-29
Clarity MEDIUM 6.1
CVE-2024-0590

The Microsoft Clarity plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9.3. This is due to mi…

Fix: 0.9.4+
Fix from $1,600 2024-02-29
Royal Elementor Addons MEDIUM 5.3
CVE-2024-0516

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to unauthorized post metadata update due to a missing capability check on…

Fix: 1.3.88+
Fix from $1,600 2024-02-29
Wrc 1167gs2 B Firmware HIGH 8.8
CVE-2024-23910

Cross-site request forgery (CSRF) vulnerability in ELECOM wireless LAN routers and wireless LAN repeater allows a remote unauthenticated attacker to …

Fix: 1.27 / 1.31+
Fix from $1,950 2024-02-28
Piwigo MEDIUM 5.4
CVE-2024-26450

An issue exists within Piwigo before v.14.2.0 allowing a malicious user to take over the application. This exploit involves chaining a Cross Site Req…

Mitigation only
Fix from $1,600 2024-02-28
Dedecms HIGH 8.8
CVE-2023-52047

Dedecms v5.7.112 was discovered to contain a Cross-Site Request Forgery (CSRF) in the file manager.

Mitigation only
Fix from $1,950 2024-02-28