Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Atahualpa HIGH 8.8
CVE-2024-27948

Cross-Site Request Forgery (CSRF) vulnerability in bytesforall Atahualpa.This issue affects Atahualpa: from n/a through 3.7.24.

Fix: after 3.7.24
Fix from $1,950 2024-02-28
Ecwid Ecommerce Shopping Cart MEDIUM 6.1
CVE-2023-51533

Cross-Site Request Forgery (CSRF) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart.This issue affects Ecwid Ecommerce Shopping Cart: fr…

Fix: 6.12.5+
Fix from $1,600 2024-02-28
Advanced Flamingo HIGH 8.8
CVE-2023-52226

Cross-Site Request Forgery (CSRF) vulnerability in Advanced Flamingo.This issue affects Advanced Flamingo: from n/a through 1.0.

Fix: after 1.0
Fix from $1,950 2024-02-28
Click Disable All HIGH 8.8
CVE-2024-21749

Cross-Site Request Forgery (CSRF) vulnerability in Atakan Au 1 click disable all.This issue affects 1 click disable all: from n/a through 1.0.1.

Fix: after 1.0.1
Fix from $1,950 2024-02-28
Unclassified MEDIUM 6.5
CVE-2023-51681

Cross-Site Request Forgery (CSRF) vulnerability in Duplicator Duplicator – WordPress Migration & Backup Plugin.This issue affects Duplicator – WordPr…

Mitigation only
Fix from $1,600 2024-02-28
Easy Paypal \& Stripe Buy Now Button HIGH 8.8
CVE-2023-51683

Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Easy PayPal & Stripe Buy Now Button.This issue affects Easy PayPal & Stripe Buy Now…

Fix: 1.8.2+
Fix from $1,950 2024-02-28
Mailerlite HIGH 8.8
CVE-2023-52223

Cross-Site Request Forgery (CSRF) vulnerability in MailerLite MailerLite – WooCommerce integration.This issue affects MailerLite – WooCommerce integr…

Fix: 2.0.9+
Fix from $1,950 2024-02-28
Pagerestrict HIGH 8.8
CVE-2024-24702

Cross-Site Request Forgery (CSRF) vulnerability in Matt Martz & Andy Stratton Page Restrict.This issue affects Page Restrict: from n/a through 2.5.5.

Fix: after 2.5.5
Fix from $1,950 2024-02-28
Unclassified MEDIUM 5.4
CVE-2024-24705

Cross-Site Request Forgery (CSRF) vulnerability in Octa Code Accessibility.This issue affects Accessibility: from n/a through 1.0.6.

Mitigation only
Fix from $1,600 2024-02-28
Oliver Pos MEDIUM 6.3
CVE-2024-1954

The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ…

Fix: 2.4.1.9+
Fix from $1,600 2024-02-28
Fatal Error Notify MEDIUM 6.1
CVE-2023-7202

The Fatal Error Notify WordPress plugin before 1.5.3 does not have authorisation and CSRF checks in its test_error AJAX action, allowing any authenti…

Fix: 1.5.3+
Fix from $1,600 2024-02-27
Smart Forms MEDIUM 6.1
CVE-2023-7203

The Smart Forms WordPress plugin before 2.6.87 does not have authorisation in various AJAX actions, which could allow users with a role as low as sub…

Fix: 2.6.87+
Fix from $1,600 2024-02-27
Bagisto HIGH 8.8
CVE-2023-36237

Cross Site Request Forgery vulnerability in Bagisto before v.1.5.1 allows an attacker to execute arbitrary code via a crafted HTML script.

Fix: 1.5.1+
Fix from $1,950 2024-02-26
Clcon 10 Firmware HIGH 8.8
CVE-2024-1889

Cross-Site Request Forgery vulnerability in SMA Cluster Controller, affecting version 01.05.01.R. This vulnerability could allow an attacker to send …

Mitigation only
Fix from $1,950 2024-02-26
Flusity HIGH 8.8
CVE-2024-26350

flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_contact_form_settings.php

No fix yet
Fix from $1,950 2024-02-22
Flusity MEDIUM 6.1
CVE-2024-26351

flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_place.php

Mitigation only
Fix from $1,600 2024-02-22
Flusity HIGH 8.8
CVE-2024-26352

flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/add_places.php

No fix yet
Fix from $1,950 2024-02-22
Flusity MEDIUM 6.1
CVE-2024-26445

flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_place.php

No fix yet
Fix from $1,600 2024-02-22
Flusity HIGH 8.8
CVE-2024-23094

Flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /cover/addons/info_media_gallery/action/edit_addon_…

Mitigation only
Fix from $1,950 2024-02-22
Jtrt Responsive Tables HIGH 8.8
CVE-2024-24802

Cross-Site Request Forgery (CSRF) vulnerability in John Tendik JTRT Responsive Tables.This issue affects JTRT Responsive Tables: from n/a through 4.1…

Fix: after 4.1.9
Fix from $1,950 2024-02-21
Debug HIGH 8.8
CVE-2024-24798

Cross-Site Request Forgery (CSRF) vulnerability in SoniNow Team Debug.This issue affects Debug: from n/a through 1.10.

Fix: 1.11+
Fix from $1,950 2024-02-21
Multi Step Form MEDIUM 5.4
CVE-2024-25905

Cross-Site Request Forgery (CSRF) vulnerability in Mondula GmbH Multi Step Form.This issue affects Multi Step Form: from n/a through 1.7.18.

Fix: 1.7.19+
Fix from $1,600 2024-02-21
Admin Menu Editor HIGH 8.8
CVE-2024-24876

Cross-Site Request Forgery (CSRF) vulnerability in Janis Elsts Admin Menu Editor.This issue affects Admin Menu Editor: from n/a through 1.12.

Fix: 1.12.1+
Fix from $1,950 2024-02-21
Tinymce And Tinymce Advanced Professsional Formats And Styles HIGH 8.8
CVE-2024-25904

Cross-Site Request Forgery (CSRF) vulnerability in David Stockl TinyMCE and TinyMCE Advanced Professsional Formats and Styles.This issue affects Tiny…

Fix: after 1.1.2
Fix from $1,950 2024-02-21
Quicksand Post Filter Jquery HIGH 8.8
CVE-2024-24849

Cross-Site Request Forgery (CSRF) vulnerability in Mark Stockton Quicksand Post Filter jQuery Plugin.This issue affects Quicksand Post Filter jQuery …

Fix: after 3.1.1
Fix from $1,950 2024-02-21
Builder HIGH 8.8
CVE-2024-24872

Cross-Site Request Forgery (CSRF) vulnerability in Themify Themify Builder.This issue affects Themify Builder: from n/a through 7.0.5.

Fix: 7.0.6+
Fix from $1,950 2024-02-21
Powerpack Addons For Elementor HIGH 8.8
CVE-2024-24843

Cross-Site Request Forgery (CSRF) vulnerability in PowerPack Addons for Elementor PowerPack Pro for Elementor.This issue affects PowerPack Pro for El…

Fix: after 2.10.8
Fix from $1,950 2024-02-21
Unclassified HIGH 8.8
CVE-2021-29050

Cross-Site Request Forgery (CSRF) vulnerability in the terms of use page in Liferay Portal before 7.3.6, and Liferay DXP 7.3 before service pack 1, 7…

Mitigation only
Fix from $1,950 2024-02-20
Decidim MEDIUM 5.7
CVE-2023-47635

Decidim is a participatory democracy framework. Starting in version 0.23.0 and prior to versions 0.27.5 and 0.28.0, the CSRF authenticity token check…

Fix: 0.27.5+
Fix from $1,600 2024-02-20
Moodle HIGH 8.8
CVE-2024-25982

The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.

Fix: 4.1.9 / 4.2.6+
Fix from $1,950 2024-02-19