Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Cybermath HIGH 8.8
CVE-2023-6676

Cross-Site Request Forgery (CSRF) vulnerability in National Keep Cyber Security Services CyberMath allows Cross Site Request Forgery. This issue aff…

Mitigation only
Fix from $1,950 2024-02-02
Flusity HIGH 8.8
CVE-2024-24524

Cross Site Request Forgery (CSRF) vulnerability in flusity-CMS v.2.33, allows remote attackers to execute arbitrary code via the add_menu.php compone…

No fix yet
Fix from $1,950 2024-02-02
Livewire HIGH 8.8
CVE-2024-22859

Cross-Site Request Forgery (CSRF) vulnerability in livewire before v3.0.4, allows remote attackers to execute arbitrary code getCsrfToken function. N…

Fix: 3.0.4+
Fix from $1,950 2024-02-01
Droit Elementor Addons HIGH 8.8
CVE-2024-22136

Cross-Site Request Forgery (CSRF) vulnerability in DroitThemes Droit Elementor Addons – Widgets, Blocks, Templates Library For Elementor Builder.This…

Fix: after 3.1.5
Fix from $1,950 2024-01-31
Profile Builder HIGH 8.8
CVE-2024-22140

Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder Pro.This issue affects Profile Builder Pro: from n/a through 3.10.0.

Fix: after 3.10.0
Fix from $1,950 2024-01-31
Wpspellcheck HIGH 8.8
CVE-2024-22143

Cross-Site Request Forgery (CSRF) vulnerability in WP Spell Check.This issue affects WP Spell Check: from n/a through 9.17.

Fix: after 9.17
Fix from $1,950 2024-01-31
Frontpage Manager HIGH 8.8
CVE-2024-22285

Cross-Site Request Forgery (CSRF) vulnerability in Elise Bosse Frontpage Manager.This issue affects Frontpage Manager: from n/a through 1.3.

Fix: after 1.3
Fix from $1,950 2024-01-31
Browser Theme Color HIGH 8.8
CVE-2024-22291

Cross-Site Request Forgery (CSRF) vulnerability in Marco Milesi Browser Theme Color.This issue affects Browser Theme Color: from n/a through 1.3.

Fix: after 1.3
Fix from $1,950 2024-01-31
Freshmail For Wordpress HIGH 8.8
CVE-2024-22304

Cross-Site Request Forgery (CSRF) vulnerability in Borbis Media FreshMail For WordPress.This issue affects FreshMail For WordPress: from n/a through …

Fix: after 2.3.2
Fix from $1,950 2024-01-31
Better Anchor Links MEDIUM 6.1
CVE-2024-22287

Cross-Site Request Forgery (CSRF) vulnerability in Luděk Melichar Better Anchor Links allows Cross-Site Scripting (XSS).This issue affects Better Anc…

Fix: after 1.7.5
Fix from $1,600 2024-01-31
Custom Dashboard Widgets HIGH 8.8
CVE-2024-22290

Cross-Site Request Forgery (CSRF) vulnerability in AboZain,O7abeeb,UnitOne Custom Dashboard Widgets allows Cross-Site Scripting (XSS).This issue affe…

Fix: after 1.3.1
Fix from $1,950 2024-01-31
Seo Panel MEDIUM 6.5
CVE-2024-22643

A Cross-Site Request Forgery (CSRF) vulnerability in SEO Panel version 4.10.0 allows remote attackers to perform unauthorized user password resets.

No fix yet
Fix from $1,600 2024-01-30
Free And Open Source Inventory Management System MEDIUM 6.5
CVE-2023-51813

Cross Site Request Forgery (CSRF) vulnerability in Free Open-Source Inventory Management System v.1.0 allows a remote attacker to execute arbitrary c…

No fix yet
Fix from $1,600 2024-01-30
Wordpress Users HIGH 8.8
CVE-2023-6390

The WordPress Users WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Fix: after 1.4.0
Fix from $1,950 2024-01-29
Custom User Css HIGH 8.8
CVE-2023-6391

The Custom User CSS WordPress plugin through 0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Fix: after 0.2
Fix from $1,950 2024-01-29
Wp Plugin Lister MEDIUM 5.4
CVE-2023-6503

The WP Plugin Lister WordPress plugin through 2.1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which c…

Fix: after 2.1.0
Fix from $1,600 2024-01-29
Autotitle HIGH 8.8
CVE-2023-6946

The Autotitle for WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Fix: after 1.0.3
Fix from $1,950 2024-01-29
Wp Social Bookmark Menu HIGH 8.8
CVE-2023-7074

The WP SOCIAL BOOKMARK MENU WordPress plugin through 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to…

Fix: after 1.2
Fix from $1,950 2024-01-29
Form Maker MEDIUM 6.3
CVE-2024-0667

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve…

Fix: after 1.15.21
Fix from $1,600 2024-01-27
Qdbcrm HIGH 8.8
CVE-2024-0880

A vulnerability was found in Qidianbang qdbcrm 1.1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file …

No fix yet
Fix from $1,950 2024-01-25
Paid Memberships Pro MEDIUM 5.3
CVE-2024-0624

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forg…

Fix: after 2.12.7
Fix from $1,600 2024-01-25
Terminal Handler HIGH 8.8
CVE-2023-47024

Cross-Site Request Forgery (CSRF) in NCR Terminal Handler v.1.5.1 leads to a one-click account takeover. This is achieved by exploiting multiple vuln…

Mitigation only
Fix from $1,950 2024-01-20
Maximo Application Suite HIGH 8.8
CVE-2023-47718

IBM Maximo Asset Management 7.6.1.3 and Manage Component 8.10 through 8.11 is vulnerable to cross-site request forgery which could allow an attacker …

Fix: 8.10.6+
Fix from $1,950 2024-01-19
Argo Cd HIGH 8.3
CVE-2024-22424

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The Argo CD API prior to versions 2.10-rc2, 2.9.4, 2.8.8, and 2.7.15 are vu…

Fix: 2.7.16 / 2.8.8+
Fix from $1,950 2024-01-19
Flycms HIGH 8.8
CVE-2024-22601

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/score/scorerule_save

Mitigation only
Fix from $1,950 2024-01-18
Flycms HIGH 8.8
CVE-2024-22603

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/links/add_link

No fix yet
Fix from $1,950 2024-01-18
Flycms HIGH 8.8
CVE-2024-22817

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/email/email_conf_updagte

No fix yet
Fix from $1,950 2024-01-18
Flycms HIGH 8.8
CVE-2024-22818

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerbility via /system/site/filterKeyword_save

No fix yet
Fix from $1,950 2024-01-18
Flycms HIGH 8.8
CVE-2024-22819

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/email/email_templets_update.

No fix yet
Fix from $1,950 2024-01-18
Flycms HIGH 8.8
CVE-2024-22699

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/admin/update_group_save.

No fix yet
Fix from $1,950 2024-01-18