Vulnerability index

Browse CVEs

7,362 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Concrete Cms HIGH 8.8
CVE-2026-8434

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescanMultiple(). The Concrete CM…

Fix: 9.5.1+
Fix from $1,950 2026-05-21
Concrete Cms HIGH 8.8
CVE-2026-8409

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delete.  The The Concrete CMS secu…

Fix: 9.5.1+
Fix from $1,950 2026-05-21
Concrete Cms HIGH 8.8
CVE-2026-8410

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/delete.  The The Concrete CMS…

Fix: 9.5.1+
Fix from $1,950 2026-05-21
Concrete Cms HIGH 8.8
CVE-2026-8411

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/delete. The Concrete CMS secu…

Fix: 9.5.1+
Fix from $1,950 2026-05-21
Concrete Cms HIGH 8.8
CVE-2026-8412

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/cache. The Concrete CMS secu…

Fix: 9.5.1+
Fix from $1,950 2026-05-21
Concrete Cms HIGH 8.8
CVE-2026-8421

Concrete CMS 9.5.0 and below contains a CSRF vulnerability in the install_package() method of concrete/controllers/single_page/dashboard/extend/insta…

Fix: 9.5.1+
Fix from $1,950 2026-05-21
Concrete Cms HIGH 8.8
CVE-2026-8426

Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/prepare_remote_upgrade/<remoteMPID…

Fix: 9.5.1+
Fix from $1,950 2026-05-21
Concrete Cms HIGH 8.8
CVE-2026-8428

Concrete CMS 9.5.0 and below emits a CSRF token in the local_available_update.php view ($token->output('do_update')) but the corresponding do_update(…

Fix: 9.5.1+
Fix from $1,950 2026-05-21
Concrete Cms MEDIUM 6.5
CVE-2026-8140

Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/install/download/<remoteId>. The download…

Fix: after 9.5.0
Fix from $1,600 2026-05-21
Concrete Cms HIGH 8.8
CVE-2026-8417

Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/do_update/<pkgHandle>. The do_upda…

Fix: 9.5.1+
Fix from $1,950 2026-05-21
Mattermost Mobile MEDIUM 6.1
CVE-2026-22880

Mattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to properly validate the SSO authentication callback origin w…

Fix: 2.37.1+
Fix from $1,600 2026-05-21
Infoscale Operations Manager HIGH 8.8
CVE-2026-44925

Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to force the user with an active se…

Fix: 9.1.3+
Fix from $1,950 2026-05-20
Unclassified HIGH 8.0
CVE-2025-11954

Cross-Site request forgery (CSRF) vulnerability in Sitemio Information Technologies Trade Ltd. Co. WISECP allows Cross Site Request Forgery. This is…

Mitigation only
Fix from $1,950 2026-05-20
Unclassified MEDIUM 6.1
CVE-2026-8420

The BLOGCHAT Chat System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.6.3. This is due …

Mitigation only
Fix from $1,600 2026-05-20
Unclassified MEDIUM 6.1
CVE-2026-6391

The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl…

Mitigation only
Fix from $1,600 2026-05-20
Unclassified MEDIUM 6.1
CVE-2026-6395

The Word 2 Cash plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting in versions up to and includi…

Mitigation only
Fix from $1,600 2026-05-20
Scadabr HIGH 8.8
CVE-2026-8604

In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a victim's session by luring any l…

Mitigation only
Fix from $1,950 2026-05-19
Unclassified MEDIUM 5.4
CVE-2018-25334

Zechat 1.5 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows an attacker to change a user's information by bypassing anti-CSRF p…

No fix yet
Fix from $1,600 2026-05-17
Unclassified MEDIUM 5.3
CVE-2018-25336

jCart for OpenCart 2.3.0.2 contains a cross-site request forgery vulnerability that allows attackers to modify user account information without authe…

No fix yet
Fix from $1,600 2026-05-17
Unclassified MEDIUM 5.3
CVE-2018-25327

Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform state-changing actions without t…

No fix yet
Fix from $1,600 2026-05-17
Unclassified HIGH 8.8
CVE-2021-47976

TextPattern CMS 4.9.0-dev contains a remote code execution vulnerability that allows authenticated attackers to upload arbitrary PHP files by exploit…

No fix yet
Fix from $1,950 2026-05-16
Unclassified MEDIUM 5.3
CVE-2020-37241

bloofoxCMS 0.5.2.1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in …

No fix yet
Fix from $1,600 2026-05-16
Turborepo MEDIUM 6.5
CVE-2026-45773

Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14, Turborepo's self-hosted login and SSO browser …

Fix: 2.9.14+
Fix from $1,600 2026-05-15
Unclassified HIGH 8.1
CVE-2026-28761

Cross-site request forgery vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. If a user views a…

Mitigation only
Fix from $1,950 2026-05-15
GitLab MEDIUM 6.5
CVE-2026-4527

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that c…

Fix: 18.9.7 / 18.10.6+
Fix from $1,600 2026-05-14
Empirbus Wireless Display Unit Firmware CRITICAL 9.3
CVE-2025-27851

The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking attack. Among other uses, the WDU …

Mitigation only
Fix from $2,300 2026-05-13
Unclassified CRITICAL 9.3
CVE-2026-44364

MISP modules are autonomous modules that can be used to extend MISP for new services. In 3.0.7 and earlier, a Cross-Site Request Forgery vulnerabilit…

Mitigation only
Fix from $2,300 2026-05-13
Ckan MEDIUM 6.1
CVE-2026-41255

CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, Access to the views via tok…

Fix: 2.10.10 / 2.11.5+
Fix from $1,600 2026-05-13
Big Ip Access Policy Manager MEDIUM 5.4
CVE-2026-40703

A cross-site request forgery (CSRF) vulnerability exists in the dashboard of the BIG-IP Configuration utility.  Note: Software versions which have re…

Fix: after 17.5.1
Fix from $1,600 2026-05-13
Warpgate MEDIUM 6.5
CVE-2026-44347

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.23.3, the SSO flow does not validate the state parameter, which ma…

No fix yet
Fix from $1,600 2026-05-12