Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Job Manager \& Career HIGH 8.8
CVE-2023-51545

Cross-Site Request Forgery (CSRF), Deserialization of Untrusted Data vulnerability in ThemeHigh Job Manager & Career – Manage job board listings, and…

Fix: after 1.4.4
Fix from $1,950 2023-12-29
New User Approve HIGH 8.8
CVE-2023-50902

Cross-Site Request Forgery (CSRF) vulnerability in WPExpertsio New User Approve.This issue affects New User Approve: from n/a through 2.5.1.

Fix: after 2.5.1
Fix from $1,950 2023-12-29
Webba Booking HIGH 8.8
CVE-2023-51354

Cross-Site Request Forgery (CSRF) vulnerability in WebbaPlugins Appointment & Event Booking Calendar Plugin – Webba Booking.This issue affects Appoin…

Fix: after 4.5.33
Fix from $1,950 2023-12-29
Block Ips For Gravity Forms HIGH 8.8
CVE-2023-51358

Cross-Site Request Forgery (CSRF) vulnerability in Bright Plugins Block IPs for Gravity Forms.This issue affects Block IPs for Gravity Forms: from n/…

Fix: after 1.0.1
Fix from $1,950 2023-12-29
Rise Blocks HIGH 8.8
CVE-2023-51378

Cross-Site Request Forgery (CSRF) vulnerability in Rise Themes Rise Blocks – A Complete Gutenberg Page Builder.This issue affects Rise Blocks – A Com…

Fix: after 3.1
Fix from $1,950 2023-12-29
Mstore Api HIGH 8.8
CVE-2023-50878

Cross-Site Request Forgery (CSRF) vulnerability in InspireUI MStore API.This issue affects MStore API: from n/a through 4.10.1.

Fix: after 4.10.1
Fix from $1,950 2023-12-29
Ultimate Addons For Wpbakery Page Builder HIGH 8.8
CVE-2023-51402

Cross-Site Request Forgery (CSRF) vulnerability in Brain Storm Force Ultimate Addons for WPBakery Page Builder.This issue affects Ultimate Addons for…

Fix: after 3.19.17
Fix from $1,950 2023-12-29
Anti Hacker HIGH 8.8
CVE-2023-50858

Cross-Site Request Forgery (CSRF) vulnerability in Bill Minozzi Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker…

Fix: after 4.34
Fix from $1,950 2023-12-28
Add Any Extension To Pages HIGH 8.8
CVE-2023-50873

Cross-Site Request Forgery (CSRF) vulnerability in Marios Alexandrou Add Any Extension to Pages.This issue affects Add Any Extension to Pages: from n…

Fix: after 1.4
Fix from $1,950 2023-12-28
Portfolio HIGH 8.8
CVE-2012-10017

A vulnerability was found in BestWebSoft Portfolio Plugin up to 2.04 on WordPress. It has been classified as problematic. This affects an unknown par…

Fix: 2.06+
Fix from $1,950 2023-12-26
Iologik E1210 Firmware HIGH 8.8
CVE-2023-5961

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in ioLogik E1200 Series firmware versions v3.3 and prior. An attacker can explo…

Fix: 3.3+
Fix from $1,950 2023-12-23
Automad MEDIUM 6.5
CVE-2023-7038

A vulnerability was found in automad up to 1.10.9. It has been rated as problematic. This issue affects some unknown processing of the file /dashboar…

Fix: after 1.10.9
Fix from $1,600 2023-12-21
Dashicons \+ Custom Post Types HIGH 8.8
CVE-2023-22674

Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in Hal Gatewood Dashicons + Custom Post Types.This issue affects Dashicons + C…

Fix: after 1.0.2
Fix from $1,950 2023-12-21
Airflow MEDIUM 6.5
CVE-2023-49920

Apache Airflow, version 2.7.0 through 2.7.3, has a vulnerability that allows an attacker to trigger a DAG in a GET request without CSRF validation. A…

Fix: after 2.7.3
Fix from $1,600 2023-12-21
Bcu 500 Firmware HIGH 8.8
CVE-2023-6689

A successful CSRF attack could force the user to perform state changing requests on the application. If the victim is an administrative account, a CS…

Mitigation only
Fix from $1,950 2023-12-20
Ocean Extra HIGH 8.8
CVE-2023-49164

Cross-Site Request Forgery (CSRF) vulnerability in OceanWP Ocean Extra.This issue affects Ocean Extra: from n/a through 2.2.2.

Fix: 2.2.3+
Fix from $1,950 2023-12-19
Advanced Category Template HIGH 8.8
CVE-2023-50835

Cross-Site Request Forgery (CSRF) vulnerability in Praveen Goswami Advanced Category Template.This issue affects Advanced Category Template: from n/a…

Fix: after 0.1
Fix from $1,950 2023-12-19
Phpsysinfo MEDIUM 6.5
CVE-2023-49006

Cross Site Request Forgery (CSRF) vulnerability in Phpsysinfo version 3.4.3 allows a remote attacker to obtain sensitive information via a crafted pa…

Patch available
Fix from $1,600 2023-12-19
Wp Extra HIGH 8.8
CVE-2023-46212

Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in TienCOP WP EXtra allows Accessing Functionality Not Properly Constrained by…

Fix: after 6.2
Fix from $1,950 2023-12-19
Participants Database HIGH 8.8
CVE-2023-48751

Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in Roland Barker, xnau webdesign Participants Database allows Accessing Functi…

Fix: after 2.5.5
Fix from $1,950 2023-12-19
Woodiscuz Woocommerce Comments HIGH 8.8
CVE-2023-49759

Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team WooDiscuz – WooCommerce Comments.This issue affects WooDiscuz – WooCommerce Comments…

Fix: after 2.3.0
Fix from $1,950 2023-12-18
Wpsoononlinepage HIGH 8.8
CVE-2023-49760

Cross-Site Request Forgery (CSRF) vulnerability in Giannopoulos Kostas WPsoonOnlinePage.This issue affects WPsoonOnlinePage: from n/a through 1.9.

Fix: after 1.9
Fix from $1,950 2023-12-18
Product Enquiry For Woocommerce HIGH 8.8
CVE-2023-49761

Cross-Site Request Forgery (CSRF) vulnerability in Gravity Master Product Enquiry for WooCommerce.This issue affects Product Enquiry for WooCommerce:…

Fix: after 3.0
Fix from $1,950 2023-12-18
Csprite HIGH 8.8
CVE-2023-49763

Cross-Site Request Forgery (CSRF) vulnerability in Creatomatic Ltd CSprite.This issue affects CSprite: from n/a through 1.1.

Fix: after 1.1
Fix from $1,950 2023-12-18
Livechat HIGH 8.8
CVE-2023-49821

Cross-Site Request Forgery (CSRF) vulnerability in LiveChat LiveChat – WP live chat plugin for WordPress.This issue affects LiveChat – WP live chat p…

Fix: after 4.5.15
Fix from $1,950 2023-12-18
Add To Cart Text Changer And Customize Button\, Add Custom Icon HIGH 8.8
CVE-2023-49153

Cross-Site Request Forgery (CSRF) vulnerability in Saiful Islam Add to Cart Text Changer and Customize Button, Add Custom Icon.This issue affects Add…

Fix: after 2.0
Fix from $1,950 2023-12-18
Button Generator HIGH 8.8
CVE-2023-49155

Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Button Generator – easily Button Builder.This issue affects Button Generator – easily …

Fix: after 2.3.8
Fix from $1,950 2023-12-18
Teachpress HIGH 8.8
CVE-2023-49163

Cross-Site Request Forgery (CSRF) vulnerability in Michael Winkler teachPress.This issue affects teachPress: from n/a through 9.0.5.

Fix: after 9.0.5
Fix from $1,950 2023-12-18
Mkrapel Regiones Y Ciudades De Chile Para Wc HIGH 8.8
CVE-2023-48781

Cross-Site Request Forgery (CSRF) vulnerability in Marketing Rapel MkRapel Regiones y Ciudades de Chile para WC.This issue affects MkRapel Regiones y…

Fix: after 4.3.0
Fix from $1,950 2023-12-18
Affiliate Booster HIGH 8.8
CVE-2023-49148

Cross-Site Request Forgery (CSRF) vulnerability in Kulwant Nagi Affiliate Booster – Pros & Cons, Notice, and CTA Blocks for Affiliates.This issue aff…

Fix: after 3.0.5
Fix from $1,950 2023-12-18