Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Jfinalcms HIGH 8.8
CVE-2023-49448

JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via admin/nav/delete.

No fix yet
Fix from $1,950 2023-12-05
Jfinalcms HIGH 8.8
CVE-2023-49372

JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/slide/save.

No fix yet
Fix from $1,950 2023-12-05
Jfinalcms HIGH 8.8
CVE-2023-49373

JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/slide/delete.

No fix yet
Fix from $1,950 2023-12-05
Jfinalcms HIGH 8.8
CVE-2023-49374

JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/slide/update.

No fix yet
Fix from $1,950 2023-12-05
Jfinalcms HIGH 8.8
CVE-2023-49375

JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/friend_link/update.

No fix yet
Fix from $1,950 2023-12-05
Jfinalcms HIGH 8.8
CVE-2023-49376

JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/delete.

No fix yet
Fix from $1,950 2023-12-05
Ac21000 G6 Firmware HIGH 8.8
CVE-2023-24048

Cross Site Request Forgery (CSRF) vulnerability in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain control of the device via crafted GE…

Mitigation only
Fix from $1,950 2023-12-04
Word Balloon MEDIUM 6.5
CVE-2023-5884

The Word Balloon WordPress plugin before 4.20.3 does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker to tr…

Fix: 4.20.3+
Fix from $1,600 2023-12-04
Ecommerce Product Catalog MEDIUM 6.5
CVE-2023-5979

The eCommerce Product Catalog Plugin for WordPress plugin before 3.3.26 does not have CSRF checks in some of its admin pages, which could allow attac…

Fix: 3.3.26+
Fix from $1,600 2023-12-04
Funnelforms Free MEDIUM 6.5
CVE-2023-5990

The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor WordPress plugin before 3.4.2 does not have CSRF checks on some of i…

Fix: 3.4.2+
Fix from $1,600 2023-12-04
Nipah Virus Testing Management System MEDIUM 6.5
CVE-2023-6474

A vulnerability has been found in PHPGurukul Nipah Virus Testing Management System 1.0 and classified as problematic. This vulnerability affects unkn…

No fix yet
Fix from $1,600 2023-12-03
Infosphere Information Server HIGH 8.8
CVE-2023-38268

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorize…

Fix: 11.7.1.0 / 11.7.1.4+
Fix from $1,950 2023-12-01
Wpforo Forum HIGH 8.8
CVE-2023-47870

Cross-Site Request Forgery (CSRF), Missing Authorization vulnerability in gVectors Team wpForo Forum wpforo allows Cross Site Request Forgery, Access…

Fix: after 2.2.6
Fix from $1,950 2023-11-30
Wp Forms Puzzle Captcha MEDIUM 6.1
CVE-2023-48278

Cross-Site Request Forgery (CSRF) vulnerability in Nitin Rathod WP Forms Puzzle Captcha allows Stored XSS.This issue affects WP Forms Puzzle Captcha:…

Fix: after 4.1
Fix from $1,600 2023-11-30
Perfmatters HIGH 8.8
CVE-2023-47875

Cross-Site Request Forgery (CSRF) vulnerability in Perfmatters allows Cross Site Request Forgery.This issue affects Perfmatters: from n/a through 2.1…

Fix: after 2.1.6
Fix from $1,950 2023-11-30
Nextgen Gallery HIGH 8.8
CVE-2023-48328

Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery allows Cross Site Request Forgery.This issue af…

Fix: 3.39+
Fix from $1,950 2023-11-30
Delete Post Revisions HIGH 8.8
CVE-2023-48754

Cross-Site Request Forgery (CSRF) vulnerability in Wap Nepal Delete Post Revisions In WordPress allows Cross Site Request Forgery.This issue affects …

Fix: after 4.6
Fix from $1,950 2023-11-30
Business Directory HIGH 8.8
CVE-2023-5803

Cross-Site Request Forgery (CSRF) vulnerability in Business Directory Team Business Directory Plugin – Easy Listing Directories for WordPress allows …

Fix: after 6.3.10
Fix from $1,950 2023-11-30
Dreamer Cms HIGH 8.8
CVE-2023-48912

Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/archives/edit.

No fix yet
Fix from $1,950 2023-11-30
Dreamer Cms HIGH 8.8
CVE-2023-48913

Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/archives/delete.

No fix yet
Fix from $1,950 2023-11-30
Dreamer Cms HIGH 8.8
CVE-2023-48914

Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/archives/add.

No fix yet
Fix from $1,950 2023-11-30
Registrationmagic HIGH 8.8
CVE-2023-47645

Cross-Site Request Forgery (CSRF) vulnerability in RegistrationMagic RegistrationMagic – Custom Registration Forms, User Registration, Payment, and U…

Fix: 5.2.3.0+
Fix from $1,950 2023-11-30
Seraphinite Post .docx Source HIGH 8.8
CVE-2023-48279

Cross-Site Request Forgery (CSRF) vulnerability in Seraphinite Solutions Seraphinite Post .DOCX Source allows Cross Site Request Forgery.This issue a…

Fix: after 2.16.6
Fix from $1,950 2023-11-30
Broken Link Checker For Youtube HIGH 8.8
CVE-2023-48281

Cross-Site Request Forgery (CSRF) vulnerability in Super Blog Me Broken Link Checker for YouTube allows Cross Site Request Forgery.This issue affects…

Fix: after 1.3
Fix from $1,950 2023-11-30
Complianz HIGH 8.8
CVE-2023-34030

Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Complianz, Really Simple Plugins Complianz Premium allows Cross-Site Request…

Fix: 6.4.8+
Fix from $1,950 2023-11-30
Schema HIGH 8.8
CVE-2023-36682

Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force US LLC Schema Pro allows Cross Site Request Forgery.This issue affects Schema Pro…

Fix: 2.7.8+
Fix from $1,950 2023-11-30
Cartflows HIGH 8.8
CVE-2023-36685

Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force US LLC CartFlows Pro allows Cross Site Request Forgery.This issue affects CartFlo…

Fix: after 1.11.12
Fix from $1,950 2023-11-30
Complianz HIGH 8.8
CVE-2023-33333

Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Plugins Complianz, Really Simple Plugins Complianz Premium allows Cross-Site Scripti…

Fix: 6.4.6 / 6.4.7+
Fix from $1,950 2023-11-30
Frontier Post HIGH 8.8
CVE-2023-6137

Cross-Site Request Forgery (CSRF) vulnerability in finnj Frontier Post allows Cross Site Request Forgery.This issue affects Frontier Post: from n/a t…

Fix: after 6.1
Fix from $1,950 2023-11-30
Awesome Support HIGH 8.8
CVE-2023-48323

Cross-Site Request Forgery (CSRF) vulnerability in Awesome Support Team Awesome Support – WordPress HelpDesk & Support Plugin allows Cross Site Reque…

Fix: after 6.1.4
Fix from $1,950 2023-11-30