Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Phpinfo Wp HIGH 8.8
CVE-2023-26542

Cross-Site Request Forgery (CSRF) vulnerability in Exeebit phpinfo() WP plugin <= 4.0 versions.

Fix: 5.0+
Fix from $1,950 2023-11-22
Cbx Currency Converter HIGH 8.8
CVE-2023-28747

Cross-Site Request Forgery (CSRF) vulnerability in codeboxr CBX Currency Converter plugin <= 3.0.3 versions.

Fix: after 3.0.3
Fix from $1,950 2023-11-22
Lws Tools HIGH 8.8
CVE-2023-27453

Cross-Site Request Forgery (CSRF) vulnerability in LWS LWS Tools plugin <= 2.3.1 versions.

Fix: after 2.3.1
Fix from $1,950 2023-11-22
Add Expires Headers \& Optimized Minify HIGH 8.8
CVE-2023-27457

Cross-Site Request Forgery (CSRF) vulnerability in Passionate Brains Add Expires Headers & Optimized Minify plugin <= 2.7 versions.

Fix: after 2.7
Fix from $1,950 2023-11-22
Wpstream HIGH 8.8
CVE-2023-27458

Cross-Site Request Forgery (CSRF) vulnerability in wpstream WpStream plugin <= 4.4.10 versions.

Fix: after 4.4.10
Fix from $1,950 2023-11-22
When Last Login HIGH 8.8
CVE-2023-27461

Cross-Site Request Forgery (CSRF) vulnerability in Yoohoo Plugins When Last Login plugin <= 1.2.1 versions.

Fix: after 1.2.1
Fix from $1,950 2023-11-22
Customify HIGH 8.8
CVE-2023-27633

Cross-Site Request Forgery (CSRF) vulnerability in Pixelgrade Customify – Intuitive Website Styling plugin <= 2.10.4 versions.

Fix: after 2.10.4
Fix from $1,950 2023-11-22
Social Auto Poster HIGH 8.8
CVE-2023-26532

Cross-Site Request Forgery (CSRF) vulnerability in AccessPress Themes Social Auto Poster plugin <= 2.1.4 versions.

Fix: after 2.1.4
Fix from $1,950 2023-11-22
Sheets To Wp Table Live Sync HIGH 8.8
CVE-2023-26535

Cross-Site Request Forgery (CSRF) vulnerability in WPPOOL Sheets To WP Table Live Sync plugin <= 2.12.15 versions.

Fix: after 2.12.15
Fix from $1,950 2023-11-22
Leyka HIGH 8.8
CVE-2023-27442

Cross-Site Request Forgery (CSRF) vulnerability in Teplitsa of social technologies Leyka plugin <= 3.29.2 versions.

Fix: after 3.29.2
Fix from $1,950 2023-11-22
Decalog HIGH 8.8
CVE-2023-27444

Cross-Site Request Forgery (CSRF) vulnerability in Pierre Lannoy / PerfOps One DecaLog plugin <= 3.7.0 versions.

Fix: after 3.7.0
Fix from $1,950 2023-11-22
Deepl Pro Api Translation HIGH 8.8
CVE-2023-27446

Cross-Site Request Forgery (CSRF) vulnerability in Fluenx DeepL API translation plugin <= 2.1.4 versions.

Fix: after 2.1.4
Fix from $1,950 2023-11-22
Cm Search And Replace HIGH 8.8
CVE-2023-28749

Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM On Demand Search And Replace plugin <= 1.3.0 versions.

Fix: after 1.3.0
Fix from $1,950 2023-11-22
Userpro MEDIUM 6.1
CVE-2023-2447

The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. This is due to missing or incor…

Fix: 5.1.2+
Fix from $1,600 2023-11-22
Sterling B2b Integrator HIGH 8.8
CVE-2022-35638

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1 is vulnerable to cross-site request forgery which co…

Fix: 6.0.3.9 / 6.1.2.3+
Fix from $1,950 2023-11-22
Post Meta Data Manager HIGH 8.8
CVE-2023-5776

The Post Meta Data Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due …

Fix: 1.2.2+
Fix from $1,950 2023-11-21
Woohoo Newspaper Magazine Theme HIGH 8.8
CVE-2023-4824

The WooHoo Newspaper Magazine theme does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in adm…

Fix: after 1.4.3
Fix from $1,950 2023-11-20
Opensis HIGH 8.8
CVE-2023-38885

OpenSIS Classic Community Edition version 9.0 lacks cross-site request forgery (CSRF) protection throughout the whole app. This may allow an attacker…

Mitigation only
Fix from $1,950 2023-11-20
Xwiki HIGH 8.8
CVE-2023-48293

The XWiki Admin Tools Application provides tools to help the administration of XWiki. Prior to version 4.5.1, a cross-site request forgery vulnerabil…

Fix: 4.5.1+
Fix from $1,950 2023-11-20
Admin Tools HIGH 8.8
CVE-2023-48292EPSS 23%

The XWiki Admin Tools Application provides tools to help the administration of XWiki. Starting in version 4.4 and prior to version 4.5.1, a cross sit…

Fix: 4.5.1+
Fix from $1,950 2023-11-20
Audio Merchant MEDIUM 5.4
CVE-2023-6197

The Audio Merchant plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0.4. This is due to missi…

Fix: after 5.0.4
Fix from $1,600 2023-11-20
Audio Merchant HIGH 8.8
CVE-2023-6196

The Audio Merchant plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.0.4. This is due to missi…

Fix: after 5.0.4
Fix from $1,950 2023-11-20
Patreon Wordpress HIGH 8.8
CVE-2023-41129

Cross-Site Request Forgery (CSRF) vulnerability in Patreon Patreon WordPress.This issue affects Patreon WordPress: from n/a through 1.8.6.

Fix: after 1.8.6
Fix from $1,950 2023-11-18
Yoast Local Seo HIGH 8.8
CVE-2023-28780

Cross-Site Request Forgery (CSRF) vulnerability in Yoast Yoast Local Premium.This issue affects Yoast Local Premium: from n/a through 14.8.

Fix: after 14.8
Fix from $1,950 2023-11-18
Easy Hide Login HIGH 8.8
CVE-2023-31075

Cross-Site Request Forgery (CSRF) vulnerability in Arshid Easy Hide Login.This issue affects Easy Hide Login: from n/a through 1.0.8.

Fix: after 1.0.8
Fix from $1,950 2023-11-18
Video Xml Sitemap Generator HIGH 8.8
CVE-2023-31089

Cross-Site Request Forgery (CSRF) vulnerability in Tradebooster Video XML Sitemap Generator.This issue affects Video XML Sitemap Generator: from n/a …

Fix: after 1.0.0
Fix from $1,950 2023-11-18
Essential Addons For Elementor HIGH 8.8
CVE-2023-32245

Cross-Site Request Forgery (CSRF) vulnerability in WPDeveloper Essential Addons for Elementor Pro.This issue affects Essential Addons for Elementor P…

Fix: after 5.4.8
Fix from $1,950 2023-11-18
Wise Chat HIGH 8.8
CVE-2023-32504

Cross-Site Request Forgery (CSRF) vulnerability in Kainex Wise Chat.This issue affects Wise Chat: from n/a through 3.1.3.

Fix: after 3.1.3
Fix from $1,950 2023-11-18
Google Site Verification Plugin Using Meta Tag HIGH 8.8
CVE-2023-32514

Cross-Site Request Forgery (CSRF) vulnerability in Himanshu Parashar Google Site Verification plugin using Meta Tag.This issue affects Google Site Ve…

Fix: after 1.2
Fix from $1,950 2023-11-18
Wordpress Tooltips HIGH 8.8
CVE-2023-25985

Cross-Site Request Forgery (CSRF) vulnerability in Tomas | Docs | FAQ | Premium Support WordPress Tooltips.This issue affects WordPress Tooltips: fro…

Fix: after 8.2.5
Fix from $1,950 2023-11-18