Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Dreamer Cms HIGH 8.8
CVE-2023-48020

Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/task/changeStatus.

No fix yet
Fix from $1,950 2023-11-14
Dreamer Cms HIGH 8.8
CVE-2023-48021

Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/task/update.

No fix yet
Fix from $1,950 2023-11-14
Baidu Tongji Generator MEDIUM 6.1
CVE-2023-31230

Cross-Site Request Forgery (CSRF) vulnerability in Haoqisir Baidu Tongji generator allows Stored XSS.This issue affects Baidu Tongji generator: from …

Fix: after 1.0.2
Fix from $1,600 2023-11-13
The7 MEDIUM 6.1
CVE-2023-32123

Cross-Site Request Forgery (CSRF) vulnerability in Dream-Theme The7 allows Stored XSS.This issue affects The7: from n/a through 11.7.3.

Fix: after 11.7.3
Fix from $1,600 2023-11-13
Extra User Details MEDIUM 6.1
CVE-2023-35877

Cross-Site Request Forgery (CSRF) vulnerability in Vadym K. Extra User Details allows Stored XSS.This issue affects Extra User Details: from n/a thro…

Fix: 0.5.1+
Fix from $1,600 2023-11-13
Tagdiv Composer MEDIUM 6.1
CVE-2023-39166

Cross-Site Request Forgery (CSRF) vulnerability in tagDiv tagDiv Composer allows Cross-Site Scripting (XSS).This issue affects tagDiv Composer: from …

Fix: 4.4+
Fix from $1,600 2023-11-13
Dreamer Cms HIGH 8.8
CVE-2023-48058

Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/task/run

No fix yet
Fix from $1,950 2023-11-13
Dreamer Cms HIGH 8.8
CVE-2023-48060

Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/task/add

No fix yet
Fix from $1,950 2023-11-13
Cleverwise Daily Quotes MEDIUM 6.1
CVE-2023-40335

Cross-Site Request Forgery (CSRF) vulnerability in Jeremy O'Connell Cleverwise Daily Quotes allows Stored XSS.This issue affects Cleverwise Daily Quo…

Fix: after 3.2
Fix from $1,600 2023-11-13
Webmaster Tools MEDIUM 6.1
CVE-2023-46092

Cross-Site Request Forgery (CSRF) vulnerability in LionScripts.Com Webmaster Tools allows Stored XSS.This issue affects Webmaster Tools: from n/a thr…

Fix: after 2.0
Fix from $1,600 2023-11-13
Auto Login New User After Registration MEDIUM 6.1
CVE-2023-46201

Cross-Site Request Forgery (CSRF) vulnerability in Jeff Sherk Auto Login New User After Registration allows Stored XSS.This issue affects Auto Login …

Fix: after 1.9.6
Fix from $1,600 2023-11-13
Custom My Account For Woocommerce MEDIUM 6.1
CVE-2023-46634

Cross-Site Request Forgery (CSRF) vulnerability in phoeniixx Custom My Account for Woocommerce allows Cross-Site Scripting (XSS).This issue affects C…

Fix: after 2.1
Fix from $1,600 2023-11-13
Category Post List Widget MEDIUM 6.1
CVE-2023-47516

Cross-Site Request Forgery (CSRF) vulnerability in Stark Digital Category Post List Widget allows Stored XSS.This issue affects Category Post List Wi…

Fix: after 2.0
Fix from $1,600 2023-11-13
Auto Affiliate Links MEDIUM 6.1
CVE-2023-47652

Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links allows Stored XSS.This issue affects Auto Affiliate Links: fro…

Fix: 6.4.2.5+
Fix from $1,600 2023-11-13
Web Push Notifications HIGH 8.8
CVE-2023-35041

Cross-Site Request Forgery (CSRF) vulnerability leading to Local File Inclusion (LF) in Webpushr Web Push Notifications Web Push Notifications – Webp…

Fix: after 4.34.0
Fix from $1,950 2023-11-13
Profile Builder HIGH 8.8
CVE-2023-47669

Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Edi…

Fix: 3.10.4+
Fix from $1,950 2023-11-13
Stop Referrer Spam HIGH 8.8
CVE-2023-33207

Cross-Site Request Forgery (CSRF) vulnerability in Krzysztof Wielogórski Stop Referrer Spam plugin <= 1.3.0 versions.

Fix: after 1.3.0
Fix from $1,950 2023-11-13
Wp Hide Post HIGH 8.8
CVE-2023-34378

Cross-Site Request Forgery (CSRF) vulnerability in scriptburn.Com WP Hide Post plugin <= 2.0.10 versions.

Fix: after 2.0.10
Fix from $1,950 2023-11-13
Kebo Twitter Feed HIGH 8.8
CVE-2023-34384

Cross-Site Request Forgery (CSRF) vulnerability in Kebo Kebo Twitter Feed plugin <= 1.5.12 versions.

Fix: after 1.5.12
Fix from $1,950 2023-11-13
Wp All Backup HIGH 8.8
CVE-2023-32583

Cross-Site Request Forgery (CSRF) vulnerability in Prashant Walke WP All Backup plugin <= 2.4.3 versions.

Fix: after 2.4.3
Fix from $1,950 2023-11-13
Post State Tags HIGH 8.8
CVE-2023-32588

Cross-Site Request Forgery (CSRF) vulnerability in BRANDbrilliance Post State Tags plugin <= 2.0.6 versions.

Fix: after 2.0.6
Fix from $1,950 2023-11-13
Wcp Openweather HIGH 8.8
CVE-2023-46638

Cross-Site Request Forgery (CSRF) vulnerability in Webcodin WCP OpenWeather plugin <= 2.5.0 versions.

Fix: after 2.5.0
Fix from $1,950 2023-11-13
Wordpress Contact Forms HIGH 8.8
CVE-2023-47230

Cross-Site Request Forgery (CSRF) vulnerability in Cimatti Consulting WordPress Contact Forms by Cimatti plugin <= 1.6.0 versions.

Fix: after 1.6.0
Fix from $1,950 2023-11-13
Wdsocialwidgets HIGH 8.8
CVE-2023-46619

Cross-Site Request Forgery (CSRF) vulnerability in WebDorado WDSocialWidgets plugin <= 1.0.15 versions.

Fix: after 1.0.15
Fix from $1,950 2023-11-13
Deepl Api Translation HIGH 8.8
CVE-2023-46620

Cross-Site Request Forgery (CSRF) vulnerability in Fluenx DeepL API translation plugin <= 2.3.9.1 versions.

Fix: after 2.3.9.1
Fix from $1,950 2023-11-13
Autolinks Manager HIGH 8.8
CVE-2023-46625

Cross-Site Request Forgery (CSRF) vulnerability in DAEXT Autolinks Manager plugin <= 1.10.04 versions.

Fix: after 1.10.04
Fix from $1,950 2023-11-13
Remove Add To Cart Woocommerce HIGH 8.8
CVE-2023-46629

Cross-Site Request Forgery (CSRF) vulnerability in themelocation Remove Add to Cart WooCommerce plugin <= 1.4.4.

Fix: after 1.4.4
Fix from $1,950 2023-11-13
Custom Header Images HIGH 8.8
CVE-2023-46636

Cross-Site Request Forgery (CSRF) vulnerability in David Stöckl Custom Header Images plugin <= 1.2.1 versions.

Fix: after 1.2.1
Fix from $1,950 2023-11-13
All In One Search Automatic Push Management HIGH 8.8
CVE-2023-26531

Cross-Site Request Forgery (CSRF) vulnerability in 闪电博 多合一搜索自动推送管理插件-支持Baidu/Google/Bing/IndexNow/Yandex/头条 allows Cross Site Req…

Fix: after 4.2.7
Fix from $1,950 2023-11-13
Wp Meteor HIGH 8.8
CVE-2023-26543

Cross-Site Request Forgery (CSRF) vulnerability in Aleksandr Guidrevitch WP Meteor Website Speed Optimization Addon plugin <= 3.1.4 versions.

Fix: after 3.1.4
Fix from $1,950 2023-11-13