Vulnerability index

Browse CVEs

7,362 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2026-66602 Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site Request Forgery. This issue affec… Fix unknown Fix from $4,9002026-08-18 MEDIUM 6.5 CVE-2026-55593 Froxlor is open source server administration software. Prior to 2.3.8, the standalone lib/ajax.php entry point bypasses the centralized request valid… Fix unknown Fix from $4,0002026-08-18 MEDIUM 6.5 CVE-2026-68923 MobSF is a mobile application security testing tool used. Prior to 4.5.1, mobsf/MobSF/settings.py places django.middleware.csrf.CsrfViewMiddleware on… Fix unknown Fix from $4,0002026-08-18 HIGH 7.4 CVE-2026-66635 Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions. Fix unknown Fix from $4,9002026-08-18 HIGH 7.1 CVE-2026-19650 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 bef… Fix unknown Fix from $4,9002026-08-17 MEDIUM 6.5 CVE-2026-17608 The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… No fix yet Fix from $4,0002026-08-16 MEDIUM 5.7 CVE-2026-15384 The Manual Image Crop WordPress plugin before 1.15 does not perform any capability check or nonce verification on the authenticated AJAX action that … Fix unknown Fix from $4,0002026-08-16 MEDIUM 5.3 CVE-2026-67366 Joomla Extension - icagenda.com - CSRF on frontend registration actions in iCagenda < 2.0.0-4.0.11 - Multiple state changing operations in the fronte… No fix yet Fix from $4,0002026-08-14 MEDIUM 6.8 CVE-2026-73847 Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant execute_tool action in admin/ai.p… No fix yet Fix from $4,0002026-08-14 MEDIUM 5.1 CVE-2026-57469 Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the web-based configuration backend of KUNBUS PiCtory i… No fix yet Fix from $4,0002026-08-14 HIGH 7.7 CVE-2026-72849 Budibase before 3.40.0 contains a cross-site request forgery vulnerability in the chat-link handoff endpoint that allows attackers to bind an externa… No fix yet Fix from $4,9002026-08-13 HIGH 7.3 CVE-2026-72658 Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery (CAPEC-62). A user who is permitted to… No fix yet Fix from $4,9002026-08-13 HIGH 7.3 CVE-2026-17069 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of anti-CSRF toke… I No fix yet Fix from $4,9002026-08-13 MEDIUM 6.5 CVE-2026-13365 IBM Planning Analytics 2.0, and 2.1 Local is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthor… Planning Analytics Local No fix yet Fix from $4,0002026-08-13 MEDIUM 5.4 CVE-2026-73481 phpList before 3.7.0-RC5 fail to enforce CSRF token validation on the bounce rule deletion endpoint (bouncerules.php / bouncerule.php). The deletion … No fix yet Fix from $4,0002026-08-13 HIGH 8.1 CVE-2026-73482 phpList before 3.7.0-RC5 contains a cross-site request forgery (CSRF) vulnerability in lists/admin/admins.php. The administrator deletion action is t… No fix yet Fix from $4,9002026-08-13 MEDIUM 5.4 CVE-2026-67990 basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f disables Rails CSRF protection for its Alertmanager and Prometheus proxy controll… No fix yet Fix from $4,0002026-08-13 MEDIUM 5.4 CVE-2026-19088 The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its authentication endpoints against CSRF, … No fix yet Fix from $4,0002026-08-13 MEDIUM 5.1 CVE-2026-73423 Astro is a web framework for content-driven websites. From 7.0.0 until 7.0.6, the composable astro/hono pipeline installs security.checkOrigin only t… No fix yet Fix from $4,0002026-08-12 HIGH 7.4 CVE-2026-48551 Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protection bypass via a self-supplied double-submit cook… No fix yet Fix from $4,9002026-08-12 HIGH 8.3 CVE-2026-73292 Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using… No fix yet Fix from $4,9002026-08-12 MEDIUM 5.2 CVE-2026-47228 Admidio is an open-source user management solution. `modules/registration.php` mode `send_login` regenerates a random password for `user_uuid_assigne… No fix yet Fix from $4,0002026-08-12 MEDIUM 5.4 CVE-2026-47229 Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/sso/clients.php` validates an `adm_csrf_token` on every state-c… No fix yet Fix from $4,0002026-08-12 HIGH 8.8 CVE-2026-73222 Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --stud… No fix yet Fix from $4,9002026-08-11 MEDIUM 5.3 CVE-2026-73162 Affected versions of MISP cti-transmute expose several state-changing account operations as GET requests: * /account/follow * /account/d… No fix yet Fix from $4,0002026-08-11 HIGH 7.3 CVE-2026-19418 The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving t… No fix yet Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-72578 A cross-site request forgery (CSRF) vulnerability in FreePBX Framework 17.0 allows an unauthenticated remote attacker to perform administrative actio… No fix yet Fix from $4,9002026-08-10 MEDIUM 5.4 CVE-2026-66642 Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella allows Cross Site Request Forgery. This issue affects WP Umbrella: from 2.24.2 throug… No fix yet Fix from $4,0002026-08-10 MEDIUM 5.3 CVE-2026-19074 The Advanced Classifieds & Directory Pro Advanced Classifieds & Directory Pro WordPress plugin before 3.4.3 (<= 3.4.2) is vulnerable to unauthenticat… No fix yet Fix from $4,0002026-08-10 CRITICAL 9.6 CVE-2026-46409 OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak des… No fix yet Fix from $2,3002026-08-07