Vulnerability index

Browse CVEs

7,362 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.1 CVE-2026-44548 ChurchCRM is an open-source church management system. Prior to 7.3.2, top-level cross-site GET navigation from an attacker-controlled page to FundRai… Mitigation only Fix from $1,9502026-05-12 HIGH 8.8 CVE-2026-42289 ChurchCRM is an open-source church management system. Prior to 7.3.2, UserEditor.php processes user account creation and permission updates entirely … Mitigation only Fix from $1,9502026-05-12 HIGH 8.8 CVE-2026-30807 Cross-Site Request Forgery vulnerability allows an attacker to perform unauthorized actions via crafted web page. This issue affects Pandora FMS: fro… Pandora Fms 777.17 / 802+ Fix from $1,9502026-05-12 MEDIUM 6.1 CVE-2026-7561 The Tm – WordPress Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is du… Mitigation only Fix from $1,6002026-05-12 HIGH 7.1 CVE-2026-45430 The Salesforce module before 1.x-1.0.1 for Backdrop CMS does not properly use a random state parameter to protect the authorization flow against CSRF… Mitigation only Fix from $1,9502026-05-12 MEDIUM 5.4 CVE-2026-0502 Due to insufficient CSRF protection in SAP BusinessObjects Business Intelligence Platform ,an authenticated user could be tricked by an attacker to s… Mitigation only Fix from $1,6002026-05-12 MEDIUM 6.5 CVE-2026-44695 Outline is a service that allows for collaborative documentation. Prior to 1.7.1, the Slack integration callback for GET /auth/slack.post accepts an … Outline 1.7.1+ Fix from $1,6002026-05-11 MEDIUM 5.4 CVE-2026-43877 WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/userSavePhoto.php is a legacy profile-photo endpoint that… Patch available Fix from $1,6002026-05-11 HIGH 8.1 CVE-2026-38566 HireFlow v1.2 does not implement CSRF token validation on any state-changing POST endpoint. All forms (password change at /profile, candidate deletio… Mitigation only Fix from $1,9502026-05-11 MEDIUM 5.3 CVE-2021-47946 OpenCart 3.0.3.6 contains a cross-site request forgery vulnerability in the /account/edit endpoint that allows unauthenticated attackers to modify vi… No fix yet Fix from $1,6002026-05-10 HIGH 8.4 CVE-2026-42286 Emlog is an open source website building system. Prior to version 2.6.11, missing CSRF protection in critical admin functions allows attackers to tri… Mitigation only Fix from $1,9502026-05-08 MEDIUM 5.3 CVE-2026-42190 RedwoodSDK is a server-first React framework. From version 1.0.0-beta.50 to before version 1.2.3, server actions in rwsdk apply HTTP method enforceme… Redwoodsdk 1.2.3+ Fix from $1,6002026-05-08 MEDIUM 6.5 CVE-2026-5791 Cross-Site request forgery (CSRF) vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Cross Site Request Forgery. This issue… No fix yet Fix from $1,6002026-05-07 HIGH 7.8 CVE-2026-28201 An improper input validation, together with an overly permissive default CORS configuration in Open Notebook v1.8.1 allows remote attacker to trick a… Open Notebook 1.8.3+ Fix from $1,9502026-05-07 MEDIUM 5.4 CVE-2025-68604 Cross-Site Request Forgery (CSRF) vulnerability in WPGraphQL allows Cross Site Request Forgery. This issue affects WPGraphQL: from n/a through 2.5.3. Mitigation only Fix from $1,6002026-05-07 HIGH 7.2 CVE-2026-40309 Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the cTrash.empty function does not validate anti-CSRF to… Mitigation only Fix from $1,9502026-05-06 HIGH 8.7 CVE-2026-40325 Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the `cTrash.restore` function does not properly validate… Mitigation only Fix from $1,9502026-05-06 HIGH 7.1 CVE-2026-40326 Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the createBundle method in `csettings.cfc` does not prop… Mitigation only Fix from $1,9502026-05-06 HIGH 7.1 CVE-2026-40174 Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the cUsers.updateAddress function does not properly vali… Mitigation only Fix from $1,9502026-05-06 MEDIUM 5.7 CVE-2025-31957 HHCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability. This could lead to unauthorized changes or exp… Bigfix Service Management Mitigation only Fix from $1,6002026-05-06 MEDIUM 6.1 CVE-2026-6702 The Publish 2 Ping.fm plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to miss… Mitigation only Fix from $1,6002026-05-05 MEDIUM 6.5 CVE-2026-42091 goshs is a SimpleHTTPServer written in Go. Prior to version 2.0.2, the PUT upload handler (httpserver/updown.go) lacks the CSRF token validation that… Goshs 2.0.2+ Fix from $1,6002026-05-04 HIGH 8.8 CVE-2026-3772 The WP Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.9.2. This is due to missing … Mitigation only Fix from $1,9502026-05-01 HIGH 8.8 CVE-2026-36960 A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the U-SPEED N300 Rounter V1.0.0. The device does not impl… Mitigation only Fix from $1,9502026-04-30 HIGH 8.8 CVE-2026-36956 A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the Dbit N300 T1 Pro wireless router V1.0.0. The router f… Dbit N300 T1 Pro Firmware No fix yet Fix from $1,9502026-04-30 MEDIUM 5.3 CVE-2018-25298 Merge PACS 7.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML f… No fix yet Fix from $1,6002026-04-29 HIGH 8.8 CVE-2026-38934 Cross Site Request Forgery vulnerability in diskoverdata diskover-community v.2.3.5. and before allows a remote attacker to escalate privileges and o… Mitigation only Fix from $1,9502026-04-27 MEDIUM 5.4 CVE-2026-41425 Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection on the cache feature in authl… Authlib 1.6.11+ Fix from $1,6002026-04-24 HIGH 7.5 CVE-2026-41317 Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS).`press.api.acc… Press 0.9.0+ Fix from $1,9502026-04-24 HIGH 8.1 CVE-2026-27841 A vulnerability in SenseLive X3050's web management interface allows state-changing operations to be triggered without proper Cross-Site Request Forg… X3500 Firmware Mitigation only Fix from $1,9502026-04-24