Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2023-40558 Cross-Site Request Forgery (CSRF) vulnerability in eMarket Design YouTube Video Gallery by YouTube Showcase plugin <= 3.3.5 versions. Youtube Video Gallery 3.3.6+ Fix from $1,9502023-10-03 MEDIUM 6.5 CVE-2023-32791 Cross-Site Request Forgery (CSRF) vulnerability in NXLog Manager 5.6.5633 version. This vulnerability allows an attacker to manipulate and delete use… Nxlog Manager Mitigation only Fix from $1,6002023-10-03 MEDIUM 6.5 CVE-2023-32792 Cross-Site Request Forgery (CSRF) vulnerability in NXLog Manager 5.6.5633 version. This vulnerability allows an attacker to eliminate roles within th… Nxlog Manager Mitigation only Fix from $1,6002023-10-03 MEDIUM 6.5 CVE-2023-39159 Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Fraud Prevention For Woocommerce plugin <= 2.1.5 versions. Fraud Prevention For Woocommerce after 2.1.5 Fix from $1,6002023-10-03 MEDIUM 6.5 CVE-2023-40009 Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Pipes plugin <= 1.4.0 versions. Wp Pipes after 1.4.0 Fix from $1,6002023-10-03 MEDIUM 6.5 CVE-2023-40198 Cross-Site Request Forgery (CSRF) vulnerability in Antsanchez Easy Cookie Law plugin <= 3.1 versions. Easy Cookie Law after 3.1 Fix from $1,6002023-10-03 HIGH 8.8 CVE-2023-40199 Cross-Site Request Forgery (CSRF) vulnerability in CRUDLab WP Like Button plugin <= 1.7.0 versions. Wp Like Button after 1.7.0 Fix from $1,9502023-10-03 HIGH 8.8 CVE-2023-40201 Cross-Site Request Forgery (CSRF) vulnerability in FuturioWP Futurio Extra plugin <= 1.8.4 versions leads to activation of arbitrary plugin. Futurio Extra after 1.8.4 Fix from $1,9502023-10-03 HIGH 8.8 CVE-2023-40202 Cross-Site Request Forgery (CSRF) vulnerability in Hannes Etzelstorfer // codemiq WP HTML Mail plugin <= 3.4.1 versions. Wp Html Mail after 3.4.1 Fix from $1,9502023-10-03 MEDIUM 6.5 CVE-2023-40212 Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Product Attachment for WooCommerce plugin <= 2.1.8 versions. Product Attachment For Woocommerce after 2.1.8 Fix from $1,6002023-10-03 HIGH 8.8 CVE-2023-25989 Cross-Site Request Forgery (CSRF) vulnerability in Meks Video Importer, Meks Time Ago, Meks ThemeForest Smart Widget, Meks Smart Author Widget, Meks … Meks Audio Player after 2.1.3 Fix from $1,9502023-10-03 HIGH 8.8 CVE-2023-2830 Cross-Site Request Forgery (CSRF) vulnerability in Trustindex.Io WP Testimonials plugin <= 1.4.2 versions. Wp Testimonials after 1.4.2 Fix from $1,9502023-10-03 HIGH 8.8 CVE-2023-39165 Cross-Site Request Forgery (CSRF) vulnerability in Fetch Designs Sign-up Sheets plugin <= 2.2.8 versions. Sign Up Sheets after 2.2.8 Fix from $1,9502023-10-03 HIGH 8.8 CVE-2023-39917 Cross-Site Request Forgery (CSRF) vulnerability in Photo Gallery Team Photo Gallery by Ays – Responsive Image Gallery plugin <= 5.2.6 versions. Photo Gallery after 5.2.6 Fix from $1,9502023-10-03 HIGH 8.8 CVE-2023-39923 Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme The Post Grid plugin <= 7.2.7 versions. The Post Grid after 7.2.7 Fix from $1,9502023-10-03 HIGH 8.8 CVE-2023-39989 Cross-Site Request Forgery (CSRF) vulnerability in 99robots Header Footer Code Manager plugin <= 1.1.34 versions. Header Footer Code Manager after 1.1.34 Fix from $1,9502023-10-03 HIGH 8.8 CVE-2023-40210 Cross-Site Request Forgery (CSRF) vulnerability in Sean Barton (Tortoise IT) SB Child List plugin <= 4.5 versions. Sb Child List after 4.5 Fix from $1,9502023-10-03 HIGH 8.8 CVE-2022-46841 Cross-Site Request Forgery (CSRF) vulnerability in Soflyy Oxygen Builder plugin <= 4.4 versions. Oxygen 4.4+ Fix from $1,9502023-10-03 HIGH 7.1 CVE-2023-24518 A Cross-site Request Forgery (CSRF) vulnerability in Pandora FMS allows an attacker to force authenticated users to send a request to a web applicati… Pandora Fms after 767 Fix from $1,9502023-10-03 HIGH 8.8 CVE-2023-25463 Cross-Site Request Forgery (CSRF) vulnerability in Gopi Ramasamy WP tell a friend popup form plugin <= 7.1 versions. Wp Tell A Friend Popup Form after 7.1 Fix from $1,9502023-10-03 HIGH 8.8 CVE-2023-37990 Cross-Site Request Forgery (CSRF) vulnerability in Mike Perelink Pro plugin <= 2.1.4 versions. Perelink Pro after 2.1.4 Fix from $1,9502023-10-03 HIGH 8.8 CVE-2023-38390 Cross-Site Request Forgery (CSRF) vulnerability in Anshul Labs Mobile Address Bar Changer plugin <= 3.0 versions. Mobile Address Bar Changer after 3.0 Fix from $1,9502023-10-03 HIGH 8.8 CVE-2023-38396 Cross-Site Request Forgery (CSRF) vulnerability in Alain Gonzalez plugin <= 3.1.2 versions. Google Map Shortcode after 3.1.2 Fix from $1,9502023-10-03 HIGH 8.8 CVE-2023-38398 Cross-Site Request Forgery (CSRF) vulnerability in Taboola plugin <= 2.0.1 versions. Tablooa after 2.0.1 Fix from $1,9502023-10-03 HIGH 8.8 CVE-2023-37891 Cross-Site Request Forgery (CSRF) vulnerability in OptiMonk OptiMonk: Popups, Personalization & A/B Testing plugin <= 2.0.4 versions. Optimonk\ 2.0.5+ Fix from $1,9502023-10-03 HIGH 8.8 CVE-2023-37991 Cross-Site Request Forgery (CSRF) vulnerability in Monchito.Net WP Emoji One plugin <= 0.6.0 versions. Wp Emoji One after 0.6.0 Fix from $1,9502023-10-03 HIGH 8.8 CVE-2023-37992 Cross-Site Request Forgery (CSRF) vulnerability in PressPage Entertainment Inc. Smarty for WordPress plugin <= 3.1.35 versions. Smarty For Wordpress after 3.1.35 Fix from $1,9502023-10-03 HIGH 8.8 CVE-2023-37996 Cross-Site Request Forgery (CSRF) vulnerability in GTmetrix GTmetrix for WordPress plugin <= 0.4.7 versions. Gtmetrix 0.4.8+ Fix from $1,9502023-10-03 HIGH 8.8 CVE-2023-37998 Cross-Site Request Forgery (CSRF) vulnerability in Saas Disabler allows Cross Site Request Forgery.This issue affects Disabler: from n/a through 3.0.… Disabler after 3.0.3 Fix from $1,9502023-10-03 HIGH 8.8 CVE-2023-38381 Cross-Site Request Forgery (CSRF) vulnerability in Cyle Conoly WP-FlyBox plugin <= 6.46 versions. Wp Flybox after 6.46 Fix from $1,9502023-10-03