Vulnerability index

Browse CVEs

7,362 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 7.1 CVE-2026-41347 OpenClaw before 2026.3.31 lacks browser-origin validation in HTTP operator endpoints when operating in trusted-proxy mode, allowing cross-site reques… Openclaw 2026.3.31+ Fix from $1,9502026-04-23 CRITICAL 9.6 CVE-2026-40471 hackage-server lacked Cross-Site Request Forgery (CSRF) protection across its endpoints. Scripts on foreign sites could trigger requests to hackage s… Mitigation only Fix from $2,3002026-04-23 HIGH 8.1 CVE-2026-4922 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that co… GitLab 18.9.6 / 18.10.4+ Fix from $1,9502026-04-22 MEDIUM 6.1 CVE-2026-4131 The WP Responsive Popup + Optin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.4. This is due… Mitigation only Fix from $1,6002026-04-22 MEDIUM 6.1 CVE-2026-4090 The Inquiry Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.4.2. This is due to missing… Mitigation only Fix from $1,6002026-04-22 HIGH 7.1 CVE-2026-40926 WWBN AVideo is an open source video platform. In versions 29.0 and prior, three admin-only JSON endpoints — `objects/categoryAddNew.json.php`, `objec… Avideo after 29.0 Fix from $1,9502026-04-21 MEDIUM 5.4 CVE-2026-40928 WWBN AVideo is an open source video platform. In versions 29.0 and prior, multiple AVideo JSON endpoints under `objects/` accept state-changing reque… Avideo after 29.0 Fix from $1,6002026-04-21 MEDIUM 5.4 CVE-2026-40929 WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/commentDelete.json.php` is a state-mutating JSON endpoint that del… Avideo after 29.0 Fix from $1,6002026-04-21 HIGH 8.3 CVE-2026-40925 WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/configurationUpdate.json.php` (also routed via `/updateConfig`) pe… Avideo after 29.0 Fix from $1,9502026-04-21 HIGH 8.1 CVE-2026-40883 goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs contains a cross-site request forgery issue in its state-changing… Goshs No fix yet Fix from $1,9502026-04-21 MEDIUM 5.4 CVE-2026-41194 FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the mailbox OAuth disconnect action is implemented as `GET /m… Patch available Fix from $1,6002026-04-21 MEDIUM 6.3 CVE-2026-31014 Dovestones Softwares AD Self Update <4.0.0.5 is vulnerable to Cross Site Request Forgery (CSRF). The affected endpoint processes state-changing reque… Ad Self Update 4.0.0.5+ Fix from $1,6002026-04-21 MEDIUM 5.3 CVE-2026-6777 Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. Firefox 150.0+ Fix from $1,6002026-04-21 MEDIUM 6.5 CVE-2026-6755 Mitigation bypass in the DOM: postMessage component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. Firefox 150.0+ Fix from $1,6002026-04-21 MEDIUM 5.4 CVE-2026-40948 The Keycloak authentication manager in `apache-airflow-providers-keycloak` did not generate or validate the OAuth 2.0 `state` parameter on the login … Apache Airflow Providers Keycloak 0.7.0+ Fix from $1,6002026-04-18 HIGH 8.1 CVE-2026-40581 ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the family record deletion endpoint (SelectDelete.php) performs per… Patch available Fix from $1,9502026-04-18 MEDIUM 6.5 CVE-2026-40458 PAC4J is vulnerable to Cross-Site Request Forgery (CSRF). A malicious attacker can craft a specially designed website which, when visited by a user, … Pac4j 5.7.10 / 6.4.1+ Fix from $1,6002026-04-17 MEDIUM 6.1 CVE-2026-1852 The Product Pricing Table by WooBeWoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. T… Mitigation only Fix from $1,6002026-04-15 HIGH 8.1 CVE-2026-40764 Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Cross Site Request Forgery.This issue affe… Mitigation only Fix from $1,9502026-04-15 HIGH 8.1 CVE-2026-28741 Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to validate CSRF tokens on an authentication endpo… Mattermost Server 10.11.13 / 11.3.3+ Fix from $1,9502026-04-15 MEDIUM 6.1 CVE-2026-4091 The OPEN-BRAIN plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5.0. This is due to missing n… Mitigation only Fix from $1,6002026-04-15 HIGH 7.1 CVE-2019-25693 ResourceSpace 8.6 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious… Resourcespace No fix yet Fix from $1,9502026-04-12 HIGH 8.8 CVE-2026-6109 A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.1. The impacted element is the function evaluateCode of the file metagpt/environ… Metagpt after 0.8.1 Fix from $1,9502026-04-12 MEDIUM 5.4 CVE-2026-39848 Dockyard is a Docker container management app. Prior to 1.1.0, Docker container start and stop operations are performed through GET requests without … Dockyard 1.1.0+ Fix from $1,6002026-04-09 HIGH 8.8 CVE-2025-70810 Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.3.15 allows a local attacker to execute arbitrary code via the login function and the aut… Phpbb No fix yet Fix from $1,9502026-04-09 MEDIUM 6.5 CVE-2026-34721 Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, the OAuth callback endpoints for Microsoft, Google, and… Zammad 6.5.4+ Fix from $1,6002026-04-08 MEDIUM 5.4 CVE-2026-0811 The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.9. This is … Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.5 CVE-2026-1672 The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulnerable to Cross-Site Request For… Mitigation only Fix from $1,6002026-04-08 MEDIUM 5.4 CVE-2026-39710 Cross-Site Request Forgery (CSRF) vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Cross Site Request Forgery.This issue affec… Mitigation only Fix from $1,6002026-04-08 HIGH 7.1 CVE-2026-39671 Cross-Site Request Forgery (CSRF) vulnerability in Dotstore Extra Fees Plugin for WooCommerce woo-conditional-product-fees-for-checkout allows Cross … Mitigation only Fix from $1,9502026-04-08