Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2023-22695 Cross-Site Request Forgery (CSRF) vulnerability in Hiroaki Miyashita Custom Field Template plugin <= 2.5.8 versions. Custom Field Template 2.5.9+ Fix from $1,9502023-07-10 HIGH 8.8 CVE-2023-23787 Cross-Site Request Forgery (CSRF) vulnerability in Premmerce Premmerce Redirect Manager plugin <= 1.0.9 versions. Redirect Manager after 1.0.9 Fix from $1,9502023-07-10 HIGH 8.8 CVE-2023-23804 Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Feed plugin <= 1.2.7 versions. Ht Feed 1.2.8+ Fix from $1,9502023-07-10 HIGH 8.8 CVE-2023-23869 Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Mobile plugin <= 1.6.1 versions. Google Xml Sitemap For Mobile after 1.6.1 Fix from $1,9502023-07-10 HIGH 8.8 CVE-2023-23897 Cross-Site Request Forgery (CSRF) vulnerability in Ozette Plugins Simple Mobile URL Redirect plugin <= 1.7.2 versions. Simple Mobile Url Redirect after 1.7.2 Fix from $1,9502023-07-10 HIGH 8.8 CVE-2023-23993 Cross-Site Request Forgery (CSRF) vulnerability in LionScripts.Com LionScripts: IP Blocker Lite plugin <= 11.1.1 versions. Ip Blocker Lite after 11.1.1 Fix from $1,9502023-07-10 HIGH 8.8 CVE-2023-24395 Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Contact Form 7 Redirect & Thank You Page plugin <= 1.0.3 versions. Contact Form 7 Redirect \& Thank You Page 1.0.4+ Fix from $1,9502023-07-10 HIGH 8.8 CVE-2023-24405 Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Contact Form 7 – PayPal & Stripe Add-on plugin <= 1.9.3 versions. Paypal \& Stripe Add On 1.9.4+ Fix from $1,9502023-07-10 HIGH 8.8 CVE-2023-25478 Cross-Site Request Forgery (CSRF) vulnerability in Jason Rouet Weather Station plugin <= 3.8.12 versions. Weather Station after 3.8.12 Fix from $1,9502023-07-10 MEDIUM 6.5 CVE-2023-36256 The Online Examination System Project 1.0 version is vulnerable to Cross-Site Request Forgery (CSRF) attacks. An attacker can craft a malicious link … Online Examination System No fix yet Fix from $1,6002023-07-07 HIGH 8.8 CVE-2023-25201 Cross Site Request Forgery (CSRF) vulnerability in MultiTech Conduit AP MTCAP2-L4E1 MTCAP2-L4E1-868-042A v.6.0.0 allows a remote attacker to execute … Conduit Ap Mtcap2 L4e1 868 042a Firmware No fix yet Fix from $1,9502023-07-07 HIGH 8.8 CVE-2023-35120 PiiGAB M-Bus is vulnerable to cross-site request forgery. An attacker who wants to execute a certain command could send a phishing mail to the owner … M Bus 900s Firmware Mitigation only Fix from $1,9502023-07-07 MEDIUM 6.5 CVE-2023-37131 A Cross-Site Request Forgery (CSRF) in the component /public/admin/profile/update.html of YznCMS v1.1.0 allows attackers to arbitrarily change the Ad… Yzncms No fix yet Fix from $1,6002023-07-06 HIGH 8.8 CVE-2023-30607 icingaweb2-module-jira provides integration with Atlassian Jira. Starting in version 1.3.0 and prior to version 1.3.2, template and field configurati… Icinga Web Jira Integration 1.3.2+ Fix from $1,9502023-07-05 HIGH 8.8 CVE-2023-31999 All versions of @fastify/oauth2 used a statically generated state parameter at startup time and were used across all requests for all users. The purp… Oauth2 7.2.0+ Fix from $1,9502023-07-04 HIGH 8.8 CVE-2023-36162 Cross Site Request Forgery vulnerability in ZZCMS v.2023 and earlier allows a remote attacker to gain privileges via the add function in adminlist.ph… Zzcms No fix yet Fix from $1,9502023-07-03 HIGH 8.8 CVE-2021-4401 The Style Kits plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.0. This is due to missing or in… Style Kits after 1.8.0 Fix from $1,9502023-07-01 MEDIUM 6.5 CVE-2021-4395 The Abandoned Cart Recovery for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.4.… Abandoned Cart Recovery For Woocommerce after 1.0.4 Fix from $1,6002023-07-01 HIGH 8.8 CVE-2021-4399 The Edwiser Bridge plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,2.0.6. This is due to missing or… Bridge after 2.0.6 Fix from $1,9502023-07-01 HIGH 8.8 CVE-2020-36745 The WP Project Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.0. This is due to missi… Wp Project Manager after 2.4.0 Fix from $1,9502023-07-01 HIGH 8.8 CVE-2020-36740 The Radio Buttons for Taxonomies plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.5. This is du… Radio Buttons For Taxonomies after 2.0.5 Fix from $1,9502023-07-01 HIGH 8.8 CVE-2021-4387 The Opal Estate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.11. This is due to missing or … Opal Estate after 1.6.11 Fix from $1,9502023-07-01 MEDIUM 6.8 CVE-2020-18409 Cross Site Request Forgery (CSRF) vulnerability was discovered in CatfishCMS 4.8.63 that would allow attackers to obtain administrator permissions vi… Catfishcms No fix yet Fix from $1,6002023-06-27 MEDIUM 6.8 CVE-2020-18416 An cross site request forgery (CSRF) vulnerability discovered in Jymusic v2.0.0.,that allows attackers to execute arbitrary code via /admin.php?s=/ad… Jymusic No fix yet Fix from $1,6002023-06-27 HIGH 8.8 CVE-2020-18418 A Cross site request forgery (CSRF) vulnerability was discovered in FeiFeiCMS v4.1.190209, which allows attackers to create administrator accounts vi… Feifeicms No fix yet Fix from $1,9502023-06-27 MEDIUM 6.8 CVE-2023-34839 A Cross Site Request Forgery (CSRF) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows a remote attacker to gain privileges via a Custom CSRF expl… Pbx No fix yet Fix from $1,6002023-06-27 HIGH 8.8 CVE-2023-1722 Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible because the application does n… Yoga Class Registration System No fix yet Fix from $1,9502023-06-24 HIGH 8.8 CVE-2023-34028 Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional plugin <= 1.0.7 versions. Wolf Wordpress Posts Bulk Editor And Manager Professional after 1.0.7 Fix from $1,9502023-06-22 MEDIUM 6.1 CVE-2023-32960 Cross-Site Request Forgery (CSRF) vulnerability in UpdraftPlus.Com, DavidAnderson UpdraftPlus WordPress Backup Plugin <= 1.23.3 versions leads to sit… Updraftplus after 1.23.3 Fix from $1,6002023-06-22 MEDIUM 6.5 CVE-2023-34927 Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password. This vulnerability allows… Casdoor after 1.331.0 Fix from $1,6002023-06-22