Vulnerability index

Browse CVEs

7,362 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 5.4 CVE-2026-39634 Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Portfolio grandportfolio allows Cross Site Request Forgery.This issue affects Gra… Mitigation only Fix from $1,6002026-04-08 MEDIUM 5.4 CVE-2026-39635 Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Magazine grandmagazine allows Cross Site Request Forgery.This issue affects Grand… Mitigation only Fix from $1,6002026-04-08 CRITICAL 9.6 CVE-2026-39640 Cross-Site Request Forgery (CSRF) vulnerability in mndpsingh287 Theme Editor theme-editor allows Code Injection.This issue affects Theme Editor: from… Mitigation only Fix from $2,3002026-04-08 MEDIUM 6.5 CVE-2026-39641 Cross-Site Request Forgery (CSRF) vulnerability in Skywarrior Blackfyre blackfyre allows Cross Site Request Forgery.This issue affects Blackfyre: fro… Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.5 CVE-2026-39632 Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Blog grandblog allows Cross Site Request Forgery.This issue affects Grand Blog: f… Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.5 CVE-2026-39633 Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Car Rental grandcarrental allows Cross Site Request Forgery.This issue affects Gr… Mitigation only Fix from $1,6002026-04-08 CRITICAL 9.6 CVE-2026-39620 Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Appointment appointment allows Upload a Web Shell to a Web Server.This issue affec… Mitigation only Fix from $2,3002026-04-08 HIGH 8.8 CVE-2026-39621 Cross-Site Request Forgery (CSRF) vulnerability in spicethemes SpicePress spicepress allows Upload a Web Shell to a Web Server.This issue affects Spi… Mitigation only Fix from $1,9502026-04-08 CRITICAL 9.6 CVE-2026-39617 Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Bluestreet bluestreet allows Cross Site Request Forgery.This issue affects Bluestr… Mitigation only Fix from $2,3002026-04-08 CRITICAL 9.6 CVE-2026-39619 Cross-Site Request Forgery (CSRF) vulnerability in priyanshumittal Busiprof busiprof allows Upload a Web Shell to a Web Server.This issue affects Bus… Mitigation only Fix from $2,3002026-04-08 MEDIUM 5.4 CVE-2026-39603 Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Photography grandphotography allows Cross Site Request Forgery.This issue affects… Mitigation only Fix from $1,6002026-04-08 HIGH 8.8 CVE-2026-3499 The Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in … Mitigation only Fix from $1,9502026-04-08 MEDIUM 5.4 CVE-2026-4401 The Download Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in the `actions_handler()` and `bulk_actions_handler()` methods… Mitigation only Fix from $1,6002026-04-08 HIGH 8.1 CVE-2026-39371 RedwoodSDK is a server-first React framework. From 1.0.0-beta.50 to 1.0.5, erver functions exported from "use server" files could be invoked via GET … Redwoodsdk 1.0.6+ Fix from $1,9502026-04-07 HIGH 7.5 CVE-2026-34896 Cross-Site Request Forgery (CSRF) vulnerability in Analytify Under Construction, Coming Soon & Maintenance Mode allows Cross Site Request Forgery.Thi… Mitigation only Fix from $1,9502026-04-07 HIGH 7.5 CVE-2026-34904 Cross-Site Request Forgery (CSRF) vulnerability in Analytify Simple Social Media Share Buttons allows Cross Site Request Forgery.This issue affects S… Mitigation only Fix from $1,9502026-04-07 MEDIUM 6.5 CVE-2016-20053 Redaxo CMS 5.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative user accounts by tr… Redaxo No fix yet Fix from $1,6002026-04-04 MEDIUM 6.5 CVE-2026-34228 Emlog is an open source website building system. Prior to version 2.6.8, the backend upgrade interface accepts remote SQL and ZIP URLs via GET parame… Emlog 2.6.8+ Fix from $1,6002026-04-03 HIGH 8.8 CVE-2025-36375 IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 1… Datapower Gateway 10.5.0.21 / 10.6.0.9+ Fix from $1,9502026-04-01 MEDIUM 5.4 CVE-2026-34749 Payload is a free and open source headless content management system. Prior to version 3.79.1, a Cross-Site Request Forgery (CSRF) vulnerability exis… Payload 3.79.1+ Fix from $1,6002026-04-01 MEDIUM 6.5 CVE-2026-5283 Inappropriate implementation in ANGLE in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to leak cross-origin data via a crafted HTML… Chrome 146.0.7680.177+ Fix from $1,6002026-04-01 MEDIUM 6.5 CVE-2026-34611 WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo endpoint objects/emailAllUsers.json.php allows administrators to… Avideo after 26.0 Fix from $1,6002026-03-31 MEDIUM 6.5 CVE-2026-34613 WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo endpoint objects/pluginSwitch.json.php allows administrators to … Avideo after 26.0 Fix from $1,6002026-03-31 HIGH 7.3 CVE-2026-34384 Admidio is an open-source user management solution. Prior to version 5.0.8, the create_user, assign_member, and assign_user action modes in modules/r… Admidio 5.0.8+ Fix from $1,9502026-03-31 HIGH 8.1 CVE-2026-34394 WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's admin plugin configuration endpoint (admin/save.json.php) lacks an… Avideo after 26.0 Fix from $1,9502026-03-31 MEDIUM 5.4 CVE-2026-3191 The Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.12. This is due to missing… Mitigation only Fix from $1,6002026-03-31 HIGH 8.8 CVE-2026-33373 An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A Cross-Site Request Forgery (CSRF) vulnerability exists in Zimbra Web Client du… Zimbra Collaboration Suite 10.0.18 / 10.1.13+ Fix from $1,9502026-03-30 MEDIUM 6.5 CVE-2026-4315 A Cross-Site Request Forgery (CSRF) vulnerability in the WatchGuard Fireware OS WebUI could allow a remote attacker to trigger a denial-of-service (D… Fireware 11.12.4 / 12.5.18+ Fix from $1,6002026-03-30 HIGH 8.2 CVE-2026-4984 The Twilio integration webhook handler accepts any POST request without validating Twilio's 'X-Twilio-Signature'. When processing media messages, it… Botpress Mitigation only Fix from $1,9502026-03-27 HIGH 8.8 CVE-2026-3857 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that cou… GitLab 18.8.7 / 18.9.3+ Fix from $1,9502026-03-25