Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2022-47422 Cross-Site Request Forgery (CSRF) vulnerability in HM Plugin Accept Stripe Donation – AidWP plugin <= 3.1.5 versions. Accept Stripe Donation Aidwp after 3.1.5 Fix from $1,9502023-03-14 HIGH 8.8 CVE-2022-47443 Cross-Site Request Forgery (CSRF) vulnerability in Daniel Powney Multi Rating plugin <= 5.0.5 versions. Multi Rating after 5.0.5 Fix from $1,9502023-03-14 HIGH 8.8 CVE-2022-47141 Cross-Site Request Forgery (CSRF) vulnerability in Seerox WP Dynamic Keywords Injector plugin <= 2.3.15 versions. Wp Dynamic Keywords Injector after 2.3.15 Fix from $1,9502023-03-14 HIGH 8.8 CVE-2022-47154 Cross-Site Request Forgery (CSRF) vulnerability in Pi Websolution CSS JS Manager, Async JavaScript, Defer Render Blocking CSS supports WooCommerce pl… Css Js Manager\, Async Javascript\, Defer Render Blocking Css Supports Woocommerce after 2.4.49 Fix from $1,9502023-03-14 HIGH 8.8 CVE-2022-47155 Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Slider by Supsystic plugin <= 1.8.5 versions. Slider after 1.8.5 Fix from $1,9502023-03-14 HIGH 8.8 CVE-2022-47162 Cross-Site Request Forgery (CSRF) vulnerability in Dannie Herdyawan DH – Anti AdBlocker plugin <= 36 versions. Dh Anti Adblocker after 36 Fix from $1,9502023-03-14 HIGH 7.5 CVE-2022-47163 Cross-Site Request Forgery (CSRF) vulnerability in Tips and Tricks HQ, josh401 WP CSV to Database – Insert CSV file content into WordPress plugin <= … Wp Csv To Database after 2.6 Fix from $1,9502023-03-14 HIGH 8.8 CVE-2023-25170 PrestaShop is an open source e-commerce web application that, prior to version 8.0.1, is vulnerable to cross-site request forgery (CSRF). When authen… Prestashop 8.0.1+ Fix from $1,9502023-03-13 HIGH 8.8 CVE-2023-25973 Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links plugin <= 6.3.0.2 versions. Auto Affiliate Links 6.3.0.3+ Fix from $1,9502023-03-13 HIGH 8.8 CVE-2023-25991 Cross-Site Request Forgery (CSRF) vulnerability in RegistrationMagic plugin <= 5.1.9.2 versions. Registrationmagic 5.1.9.3+ Fix from $1,9502023-03-13 HIGH 8.8 CVE-2022-47166 Cross-Site Request Forgery (CSRF) vulnerability in voidCoders Void Contact Form 7 Widget For Elementor Page Builder plugin <= 2.1.1 versions. Void Contact Form 7 Widget For Elementor Page Builder 2.2+ Fix from $1,9502023-03-13 HIGH 8.8 CVE-2022-47440 Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Tickets plugin <= 1.9.10 versions. My Tickets 1.9.11+ Fix from $1,9502023-03-13 HIGH 8.8 CVE-2023-1205 NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 is vulnerable to cross-site request forgery attacks on all endpoints due to improperly implemented… Rax30 Firmware 1.0.10.94+ Fix from $1,9502023-03-10 HIGH 8.8 CVE-2023-27490 NextAuth.js is an open source authentication solution for Next.js applications. `next-auth` applications using OAuth provider versions before `v4.20.… Next Auth 4.20.1+ Fix from $1,9502023-03-09 MEDIUM 6.5 CVE-2021-4333 The WP Statistics plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 13.1.1. This is due to missing o… Wp Statistics after 13.1.1 Fix from $1,6002023-03-07 HIGH 8.8 CVE-2020-36669 The JetBackup – WP Backup, Migrate & Restore plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.3.9.… Jetbackup after 1.3.9 Fix from $1,9502023-03-07 HIGH 8.8 CVE-2022-4265 The Replyable WordPress plugin before 2.2.10 does not validate the class name submitted by the request when instantiating an object in the prompt_dis… Replyable 2.2.10+ Fix from $1,9502023-03-06 MEDIUM 5.4 CVE-2022-46798 Cross-Site Request Forgery (CSRF) vulnerability in HasThemes ShopLentor plugin <= 2.5.1 leading to plugin settings change. Woolentor Woocommerce Elementor Addons \+ Builder 2.5.2+ Fix from $1,6002023-03-01 MEDIUM 5.4 CVE-2022-46805 Cross-Site Request Forgery (CSRF) vulnerability in Lauri Karisola / WP Trio Conditional Shipping for WooCommerce plugin <= 2.3.1 leading to activatio… Conditional Shipping For Woocommerce 2.3.2+ Fix from $1,6002023-03-01 HIGH 8.8 CVE-2022-45068 Cross-Site Request Forgery (CSRF) vulnerability in Mercado Pago Mercado Pago payments for WooCommerce plugin <= 6.3.1. Mercado Pago Payments For Woocommerce 6.4.0+ Fix from $1,9502023-03-01 MEDIUM 5.4 CVE-2022-45804 Cross-Site Request Forgery (CSRF) vulnerability in RoboSoft Photo Gallery, Images, Slider in Rbs Image Gallery plugin <= 3.2.9 leading to galleries h… Robo Gallery 3.2.11+ Fix from $1,6002023-03-01 MEDIUM 6.5 CVE-2023-23973 Cross-Site Request Forgery (CSRF) vulnerability in a3rev Software Contact Us Page – Contact People plugin <= 3.7.0. Contact Us Page Contact People 3.7.1+ Fix from $1,6002023-03-01 MEDIUM 5.4 CVE-2023-23974 Cross-Site Request Forgery (CSRF) vulnerability in Fullworks Quick Event Manager plugin <= 9.7.4 affecting all registration actions (delete, delete a… Quick Event Manager 9.7.5+ Fix from $1,6002023-03-01 MEDIUM 5.4 CVE-2023-23984 Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Bubble Menu – circle floating menu plugin <= 3.0.1 leading to form deletion. Bubble Menu 3.0.2+ Fix from $1,6002023-03-01 MEDIUM 5.4 CVE-2023-27295 Cross-site request forgery is facilitated by OpenCATS failure to require CSRF tokens in POST requests. An attacker can exploit this issue by creating… Opencats No fix yet Fix from $1,6002023-02-28 MEDIUM 5.4 CVE-2023-23983 Cross-Site Request Forgery (CSRF) vulnerability in wpdevart Responsive Vertical Icon Menu plugin <= 1.5.8 can lead to theme deletion. Responsive Vertical Icon Menu 1.5.9+ Fix from $1,6002023-02-28 HIGH 8.8 CVE-2022-43459 Cross-Site Request Forgery (CSRF) vulnerability in Forms by CaptainForm – Form Builder for WordPress plugin <= 2.5.3 versions. Captainform after 2.5.3 Fix from $1,9502023-02-28 HIGH 8.8 CVE-2023-24419 Cross-Site Request Forgery (CSRF) vulnerability in Strategy11 Form Builder Team Formidable Forms plugin <= 5.5.6 versions. Formidable Form Builder 5.5.7+ Fix from $1,9502023-02-28 HIGH 8.8 CVE-2023-1033 Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 2.0.11. Froxlor 2.0.11+ Fix from $1,9502023-02-25 HIGH 8.8 CVE-2021-34167 Cross Site Request Forgery (CSRF) vulnerability in taoCMS 3.0.2 allows remote attackers to gain escalated privileges via taocms/admin/admin.php. Taocms No fix yet Fix from $1,9502023-02-24