Vulnerability index

Browse CVEs

7,362 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2026-29839 DedeCMS v5.7.118 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability in /sys_task_add.php. Dedecms Mitigation only Fix from $1,9502026-03-24 MEDIUM 6.5 CVE-2026-33252 The Go MCP SDK used Go's standard encoding/json. Prior to version 1.4.1, the Go SDK's Streamable HTTP transport accepted browser-generated cross-site… Mcp Go Sdk 1.4.1+ Fix from $1,6002026-03-24 HIGH 8.8 CVE-2026-33649 WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Permissions/setPermission.json.php` endpoint accepts … Avideo after 26.0 Fix from $1,9502026-03-23 HIGH 8.8 CVE-2026-33507 WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pluginImport.json.php` endpoint allows admin users t… Avideo after 26.0 Fix from $1,9502026-03-23 MEDIUM 6.5 CVE-2026-31849 Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement CSRF protections on state-changing endpoints such as /goform/setS… Nebula300plus Firmware after 12.01.01.37 Fix from $1,6002026-03-23 MEDIUM 6.1 CVE-2026-2723 The Post Snippits plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing … Mitigation only Fix from $1,6002026-03-21 HIGH 8.1 CVE-2025-14037 The Invelity Product Feeds plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 1.2… Mitigation only Fix from $1,9502026-03-21 HIGH 8.8 CVE-2026-32989 Precurio Intranet Portal 4.4 contains a cross-site request forgery vulnerability that allows attackers to induce authenticated users to submit crafte… Intranet Portal No fix yet Fix from $1,9502026-03-20 MEDIUM 5.4 CVE-2026-33372 An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A cross-site request forgery (CSRF) vulnerability exists in Zimbra Webmail due t… Zimbra Collaboration Suite 10.1.16+ Fix from $1,6002026-03-20 HIGH 7.1 CVE-2024-32537 Cross-Site request forgery (CSRF) vulnerability in joshuae1974 Flash Video Player allows Cross Site Request Forgery.This issue affects Flash Video Pl… Mitigation only Fix from $1,9502026-03-20 MEDIUM 5.7 CVE-2026-32755 Admidio is an open-source user management solution. In versions 5.0.6 and below, the save_membership action in modules/profile/profile_function.php s… Admidio 5.0.7+ Fix from $1,6002026-03-19 MEDIUM 5.7 CVE-2026-32816 Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the delete, activate, and deactivate modes in modules/groups-rol… Admidio 5.0.7+ Fix from $1,6002026-03-19 HIGH 8.8 CVE-2025-55040 The import form CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to upload and install malicious form definitions through a CSRF attack… Mura Cms Mitigation only Fix from $1,9502026-03-18 HIGH 8.0 CVE-2025-55041 MuraCMS through 10.1.10 contains a CSRF vulnerability in the Add To Group functionality for user management (cUsers.cfc addToGroup method) that allow… Mura Cms Mitigation only Fix from $1,9502026-03-18 MEDIUM 6.5 CVE-2025-55043 MuraCMS through 10.1.10 contains a CSRF vulnerability in the bundle creation functionality (csettings.cfc createBundle method) that allows unauthenti… Mura Cms Mitigation only Fix from $1,6002026-03-18 HIGH 8.8 CVE-2025-55044 The Trash Restore CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to restore deleted content from the trash to unauthorized locations … Mura Cms Mitigation only Fix from $1,9502026-03-18 HIGH 7.1 CVE-2025-55045 The update address CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to manipulate user address information through CSRF. The vulnerable… Mura Cms Mitigation only Fix from $1,9502026-03-18 HIGH 8.1 CVE-2025-55046 MuraCMS through 10.1.10 contains a CSRF vulnerability that allows attackers to permanently destroy all deleted content stored in the trash system thr… Mura Cms Mitigation only Fix from $1,9502026-03-18 HIGH 7.1 CVE-2026-22323 A CSRF vulnerability in the Link Aggregation configuration interface allows an unauthenticated remote attacker to trick authenticated users into send… Mitigation only Fix from $1,9502026-03-18 MEDIUM 6.5 CVE-2026-32839 Edimax GS-5008PL firmware version 1.00.54 and prior contain a cross-site request forgery vulnerability that allows remote attackers to perform unauth… Gs 5008pl Firmware after 1.00.54 Fix from $1,6002026-03-17 HIGH 8.0 CVE-2016-20034 Wowza Streaming Engine 4.5.0 contains a privilege escalation vulnerability that allows authenticated read-only users to elevate privileges to adminis… Streaming Engine No fix yet Fix from $1,9502026-03-16 HIGH 8.8 CVE-2015-20117 Next Click Ventures RealtyScript 4.0.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create unauthoriz… Realtyscript No fix yet Fix from $1,9502026-03-16 MEDIUM 6.5 CVE-2026-32443 Cross-Site Request Forgery (CSRF) vulnerability in Josh Kohlbach Product Feed PRO for WooCommerce woo-product-feed-pro allows Cross Site Request Forg… Mitigation only Fix from $1,6002026-03-13 MEDIUM 5.4 CVE-2026-32420 Cross-Site Request Forgery (CSRF) vulnerability in Ruben Garcia GamiPress gamipress allows Cross Site Request Forgery.This issue affects GamiPress: f… Mitigation only Fix from $1,6002026-03-13 MEDIUM 5.4 CVE-2026-32328 Cross-Site Request Forgery (CSRF) vulnerability in shufflehound Lemmony lemmony allows Cross Site Request Forgery.This issue affects Lemmony: from n/… Mitigation only Fix from $1,6002026-03-13 MEDIUM 5.4 CVE-2026-22215 wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability in the getFollowsPage() function that allows attackers to trigger unauthor… Wpdiscuz 7.6.47+ Fix from $1,6002026-03-13 MEDIUM 6.5 CVE-2026-22202 wpDiscuz before 7.6.47 contains a cross-site request forgery vulnerability that allows attackers to delete all comments associated with an email addr… Wpdiscuz 7.6.47+ Fix from $1,6002026-03-13 HIGH 7.3 CVE-2026-31954 Emlog is an open source website building system. In 2.6.6 and earlier, the delete_async action (asynchronous delete) lacks a call to LoginAuth::check… Emlog after 2.6.6 Fix from $1,9502026-03-11 HIGH 8.1 CVE-2026-30868 OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.4, multiple OPNsense MVC API endpoints perform state‑changing operations but… Opnsense 26.1.4+ Fix from $1,9502026-03-11 HIGH 8.1 CVE-2026-2626 The divi-booster WordPress plugin before 5.0.2 does not have authorization and CSRF checks in one of its fixing function, allowing unauthenticated us… Mitigation only Fix from $1,9502026-03-11