Vulnerability index

Browse CVEs

7,362 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.1 CVE-2026-2324 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions … Mitigation only Fix from $1,6002026-03-11 HIGH 8.8 CVE-2026-28495 GetSimple CMS is a content management system. The massiveAdmin plugin (v6.0.3) bundled with GetSimpleCMS-CE v3.3.22 allows an authenticated administr… Getsimple Cms after 3.3.22 Fix from $1,9502026-03-10 HIGH 7.1 CVE-2026-28281 InstantCMS is a free and open source content management system. Prior to 2.18.1, InstantCMS does not validate CSRF tokens, which allows attackers gra… Instantcms 2.18.1+ Fix from $1,9502026-03-10 HIGH 8.8 CVE-2025-70031 An issue pertaining to CWE-352: Cross-Site Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. Sunbirded Portal Mitigation only Fix from $1,9502026-03-09 HIGH 8.8 CVE-2026-3770 A flaw has been found in SourceCodester Computer Laboratory Management System 1.0. This affects an unknown part. This manipulation causes cross-site … Computer Laboratory Management System No fix yet Fix from $1,9502026-03-08 HIGH 8.8 CVE-2026-29784 Ghost is a Node.js content management system. From version 5.101.6 to 6.19.2, incomplete CSRF protections around /session/verify made it possible to … Ghost 6.19.3+ Fix from $1,9502026-03-07 HIGH 8.8 CVE-2018-25200 OOP CMS BLOG 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative user accounts by … Php Oop Cms Blog No fix yet Fix from $1,9502026-03-06 MEDIUM 6.5 CVE-2018-25190 Easyndexer 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative accounts by submitt… Easyndexer No fix yet Fix from $1,6002026-03-06 MEDIUM 5.3 CVE-2018-25174 ABC ERP 0.6.4 contains a cross-site request forgery vulnerability that allows attackers to modify administrator credentials by submitting forged requ… No fix yet Fix from $1,6002026-03-06 HIGH 8.2 CVE-2018-25176 Alive Parish 2.0.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malici… No fix yet Fix from $1,9502026-03-06 MEDIUM 5.3 CVE-2018-25177 Data Center Audit 2.6.2 contains a cross-site request forgery vulnerability that allows attackers to reset administrator passwords without authentica… No fix yet Fix from $1,6002026-03-06 HIGH 8.2 CVE-2018-25170 DoceboLMS 1.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code thro… No fix yet Fix from $1,9502026-03-06 MEDIUM 5.1 CVE-2026-1468 QuickCMS is vulnerable to Cross-Site Request Forgery across multiple endpoints. An attacker can craft special website, which when visited by the vict… Mitigation only Fix from $1,6002026-03-06 HIGH 7.5 CVE-2026-3589 The WooCommerce WordPress plugin from versions 5.4.0 to 10.5.2 does not properly handle batch requests, which could allow unauthenticated users to ma… Mitigation only Fix from $1,9502026-03-06 HIGH 8.1 CVE-2025-59541 Chamilo is a learning management system. Prior to version 1.11.34, a Cross-Site Request Forgery (CSRF) vulnerability allows an attacker to delete pro… Chamilo Lms 1.11.34+ Fix from $1,9502026-03-06 HIGH 7.1 CVE-2026-28477 OpenClaw versions prior to 2026.2.14 contain an oauth state validation bypass vulnerability in the manual Chutes login flow that allows attackers to … Openclaw 2026.2.14+ Fix from $1,9502026-03-05 CRITICAL 9.8 CVE-2026-30793 Cross-Site Request Forgery (CSRF) vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter UR… Rustdesk after 1.4.5 Fix from $2,3002026-03-05 MEDIUM 5.4 CVE-2025-64166 Mercurius is a GraphQL adapter for Fastify. Prior to version 16.4.0, a cross-site request forgery (CSRF) vulnerability was identified. The issue aris… Mercurius 16.4.0+ Fix from $1,6002026-03-05 MEDIUM 6.8 CVE-2026-2994 Concrete CMS below version 9.4.8 is subject to CSRF by a Rogue Administrator using the Anti-Spam Allowlist Group Configuration via group_id parameter… Concrete Cms 9.4.8+ Fix from $1,6002026-03-04 HIGH 8.1 CVE-2021-35486 A Cross-Site Request Forgery (CSRF) vulnerability in Nokia IMPACT through 19.11.2.10-20210118042150283 allows a remote attacker to import and overwri… Impact Mobile after 19.11.2.10-20210118042150283 Fix from $1,9502026-03-03 MEDIUM 6.5 CVE-2026-27758 SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a cross-site request forgery vulnerability in its management interface that allows… Sl902 Swtgw124as Firmware after 200.1.20 Fix from $1,6002026-02-27 MEDIUM 6.5 CVE-2026-27609 Parse Dashboard is a standalone dashboard for managing Parse Server apps. In versions 7.3.0-alpha.42 through 9.0.0-alpha.7, the AI Agent API endpoint… Parse Dashboard Mitigation only Fix from $1,6002026-02-25 MEDIUM 6.5 CVE-2026-27589 Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, the local caddy admin API (default listen `127.0.0.1:2019`)… Caddy 2.11.1+ Fix from $1,6002026-02-24 HIGH 8.7 CVE-2026-25649 Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users can steal OAuth 2.0 … Traccar after 6.11.1 Fix from $1,9502026-02-23 MEDIUM 5.1 CVE-2026-23694 Aruba HiSpeed Cache (aruba-hispeed-cache) WordPress plugin versions prior to 3.0.5 contain a cross-site request forgery (CSRF) vulnerability affectin… Mitigation only Fix from $1,6002026-02-23 MEDIUM 6.5 CVE-2025-13671 Cross-Site Request Forgery (CSRF) vulnerability in OpenText™ Web Site Management Server allows Cross Site Request Forgery. The vulnerability could ma… Web Site Management Server No fix yet Fix from $1,6002026-02-19 HIGH 7.1 CVE-2026-26317 OpenClaw is a personal AI assistant. Prior to 2026.2.14, browser-facing localhost mutation routes accepted cross-origin browser requests without expl… Openclaw 2026.2.14+ Fix from $1,9502026-02-19 MEDIUM 5.4 CVE-2026-27050 Cross-Site Request Forgery (CSRF) vulnerability in ThimPress RealPress realpress allows Cross Site Request Forgery.This issue affects RealPress: from… Mitigation only Fix from $1,6002026-02-19 MEDIUM 5.4 CVE-2026-25422 Cross-Site Request Forgery (CSRF) vulnerability in Themes4WP Popularis Extra popularis-extra allows Cross Site Request Forgery.This issue affects Pop… Mitigation only Fix from $1,6002026-02-19 MEDIUM 5.4 CVE-2026-25337 Cross-Site Request Forgery (CSRF) vulnerability in wpcoachify Coachify coachify allows Cross Site Request Forgery.This issue affects Coachify: from n… Mitigation only Fix from $1,6002026-02-19