Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 7.1 CVE-2021-25095 The IP2Location Country Blocker WordPress plugin before 2.26.5 does not have authorisation and CSRF checks in the ip2location_country_blocker_save_ru… Country Blocker 2.26.5+ Fix from $1,9502022-02-07 MEDIUM 6.5 CVE-2021-24947 The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_regions_file_path parameter in… Responsive Vector Maps 6.4.2+ Fix from $1,6002022-02-07 MEDIUM 6.5 CVE-2021-24993 The Ultimate Product Catalog WordPress plugin before 5.0.26 does not have authorisation and CSRF checks in some AJAX actions, which could allow any a… Ultimate Product Catalog 5.0.26+ Fix from $1,6002022-02-07 MEDIUM 6.5 CVE-2021-24843 The SupportCandy WordPress plugin before 2.2.7 does not have CRSF check in its wpsc_tickets AJAX action, which could allow attackers to make a logged… Supportcandy 2.2.7+ Fix from $1,6002022-02-07 HIGH 8.8 CVE-2021-24879 The SupportCandy WordPress plugin before 2.2.7 does not have CSRF check in the wpsc_tickets AJAX action, nor has any sanitisation or escaping in some… Supportcandy 2.2.7+ Fix from $1,9502022-02-07 MEDIUM 6.5 CVE-2021-32732 ### Impact It's possible to know if a user has or not an account in a wiki related to an email address, and which username(s) is actually tied to tha… Xwiki 12.10.5+ Fix from $1,6002022-02-04 HIGH 8.8 CVE-2020-7534 A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists on the web server used, that could cause a leak of sensitive data or unauthorized a… Modicon M340 Bmxp342020 Firmware Patch available Fix from $1,9502022-02-04 HIGH 8.8 CVE-2021-46398EPSS 7% A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor user with admin privilege and ge… Filebrowser 2.18.0+ Fix from $1,9502022-02-04 HIGH 8.8 CVE-2021-45268 A Cross Site Request Forgery (CSRF) vulnerability exists in Backdrop CMS 1.20, which allows Remote Attackers to gain Remote Code Execution (RCE) on t… Backdrop No fix yet Fix from $1,9502022-02-03 HIGH 8.8 CVE-2021-39044 IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthoriz… Financial Transaction Manager Mitigation only Fix from $1,9502022-02-02 HIGH 8.8 CVE-2022-23601 Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony form component provides a CSRF protecti… Symfony 5.3.15 / 5.4.4+ Fix from $1,9502022-02-01 MEDIUM 6.5 CVE-2021-25072 The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.25 does not have CSRF check in place when deleting items, allowing attacker … Social Networks Auto Poster 4.3.25+ Fix from $1,6002022-02-01 MEDIUM 6.5 CVE-2021-25092 The Link Library WordPress plugin before 7.2.8 does not have CSRF check when resetting library settings, allowing attackers to make a logged in admin… Link Library 7.2.8+ Fix from $1,6002022-02-01 MEDIUM 6.5 CVE-2021-25097 The LabTools WordPress plugin through 1.0 does not have proper authorisation and CSRF check in place when deleting publications, allowing any authent… Labtools after 1.0 Fix from $1,6002022-02-01 MEDIUM 6.5 CVE-2021-24761 The Error Log Viewer WordPress plugin before 1.1.2 does not perform nonce check when deleting a log file and does not have path traversal prevention,… Error Log Viewer 1.1.2+ Fix from $1,6002022-02-01 HIGH 8.8 CVE-2021-24763 The Perfect Survey WordPress plugin before 1.5.2 does not have proper authorisation nor CSRF checks in the save_global_setting AJAX action, allowing … Perfect Survey 1.5.2+ Fix from $1,9502022-02-01 MEDIUM 6.5 CVE-2022-23887 YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily delete user accounts via /admin/admin… Yzmcms No fix yet Fix from $1,6002022-01-28 HIGH 8.8 CVE-2022-23888 YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgey (CSRF) via the component /yzmcms/comment/index/init.html. Yzmcms No fix yet Fix from $1,9502022-01-28 HIGH 8.8 CVE-2021-22724 A CVE-352 Cross-Site Request Forgery (CSRF) vulnerability exists that could allow an attacker to impersonate the user or carry out actions on their b… Evc1s22p4 Firmware 3.4.0.2+ Fix from $1,9502022-01-28 HIGH 8.8 CVE-2021-22725 A CVE-352 Cross-Site Request Forgery (CSRF) vulnerability exists that could allow an attacker to impersonate the user or carry out actions on their b… Evc1s22p4 Firmware 3.4.0.2+ Fix from $1,9502022-01-28 HIGH 8.8 CVE-2021-44122 SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php, ecrire/balise/… Spip Patch available Fix from $1,9502022-01-26 HIGH 8.8 CVE-2022-0335 A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The "delete badge alignment" f… Moodle 3.9.12 / 3.10.9+ Fix from $1,9502022-01-25 HIGH 8.0 CVE-2022-0269 Cross-Site Request Forgery (CSRF) in Packagist yetiforce/yetiforce-crm prior to 6.3.0. Yetiforce Customer Relationship Management 6.3.0+ Fix from $1,9502022-01-24 MEDIUM 6.5 CVE-2021-24989 The Accept Donations with PayPal WordPress plugin before 1.3.4 does not have CSRF check in place and does not ensure that the post to be deleted belo… Accept Donations With Paypal 1.3.4+ Fix from $1,6002022-01-24 MEDIUM 6.5 CVE-2021-25013 The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJAX action, and does not ensure… Qubely 1.7.8+ Fix from $1,6002022-01-24 HIGH 8.8 CVE-2021-25073 The WP125 WordPress plugin before 1.5.5 does not have CSRF checks in various action, for example when deleting an ad, allowing attackers to make a lo… Wp125 1.5.5+ Fix from $1,9502022-01-24 HIGH 8.8 CVE-2021-24696 The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) ma… Simple Download Monitor 3.9.9+ Fix from $1,9502022-01-24 HIGH 8.0 CVE-2021-24936 The WP Extra File Types WordPress plugin before 0.5.1 does not have CSRF check when saving its settings, nor sanitise and escape some of them, which … Wp Extra File Types 0.5.1+ Fix from $1,9502022-01-24 MEDIUM 5.7 CVE-2021-24968 The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the ewd_ufaq_welcome_add_faq and ewd_ufaq_welcome_add_faq_… Ultimate Faq 2.1.2+ Fix from $1,6002022-01-24 MEDIUM 6.5 CVE-2021-46027 mysiteforme, as of 19-12-2022, has a CSRF vulnerability in the background blog management. The attacker constructs a CSRF load. Once the administrato… Mysiteforme No fix yet Fix from $1,6002022-01-19