Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.1 CVE-2021-38342 The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to Cross-Site Request Forgery via the `npBulkAction`s and `npBulkEdit` `admin_post` action… Nested Pages after 3.1.15 Fix from $1,9502021-08-30 MEDIUM 6.5 CVE-2020-18123 A cross-site request forgery (CSRF) vulnerability in Indexhibit 2.1.5 allows attackers to arbitrarily delete admin accounts. Indexhibit No fix yet Fix from $1,6002021-08-30 MEDIUM 5.7 CVE-2020-18124 A cross-site request forgery (CSRF) vulnerability in Indexhibit 2.1.5 allows attackers to arbitrarily reset account passwords. Indexhibit No fix yet Fix from $1,6002021-08-30 HIGH 8.8 CVE-2021-24581 The Blue Admin WordPress plugin through 21.06.01 does not sanitise or escape its "Logo Title" setting before outputting in a page, leading to a Store… Blue Admin after 21.06.01 Fix from $1,9502021-08-30 HIGH 8.8 CVE-2021-40172 Zoho ManageEngine Log360 before Build 5219 allows a CSRF attack on proxy settings. Manageengine Log360 after 5.1 Fix from $1,9502021-08-29 HIGH 8.8 CVE-2021-40173 Zoho ManageEngine Cloud Security Plus before Build 4117 allows a CSRF attack on the server proxy settings. Manageengine Cloud Security Plus after 4.0 Fix from $1,9502021-08-29 HIGH 8.8 CVE-2021-40174 Zoho ManageEngine Log360 before Build 5224 allows a CSRF attack for disabling the logon security settings. Manageengine Log360 after 5.1 Fix from $1,9502021-08-29 HIGH 8.8 CVE-2021-3734 yourls is vulnerable to Improper Restriction of Rendered UI Layers or Frames Yourls after 1.8.1 Fix from $1,9502021-08-26 HIGH 8.8 CVE-2020-18917 The plus/search.php component in DedeCMS 5.7 SP2 allows remote attackers to execute arbitrary PHP code via the typename parameter because the content… Dedecms No fix yet Fix from $1,9502021-08-24 HIGH 8.8 CVE-2021-23431 The package joplin before 2.3.2 are vulnerable to Cross-site Request Forgery (CSRF) due to missing CSRF checks in various forms. Joplin 2.3.2+ Fix from $1,9502021-08-24 MEDIUM 6.5 CVE-2021-3728 firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) Firefly Iii Patch available Fix from $1,6002021-08-23 MEDIUM 6.5 CVE-2021-3730 firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) Firefly Iii Patch available Fix from $1,6002021-08-23 HIGH 8.8 CVE-2021-24565 The Contact Form 7 Captcha WordPress plugin before 0.0.9 does not have any CSRF check in place when saving its settings, allowing attacker to make a … Contact Form 7 Captcha 0.0.9+ Fix from $1,9502021-08-23 HIGH 8.8 CVE-2021-24555 The daac_delete_booking_callback function, hooked to the daac_delete_booking AJAX action, takes the id POST parameter which is passed into the SQL st… Diary Availability Calendar after 1.0.3 Fix from $1,9502021-08-23 MEDIUM 6.5 CVE-2021-39243 Cross-Site Request Forgery (CSRF) exists on Altus Nexto, Nexto Xpress, and Hadron Xtorm devices via any CGI endpoint. This affects Nexto NX3003 1.8.1… Nexto Nx3003 Firmware No fix yet Fix from $1,6002021-08-23 HIGH 8.1 CVE-2020-24130 A cross site request forgery (CSRF) vulnerability in the configure.html component of Ponzu 0.11.0 allows attackers to change user and administrator c… Ponzu No fix yet Fix from $1,9502021-08-20 HIGH 8.8 CVE-2020-20642 Cross Site Request Forgery (CSRF) vulnerability exists in EyouCMS 1.3.6 that can add an htm page to execute the js code via login.php?m=admin&c=Filem… Eyoucms No fix yet Fix from $1,9502021-08-19 HIGH 8.8 CVE-2021-28490 In OWASP CSRFGuard through 3.1.0, CSRF can occur because the CSRF cookie may be retrieved by using only a session token. Csrfguard after 3.1.0 Fix from $1,9502021-08-19 HIGH 8.8 CVE-2021-34645 The Shopping Cart & eCommerce Store WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_currency_settings function found in the… Shopping Cart \& Ecommerce Store after 5.1.0 Fix from $1,9502021-08-19 HIGH 8.8 CVE-2020-19669 Cross Site Request Forgery (CSRF) vulnerability exists in Eyoucms 1.3.6 that can add an admin account via /login.php?m=admin&c=Admin&a=admin_add&lang… Eyoucms No fix yet Fix from $1,9502021-08-18 HIGH 8.0 CVE-2021-20758 Cross-site request forgery (CSRF) vulnerability in Message of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to hijack the authe… Garoon after 5.0.2 Fix from $1,9502021-08-18 MEDIUM 6.5 CVE-2020-28846 Cross Site Request Forgery (CSRF) vulnerability exists in SeaCMS 10.7 in admin_manager.php, which could let a malicious user add an admin account. Seacms No fix yet Fix from $1,6002021-08-17 MEDIUM 6.5 CVE-2020-4992 IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.16 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious a… Datapower Gateway after 2018.4.1.16 Fix from $1,6002021-08-17 MEDIUM 6.1 CVE-2021-24536 The Custom Login Redirect WordPress plugin through 1.0.0 does not have CSRF check in place when saving its settings, and do not sanitise or escape us… Custom Login Redirect after 1.0.0 Fix from $1,6002021-08-16 MEDIUM 6.1 CVE-2021-24410 The తెలుగు బైబిల్ వచనములు WordPress plugin through 1.0 is lacking any CSRF check when saving its settings and verses, and do not sanitise or escape t… Telugu Bible Verse Daily after 1.0 Fix from $1,6002021-08-16 MEDIUM 6.1 CVE-2021-24411 The Social Tape WordPress plugin through 1.0 does not have CSRF checks in place when saving its settings, and do not sanitise or escape them before o… Social Tape after 1.0 Fix from $1,6002021-08-16 MEDIUM 6.1 CVE-2021-24466 The Verse-O-Matic WordPress plugin through 4.1.1 does not have any CSRF checks in place, allowing attackers to make logged in administrators do unwan… Verse O Matic after 4.1.1 Fix from $1,6002021-08-16 MEDIUM 6.1 CVE-2021-24535 The Light Messages WordPress plugin through 1.0 is lacking CSRF check when updating it's settings, and is not sanitising its Message Content in them … Light Messages after 1.0 Fix from $1,6002021-08-16 HIGH 8.8 CVE-2020-22403 Cross Site Request Forgery (CSRF) vulnerability in Express cart v1.1.16 allows attackers to add an administrator account, add discount code or other … Express Cart after 1.1.10 Fix from $1,9502021-08-12 HIGH 8.0 CVE-2020-18458 Cross Site Request Forgery (CSRF) vulnerability exists in DamiCMS v6.0.6 that can add an admin account via admin.php?s=/Admin/doadd. Damicms No fix yet Fix from $1,9502021-08-12