Vulnerability index

Browse CVEs

7,366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 5.4 CVE-2021-41074 A CSRF issue in index.php in QloApps hotel eCommerce 1.5.1 allows an attacker to change the admin's email address via a crafted HTML document. Qloapps Mitigation only Fix from $1,6002026-01-12 MEDIUM 5.4 CVE-2025-14976 The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugi… Mitigation only Fix from $1,6002026-01-10 MEDIUM 6.5 CVE-2026-22030 React Router is a router for React. In @remix-run/server-runtime version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, React Router (or Rem… React Router 2.17.3+ Fix from $1,6002026-01-10 HIGH 8.8 CVE-2026-22194 GestSup versions up to and including 3.2.60 contain a cross-site request forgery (CSRF) vulnerability where the application does not verify the authe… Gestsup after 3.2.56 Fix from $1,9502026-01-09 HIGH 8.8 CVE-2025-68158 Authlib is a Python library which builds OAuth and OpenID Connect servers. In versions 1.0.0 through 1.6.5, cache-backed state/request-token storage … Authlib 1.6.6+ Fix from $1,9502026-01-08 MEDIUM 6.8 CVE-2025-61547 Cross-Site Request Forgery (CSRF) is present on all functions in edu Business Solutions Print Shop Pro WebDesk version 18.34 (fixed in 19.76). The ap… Print Shop Pro Webdesk No fix yet Fix from $1,6002026-01-08 MEDIUM 5.3 CVE-2019-25259 Leica Geosystems GR10/GR25/GR30/GR50 GNSS 4.30.063 contains a cross-site request forgery vulnerability that allows attackers to perform administrativ… No fix yet Fix from $1,6002026-01-08 MEDIUM 6.1 CVE-2025-13519 The SVG Map Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missi… Mitigation only Fix from $1,6002026-01-07 HIGH 8.8 CVE-2020-36908 SnapGear Management Console SG560 version 3.1.5 contains a cross-site request forgery vulnerability that allows attackers to perform administrative a… Snapgear Sg560 Firmware No fix yet Fix from $1,9502026-01-06 MEDIUM 5.4 CVE-2023-52212 Cross-Site Request Forgery (CSRF) vulnerability in Automattic WP Job Manager allows Cross Site Request Forgery.This issue affects WP Job Manager: fro… Mitigation only Fix from $1,6002026-01-05 CRITICAL 9.3 CVE-2026-21430 Emlog is an open source website building system. In version 2.5.23, article creation functionality is vulnerable to cross-site request forgery (CSRF)… Emlog No fix yet Fix from $2,3002026-01-02 HIGH 8.8 CVE-2025-15405 A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function. The manipulation results in cross-site request forger… Phpems after 11.0 Fix from $1,9502026-01-01 HIGH 7.1 CVE-2025-31054 Cross-Site Request Forgery (CSRF) vulnerability in Themefy Bloggie allows Reflected XSS.This issue affects Bloggie: from n/a through 2.0.8. Mitigation only Fix from $1,9502025-12-31 MEDIUM 5.4 CVE-2025-62134 Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Contact Form Widget new-contact-form-widget allows Cross Site Request Forgery.This issue… Mitigation only Fix from $1,6002025-12-31 MEDIUM 5.4 CVE-2025-62117 Cross-Site Request Forgery (CSRF) vulnerability in Jayce53 EasyIndex easyindex allows Cross Site Request Forgery.This issue affects EasyIndex: from n… Mitigation only Fix from $1,6002025-12-31 MEDIUM 5.4 CVE-2025-62120 Cross-Site Request Forgery (CSRF) vulnerability in Rick Beckman OpenHook thesis-openhook allows Cross Site Request Forgery.This issue affects OpenHoo… Mitigation only Fix from $1,6002025-12-31 HIGH 8.1 CVE-2025-62992 Cross-Site Request Forgery (CSRF) vulnerability in everestthemes Everest Backup everest-backup allows Path Traversal.This issue affects Everest Backu… Everest Backup after 2.3.9 Fix from $1,9502025-12-31 HIGH 7.1 CVE-2025-49028 Cross-Site Request Forgery (CSRF) vulnerability in Zoho Mail Zoho ZeptoMail transmail allows Stored XSS.This issue affects Zoho ZeptoMail: from n/a t… Mitigation only Fix from $1,9502025-12-31 HIGH 7.1 CVE-2025-49353 Cross-Site Request Forgery (CSRF) vulnerability in Marcin Kijak Noindex by Path noindex-by-path allows Stored XSS.This issue affects Noindex by Path:… Mitigation only Fix from $1,9502025-12-31 HIGH 7.1 CVE-2025-49354 Cross-Site Request Forgery (CSRF) vulnerability in Mindstien Technologies Recent Posts From Each Category recent-posts-from-each-category allows Stor… Mitigation only Fix from $1,9502025-12-31 HIGH 7.1 CVE-2025-68885 Cross-Site Request Forgery (CSRF) vulnerability in page-carbajal Custom Post Status custom-post-status allows Stored XSS.This issue affects Custom Po… Mitigation only Fix from $1,9502025-12-31 HIGH 7.1 CVE-2025-49342 Cross-Site Request Forgery (CSRF) vulnerability in merzedes Custom Style custom-style allows Stored XSS.This issue affects Custom Style: from n/a thr… Mitigation only Fix from $1,9502025-12-31 HIGH 7.1 CVE-2025-49343 Cross-Site Request Forgery (CSRF) vulnerability in socialprofilr Social Profilr social-profilr-display-social-network-profile allows Stored XSS.This … No fix yet Fix from $1,9502025-12-31 HIGH 7.1 CVE-2025-49344 Cross-Site Request Forgery (CSRF) vulnerability in reneade SensitiveTagCloud sensitive-tag-cloud allows Stored XSS.This issue affects SensitiveTagClo… Mitigation only Fix from $1,9502025-12-31 HIGH 7.1 CVE-2025-49345 Cross-Site Request Forgery (CSRF) vulnerability in mg12 WP-EasyArchives wp-easyarchives allows Stored XSS.This issue affects WP-EasyArchives: from n/… Mitigation only Fix from $1,9502025-12-31 HIGH 7.1 CVE-2025-59137 Cross-Site Request Forgery (CSRF) vulnerability in eleopard Behance Portfolio Manager portfolio-manager-powered-by-behance allows Stored XSS.This iss… Mitigation only Fix from $1,9502025-12-31 HIGH 7.1 CVE-2025-49346 Cross-Site Request Forgery (CSRF) vulnerability in peterwsterling Simple Archive Generator simple-archive-generator allows Stored XSS.This issue affe… Mitigation only Fix from $1,9502025-12-31 HIGH 7.1 CVE-2025-59131 Cross-Site Request Forgery (CSRF) vulnerability in hoernerfranz WP-CalDav2ICS wp-caldav2ics allows Stored XSS.This issue affects WP-CalDav2ICS: from … Mitigation only Fix from $1,9502025-12-30 HIGH 8.8 CVE-2022-50804 JM-DATA ONU JF511-TV version 1.0.67 is vulnerable to cross-site request forgery (CSRF) attacks, allowing attackers to perform administrative actions … Onu Jf511 Tv Firmware No fix yet Fix from $1,9502025-12-30 CRITICAL 9.6 CVE-2025-52835 Cross-Site Request Forgery (CSRF) vulnerability in ConoHa by GMO WING WordPress Migrator wing-migrator allows Upload a Web Shell to a Web Server.This… Mitigation only Fix from $2,3002025-12-30