Vulnerability index

Browse CVEs

7,362 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 7.5 CVE-2026-16262 The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an un… No fix yet Fix from $1,9502026-08-07 MEDIUM 6.5 CVE-2026-66686 Unauthenticated Cross Site Request Forgery (CSRF) in Plugins Garbage Collector (Database Cleanup) <= 0.14 versions. No fix yet Fix from $1,6002026-08-06 HIGH 7.1 CVE-2026-28172 Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions. No fix yet Fix from $1,9502026-08-06 MEDIUM 5.4 CVE-2025-13394 The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Request Forgery (CSRF) attacks. Sp… Api Control Plane 2.0.0.401 / 2.0.0.421+ Fix from $1,6002026-08-06 MEDIUM 6.5 CVE-2026-14204 The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, allowing attackers to trick a lo… No fix yet Fix from $1,6002026-08-06 MEDIUM 5.3 CVE-2026-14313 PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-bacs-receipt-upload-for-wooco… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.5 CVE-2026-66885 Cross-Site Request Forgery (CSRF) vulnerability in livebook-dev livebook allows an attacker to authenticate a victim's browser session under the atta… Livebook 0.18.7 / 0.19.9+ Fix from $1,6002026-08-05 HIGH 8.8 CVE-2026-70432 A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows attackers to execute arbitrary co… No fix yet Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-7326 A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures a… No fix yet Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-71273 OpenBK7231T's /cfg_wifi_set endpoint (src/httpserver/http_fns.c) accepts configuration changes via a plain GET request with no CSRF token. If the par… No fix yet Fix from $1,6002026-08-05 HIGH 8.8 CVE-2026-60009 In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled deploymen… Theia 1.74.0+ Fix from $1,9502026-08-05 HIGH 8.1 CVE-2026-7444 The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.16. This is du… No fix yet Fix from $1,9502026-08-05 CRITICAL 9.6 CVE-2026-70376 Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain in data/inc/functions.admin.php, gating every admin.ph… No fix yet Fix from $2,3002026-08-05 HIGH 8.8 CVE-2026-69082 CTI-Transmute contained a cross-site request forgery vulnerability in the administrative user deletion functionality. The /account/delete/<id> endpoi… No fix yet Fix from $1,9502026-08-03 MEDIUM 5.4 CVE-2026-16292 The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing… No fix yet Fix from $1,6002026-08-02 HIGH 8.1 CVE-2026-12586 The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset action, validating only a CS… No fix yet Fix from $1,9502026-08-02 HIGH 8.8 CVE-2026-15988 The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… No fix yet Fix from $1,9502026-08-01 HIGH 8.8 CVE-2026-50986 PrestaShop module, totadministrativemandate <1.8.1 is vulnerable to Cross Site Request Forgery (CSRF). The payment validation controller has no CSRF … No fix yet Fix from $1,9502026-07-31 MEDIUM 6.9 CVE-2025-67651 A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSit… No fix yet Fix from $1,6002026-07-31 HIGH 8.8 CVE-2026-66416 Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to perform state-changing actions on behalf … Mitigation only Fix from $1,9502026-07-30 MEDIUM 6.1 CVE-2026-44613 Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin state-changing requests and a… Zeppelin 0.12.1+ Fix from $1,6002026-07-30 HIGH 8.8 CVE-2026-28813 Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Users are recommended to upgrade to version 2.12.… Jspwiki 2.12.4+ Fix from $1,9502026-07-30 HIGH 8.3 CVE-2026-5219 Cross-Site request forgery (CSRF) vulnerability in Softtr Information Technology Trade Ltd. Co. E-Commerce Pack allows Cross Site Request Forgery. T… No fix yet Fix from $1,9502026-07-30 HIGH 7.1 CVE-2026-14239 The tourmaster WordPress plugin before 5.4.8 does not perform a nonce check when storing a custom-filter label taken from a request parameter, and do… No fix yet Fix from $1,9502026-07-30 MEDIUM 6.5 CVE-2026-17936 Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific… Chrome 151.0.7922.72+ Fix from $1,6002026-07-30 HIGH 8.8 CVE-2026-2482 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to exe… Websphere Application Server 26.0.0.9+ Fix from $1,9502026-07-29 HIGH 7.3 CVE-2026-65947 Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2 Gridbox 2.20.2+ Fix from $1,9502026-07-29 HIGH 8.8 CVE-2026-65944 Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0 Ro Csvi 9.11.0+ Fix from $1,9502026-07-29 HIGH 7.1 CVE-2026-14234 The WOLF WordPress plugin before 1.1.0 does not perform a nonce or capability check on one of its AJAX actions, allowing an unauthenticated attacker… No fix yet Fix from $1,9502026-07-29 MEDIUM 6.9 CVE-2026-47725 nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.3, every /ui/* POST / PUT / PATCH / DE… No fix yet Fix from $1,6002026-07-28