Vulnerability index

Browse CVEs

7,366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2025-13177 A vulnerability was detected in Bdtask/CodeCanyon SalesERP up to 20250728. This affects an unknown part. The manipulation results in cross-site reque… Saleserp after 2025-10-16 Fix from $1,9502025-11-14 MEDIUM 6.5 CVE-2025-59480 Mattermost Mobile Apps versions <=2.32.0 fail to verify that SSO redirect tokens originate from the trusted server, which allows a malicious Mattermo… Mattermost Mobile 2.33.0+ Fix from $1,6002025-11-13 MEDIUM 6.5 CVE-2025-13119 A flaw has been found in Fabian Ros/SourceCodester Simple E-Banking System 1.0. This affects an unknown part. This manipulation causes cross-site req… Simple E Banking System No fix yet Fix from $1,6002025-11-13 MEDIUM 6.5 CVE-2025-64271 Cross-Site Request Forgery (CSRF) vulnerability in HasThemes WP Plugin Manager wp-plugin-manager allows Cross Site Request Forgery.This issue affects… Wp Plugin Manager 1.4.8+ Fix from $1,6002025-11-13 MEDIUM 6.5 CVE-2025-64262 Cross-Site Request Forgery (CSRF) vulnerability in ramon fincken Auto Prune Posts auto-prune-posts allows Cross Site Request Forgery.This issue affec… Mitigation only Fix from $1,6002025-11-13 HIGH 8.8 CVE-2025-57310 A Cross-Site Request Forgery (CSRF) vulnerability in Salmen2/Simple-Faucet-Script v1.07 via crafted POST request to admin.php?p=ads&c=1 allowing atta… Simple Faucet Script No fix yet Fix from $1,9502025-11-12 MEDIUM 6.5 CVE-2025-60645 A Cross-Site Request Forgery (CSRF) in xxl-api v1.3.0 allows attackers to arbitrarily add users to the management module via a crafted GET request. Xxl Api after 1.3.0 Fix from $1,6002025-11-12 MEDIUM 6.1 CVE-2025-12589 The WP-Walla plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in all versions up to, and including, 0.… Mitigation only Fix from $1,6002025-11-11 MEDIUM 6.1 CVE-2025-12590 The YSlider plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in all versions up to, and including, 1.1… Mitigation only Fix from $1,6002025-11-11 HIGH 7.1 CVE-2025-63711 A Cross-Site Request Forgery (CSRF) vulnerability in the SourceCodester Client Database Management System 1.0 allows an attacker to cause an authenti… Client Database Management System No fix yet Fix from $1,9502025-11-10 HIGH 8.8 CVE-2025-63712 Cross-Site Request Forgery (CSRF) in SourceCodester Product Expiry Management System. The User Management module (delete-user.php) allows remote atta… Web Based Pharmacy Product Management System No fix yet Fix from $1,9502025-11-10 MEDIUM 6.5 CVE-2025-63710 The send_message.php endpoint in SourceCodester Simple Public Chat Room 1.0 is vulnerable to Cross-Site Request Forgery (CSRF). The application does … Simple Public Chat Room No fix yet Fix from $1,6002025-11-10 MEDIUM 6.5 CVE-2025-63717 The change password functionality at /pet_grooming/admin/change_pass.php in SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cros… Pet Grooming Management Software No fix yet Fix from $1,6002025-11-07 MEDIUM 6.5 CVE-2025-63716 The SourceCodester Leads Manager Tool v1.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow unauthorized state-changing operatio… Leads Manager Tool No fix yet Fix from $1,6002025-11-07 HIGH 8.8 CVE-2025-58469 A cross-site request forgery (CSRF) vulnerability has been reported to affect QuLog Center. The remote attackers can then exploit the vulnerability t… Qulog Center 1.8.2.923+ Fix from $1,9502025-11-07 HIGH 7.1 CVE-2025-53316 Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel WP GDPR Cookie Consent wp-gdpr-cookie-consent allows Stored XSS.This issue affects… Mitigation only Fix from $1,9502025-11-06 HIGH 7.1 CVE-2025-48077 Cross-Site Request Forgery (CSRF) vulnerability in nitinmaurya12 Block Country block-country allows Stored XSS.This issue affects Block Country: from… Mitigation only Fix from $1,9502025-11-06 HIGH 7.1 CVE-2025-48078 Cross-Site Request Forgery (CSRF) vulnerability in Norbert Slick Google Map slick-google-map allows Stored XSS.This issue affects Slick Google Map: f… Mitigation only Fix from $1,9502025-11-06 HIGH 7.1 CVE-2025-48083 Cross-Site Request Forgery (CSRF) vulnerability in andriassundskard wpNamedUsers wpnamedusers allows Stored XSS.This issue affects wpNamedUsers: from… Mitigation only Fix from $1,9502025-11-06 HIGH 7.1 CVE-2025-48085 Cross-Site Request Forgery (CSRF) vulnerability in ZIPANG Simple Stripe simple-stripe allows Stored XSS.This issue affects Simple Stripe: from n/a th… Mitigation only Fix from $1,9502025-11-06 MEDIUM 6.1 CVE-2025-12456 The Centangle-Team plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missi… Mitigation only Fix from $1,6002025-11-04 MEDIUM 6.1 CVE-2025-12452 The Visit Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validati… Mitigation only Fix from $1,6002025-11-04 MEDIUM 6.1 CVE-2025-12412 The Top Bar Notification plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.12. This is due to … Mitigation only Fix from $1,6002025-11-04 MEDIUM 5.4 CVE-2025-12413 The Social Media WPCF7 Stop Words plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.3. This … Mitigation only Fix from $1,6002025-11-04 MEDIUM 6.1 CVE-2025-12415 The MapMap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing or inco… Mitigation only Fix from $1,6002025-11-04 MEDIUM 6.1 CVE-2025-12416 The Pagerank Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Site Request Forgery in all versions up to, and includ… Mitigation only Fix from $1,6002025-11-04 MEDIUM 6.1 CVE-2025-12400 The LMB^Box Smileys plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2. This is due to missin… Mitigation only Fix from $1,6002025-11-04 MEDIUM 6.1 CVE-2025-12402 The LinkedIn Resume plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.00. This is due to missi… Mitigation only Fix from $1,6002025-11-04 MEDIUM 6.1 CVE-2025-12403 The Associados Amazon Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.8. This is due … Mitigation only Fix from $1,6002025-11-04 MEDIUM 6.1 CVE-2025-12410 The SH Contextual Help plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.1. This is due to m… Mitigation only Fix from $1,6002025-11-04