Vulnerability index

Browse CVEs

7,366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.1 CVE-2025-12401 The Label Plugins plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5. This is due to missing … Mitigation only Fix from $1,6002025-11-04 MEDIUM 5.4 CVE-2025-64368 Cross-Site Request Forgery (CSRF) vulnerability in Mikado-Themes Bard bardwp allows Cross Site Request Forgery.This issue affects Bard: from n/a thro… Bard 1.7+ Fix from $1,6002025-10-31 MEDIUM 5.4 CVE-2023-53688 Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) and cross-site request forgery (CSRF) via the Hypermap Replay compone… Nagios Xi 5.11.3+ Fix from $1,6002025-10-30 MEDIUM 5.1 CVE-2025-10317 Quick.Cart is vulnerable to Cross-Site Request Forgery in product creation functionality. Malicious attacker can craft special website, which when vi… Mitigation only Fix from $1,6002025-10-30 HIGH 8.6 CVE-2025-62797 FluxCP is a web-based Control Panel for rAthena servers written in PHP. A critical Cross-Site Request Forgery (CSRF) vulnerability exists in the Flux… Patch available Fix from $1,9502025-10-29 HIGH 8.8 CVE-2025-12479 Systemic Lack of Cross-Site Request Forgery (CSRF) Token Implementation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . Blu Ic2 Firmware 1.20+ Fix from $1,9502025-10-29 MEDIUM 5.4 CVE-2025-64149 A cross-site request forgery (CSRF) vulnerability in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers to connect to an attacker-s… Publish To Bitbucket after 0.4 Fix from $1,6002025-10-29 MEDIUM 5.4 CVE-2025-64133 A cross-site request forgery (CSRF) vulnerability in Jenkins Extensible Choice Parameter Plugin 239.v5f5c278708cf and earlier allows attackers to exe… Extensible Choice Parameter after 239.v5f5c278708cf Fix from $1,6002025-10-29 HIGH 7.1 CVE-2025-60075 Cross-Site Request Forgery (CSRF) vulnerability in Allegro Marketing hpb seo plugin for WordPress hpbseo allows Reflected XSS.This issue affects hpb … Mitigation only Fix from $1,9502025-10-29 MEDIUM 5.3 CVE-2025-57931 Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Popup box ays-popup-box allows Cross Site Request Forgery.This issue affects Popup box: fr… Mitigation only Fix from $1,6002025-10-29 MEDIUM 5.4 CVE-2025-55758 Multiple CSRF attack vectors in JDownloads component 1.0.0-4.0.47 for Joomla were discovered. Mitigation only Fix from $1,6002025-10-28 MEDIUM 6.5 CVE-2025-62258 CSRF vulnerability in Headless API in Liferay Portal 7.4.0 through 7.4.3.107, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, … Digital Experience Platform 7.4.3.108+ Fix from $1,6002025-10-27 MEDIUM 6.1 CVE-2025-54969 An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service does not implement CSRF protections. An attacker who social… Socet Gxp 4.6.0.2+ Fix from $1,6002025-10-27 HIGH 7.0 CVE-2025-34133 Wimi Teamwork versions prior to 7.38.17 contains a cross-site request forgery (CSRF) vulnerability in its API. The API accepts any authenticated requ… Mitigation only Fix from $1,9502025-10-27 MEDIUM 5.4 CVE-2025-11154 The IDonate WordPress plugin before 2.1.13 does not have authorisation and CSRF when deleting users via an action handler, allowing unauthenticated … Idonate 2.1.13+ Fix from $1,6002025-10-27 HIGH 7.1 CVE-2025-62986 Cross-Site Request Forgery (CSRF) vulnerability in FanBridge FanBridge signup fanbridge-signup allows Stored XSS.This issue affects FanBridge signup:… Mitigation only Fix from $1,9502025-10-27 HIGH 7.1 CVE-2025-62957 Cross-Site Request Forgery (CSRF) vulnerability in NikanWP NikanWP WooCommerce Reporting wc-reports-lite allows Stored XSS.This issue affects NikanWP… Mitigation only Fix from $1,9502025-10-27 HIGH 7.1 CVE-2025-62962 Cross-Site Request Forgery (CSRF) vulnerability in Andrea Landonio CloudSearch cloud-search allows Stored XSS.This issue affects CloudSearch: from n/… Mitigation only Fix from $1,9502025-10-27 HIGH 7.1 CVE-2025-62956 Cross-Site Request Forgery (CSRF) vulnerability in iseremet Reloadly reloadly-topup-widget allows Stored XSS.This issue affects Reloadly: from n/a th… Mitigation only Fix from $1,9502025-10-27 HIGH 7.1 CVE-2025-62945 Cross-Site Request Forgery (CSRF) vulnerability in Eduard Pinuaga Linares Did Prestashop Display did-prestashop-display allows Stored XSS.This issue … Mitigation only Fix from $1,9502025-10-27 HIGH 7.1 CVE-2025-62933 Cross-Site Request Forgery (CSRF) vulnerability in Prakash Awesome Testimonials awesome-testimonials allows Stored XSS.This issue affects Awesome Tes… Mitigation only Fix from $1,9502025-10-27 HIGH 7.1 CVE-2025-62934 Cross-Site Request Forgery (CSRF) vulnerability in Mejar WP Business Hours wp-business-hours allows Stored XSS.This issue affects WP Business Hours: … Mitigation only Fix from $1,9502025-10-27 HIGH 7.1 CVE-2025-62896 Cross-Site Request Forgery (CSRF) vulnerability in digitaldonkey Multilang Contact Form multilang-contact-form allows Stored XSS.This issue affects M… Mitigation only Fix from $1,9502025-10-27 HIGH 7.1 CVE-2025-62886 Cross-Site Request Forgery (CSRF) vulnerability in wpdevart Pricing Table builder wpdevart-pricing-table allows Stored XSS.This issue affects Pricing… Mitigation only Fix from $1,9502025-10-27 HIGH 8.8 CVE-2025-12221 Busybox 1.31.1 - Multiple Known Vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. Blu Ic2 Firmware 1.20+ Fix from $1,9502025-10-25 HIGH 8.8 CVE-2025-12095 The Simple Registration for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.8.… Mitigation only Fix from $1,9502025-10-25 HIGH 8.8 CVE-2025-12028 The IndieAuth plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.4. This is due to missing no… Mitigation only Fix from $1,9502025-10-24 MEDIUM 5.3 CVE-2025-56009 Cross site request forgery (CSRF) vulnerability in KeeneticOS before 4.3 at "/rci" API endpoint allows attackers to take over the device via adding a… Keeneticos 4.3+ Fix from $1,6002025-10-23 HIGH 7.1 CVE-2025-62005 Cross-Site Request Forgery (CSRF) vulnerability in FantasticPlugins SUMO Memberships for WooCommerce sumomemberships allows Cross Site Request Forger… Mitigation only Fix from $1,9502025-10-22 HIGH 7.1 CVE-2025-60168 Cross-Site Request Forgery (CSRF) vulnerability in integrationshotelrunner HotelRunner Booking Widget hotelrunner allows Stored XSS.This issue affect… Mitigation only Fix from $1,9502025-10-22