Vulnerability index

Browse CVEs

7,366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2025-60208 Cross-Site Request Forgery (CSRF) vulnerability in Tusko Trush Advanced Custom Fields : CPT Options Pages acf-cpt-options-pages allows Object Injecti… Mitigation only Fix from $1,9502025-10-22 HIGH 7.1 CVE-2025-60132 Cross-Site Request Forgery (CSRF) vulnerability in johnh10 Video Blogster Lite video-blogster-lite allows Stored XSS.This issue affects Video Blogste… Mitigation only Fix from $1,9502025-10-22 HIGH 7.5 CVE-2025-62771 Mercku M6a devices through 2.1.0 allow password changes via intranet CSRF attacks. Mitigation only Fix from $1,9502025-10-22 HIGH 8.8 CVE-2025-47410 Apache Geode is vulnerable to CSRF attacks through GET requests to the Management and Monitoring REST API that could allow an attacker who has tricke… Geode 1.15.2+ Fix from $1,9502025-10-18 HIGH 8.8 CVE-2025-9890 The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0. This is due to missing o… Mitigation only Fix from $1,9502025-10-18 HIGH 7.3 CVE-2025-60535 A Cross-Site Request Forgery (CSRF) in the component /endpoints/currency/currency of Wallos v4.1.1 allows attackers to execute arbitrary operations v… Mitigation only Fix from $1,9502025-10-14 MEDIUM 5.4 CVE-2025-59428 EspoCRM is an open source customer relationship management application. In versions before 9.1.9, a vulnerability allows arbitrary user creation, inc… Espocrm 9.1.9+ Fix from $1,6002025-10-14 MEDIUM 6.5 CVE-2025-7330 A cross-site request forgery security issue exists in the product and version listed. The vulnerability stems from missing CSRF checks on the impacte… 1783 Natr Firmware 1.007+ Fix from $1,6002025-10-14 MEDIUM 5.4 CVE-2025-42908 Due to a Cross-Site Request Forgery (CSRF) vulnerability in SAP NetWeaver Application Server for ABAP, an authenticated attacker could initiate trans… Mitigation only Fix from $1,6002025-10-14 HIGH 8.8 CVE-2025-61930 Emlog is an open source website building system. Emlog Pro versions 2.5.19 and earlier are vulnerable to Cross‑Site Request Forgery (CSRF) on the pas… Emlog after 2.5.19 Fix from $1,9502025-10-10 MEDIUM 5.5 CVE-2025-43296 A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26. An app may bypass Gatekeeper checks. macOS 26.0+ Fix from $1,6002025-10-09 MEDIUM 5.4 CVE-2025-11166 The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to, and including… Mitigation only Fix from $1,6002025-10-09 HIGH 8.0 CVE-2025-60956 Cross Site Request Forgery (CSRF) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attacke… Sonoma D12 Firmware Mitigation only Fix from $1,9502025-10-06 MEDIUM 5.3 CVE-2025-9892 The Restrict User Registration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is … Mitigation only Fix from $1,6002025-10-03 MEDIUM 6.1 CVE-2025-9884 The Mobile Site Redirect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to… Mitigation only Fix from $1,6002025-10-03 HIGH 8.8 CVE-2025-9213 The TextBuilder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 1.0.0 to 1.1.1. This is due to missing or incorrect nonc… Mitigation only Fix from $1,9502025-10-03 HIGH 7.1 CVE-2025-61604 WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Cross-Site Request Forgery (CSRF) vu… Wegia 3.5.0+ Fix from $1,9502025-10-02 HIGH 8.8 CVE-2025-54286 Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and start container instances with… Lxd 5.0.5 / 5.21.4+ Fix from $1,9502025-10-02 MEDIUM 6.1 CVE-2025-9946 The LockerPress – WordPress Security Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.… Mitigation only Fix from $1,6002025-09-30 HIGH 8.8 CVE-2025-7052 The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1.94. This is due to missing n… Mitigation only Fix from $1,9502025-09-30 HIGH 8.8 CVE-2025-35030 Medical Informatics Engineering Enterprise Health has a cross site request forgery vulnerability that allows an unauthenticated attacker to trick adm… Enterprise Health Mitigation only Fix from $1,9502025-09-29 MEDIUM 6.1 CVE-2025-9899 The Trust Reviews plugin for Google, Tripadvisor, Yelp, Airbnb and other platforms plugin for WordPress is vulnerable to Cross-Site Request Forgery i… Mitigation only Fix from $1,6002025-09-27 MEDIUM 6.5 CVE-2025-11051 A vulnerability has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code. The manipulation lead… Pet Grooming Management Software No fix yet Fix from $1,6002025-09-27 MEDIUM 5.4 CVE-2025-10498 The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… Ninja Forms 3.12.1+ Fix from $1,6002025-09-27 HIGH 8.8 CVE-2024-43192 IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and u… Storage Ts4500 Library Firmware Mitigation only Fix from $1,9502025-09-27 HIGH 8.2 CVE-2025-59845 Apollo Studio Embeddable Explorer & Embeddable Sandbox are website embeddable software solutions from Apollo GraphQL. Prior to Apollo Sandbox version… Mitigation only Fix from $1,9502025-09-26 HIGH 8.8 CVE-2025-11029 A weakness has been identified in givanz Vvveb up to 1.0.7.2. This vulnerability affects unknown code. Executing manipulation can lead to cross-site … Vvveb after 1.0.7.2 Fix from $1,9502025-09-26 HIGH 7.1 CVE-2025-60171 Cross-Site Request Forgery (CSRF) vulnerability in yourplugins Conditional Cart Messages for WooCommerce – YourPlugins.com yourplugins-wc-conditional… Mitigation only Fix from $1,9502025-09-26 HIGH 7.1 CVE-2025-60172 Cross-Site Request Forgery (CSRF) vulnerability in flytedesk Flytedesk Digital flytedesk-digital allows Stored XSS.This issue affects Flytedesk Digit… Mitigation only Fix from $1,9502025-09-26 HIGH 7.1 CVE-2025-60173 Cross-Site Request Forgery (CSRF) vulnerability in Ashwani kumar GST for WooCommerce gst-for-woocommerce allows Stored XSS.This issue affects GST for… Mitigation only Fix from $1,9502025-09-26