Vulnerability index

Browse CVEs

7,366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.5 CVE-2025-57902 Cross-Site Request Forgery (CSRF) vulnerability in Md Taufiqur Rahman RIS Version Switcher – Downgrade or Upgrade WP Versions Easily ris-version-swit… Mitigation only Fix from $1,6002025-09-22 MEDIUM 5.4 CVE-2025-53451 Cross-Site Request Forgery (CSRF) vulnerability in mihdan Mihdan: No External Links mihdan-no-external-links allows Cross Site Request Forgery.This i… Mitigation only Fix from $1,6002025-09-22 MEDIUM 5.3 CVE-2025-10759 A vulnerability was detected in Webkul QloApps up to 1.7.0. This affects an unknown function of the component CSRF Token Handler. Performing manipula… Qloapps after 1.7.0 Fix from $1,6002025-09-21 MEDIUM 6.1 CVE-2025-9882 The osTicket WP Bridge plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.2. This is due to m… Mitigation only Fix from $1,6002025-09-20 MEDIUM 6.1 CVE-2025-9883 The Browser Sniff plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3. This is due to missing … Mitigation only Fix from $1,6002025-09-20 HIGH 7.8 CVE-2025-50255 Cross Site Request Forgery (CSRF) vulnerability in Smartvista BackOffice SmartVista Suite 2.2.22 via crafted GET request. Mitigation only Fix from $1,9502025-09-18 MEDIUM 6.3 CVE-2025-54390 A Cross-Site Request Forgery (CSRF) vulnerability exists in the ResetPasswordRequest operation of Zimbra Collaboration (ZCS) when the zimbraFeatureRe… Mitigation only Fix from $1,6002025-09-17 MEDIUM 5.4 CVE-2025-10188 The The Hack Repair Guy's Plugin Archiver plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.… Mitigation only Fix from $1,6002025-09-17 HIGH 7.3 CVE-2025-56710 A Cross-Site Request Forgery (CSRF) vulnerability was identified in the Profile Page of the PHPGurukul Student-Result-Management-System-Using-PHP-V2.… Student Result Management System No fix yet Fix from $1,9502025-09-15 MEDIUM 6.1 CVE-2025-9880 The Side Slide Responsive Menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is du… Mitigation only Fix from $1,6002025-09-12 MEDIUM 6.1 CVE-2025-9881 The Ultimate Blogroll plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.2. This is due to mi… Mitigation only Fix from $1,6002025-09-12 MEDIUM 5.3 CVE-2025-9617 The Publish approval plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missi… Mitigation only Fix from $1,6002025-09-11 MEDIUM 6.1 CVE-2025-9620 The Seo Monster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.3.3. This is due to missing … Mitigation only Fix from $1,6002025-09-11 MEDIUM 6.1 CVE-2025-58430 listmonk is a standalone, self-hosted, newsletter and mailing list manager. In versions up to and including 1.1.0, every http request in addition to … Listmonk after 1.1.0 Fix from $1,6002025-09-09 HIGH 8.6 CVE-2025-54256 Dreamweaver Desktop versions 21.5 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in arbitrary code e… Dreamweaver 21.6+ Fix from $1,9502025-09-09 HIGH 7.1 CVE-2025-58991 Cross-Site Request Forgery (CSRF) vulnerability in Cristiano Zanca WooCommerce Booking Bundle Hours allows Stored XSS. This issue affects WooCommerce… Mitigation only Fix from $1,9502025-09-09 CRITICAL 9.6 CVE-2025-58997 Cross-Site Request Forgery (CSRF) vulnerability in Frenify Mow mow allows Code Injection.This issue affects Mow: from n/a through <= 4.10. Mitigation only Fix from $2,3002025-09-09 HIGH 8.8 CVE-2025-55147 CSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neuro… Connect Secure 22.7 / 22.8+ Fix from $1,9502025-09-09 MEDIUM 5.4 CVE-2025-8711 CSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neuro… Connect Secure 22.7 / 22.8+ Fix from $1,6002025-09-09 HIGH 7.1 CVE-2025-48104 Cross-Site Request Forgery (CSRF) vulnerability in ericzane Floating Window Music Player floating-window-music-player allows Stored XSS.This issue af… Mitigation only Fix from $1,9502025-09-05 MEDIUM 6.5 CVE-2025-58878 Cross-Site Request Forgery (CSRF) vulnerability in usamafarooq Woocommerce Gifts Product woo-gift-product allows Cross Site Request Forgery.This issu… Mitigation only Fix from $1,6002025-09-05 MEDIUM 6.5 CVE-2025-58869 Cross-Site Request Forgery (CSRF) vulnerability in Simasicher SimaCookie simasicher-dsgvo-cookie allows Stored XSS.This issue affects SimaCookie: fro… Mitigation only Fix from $1,6002025-09-05 HIGH 7.1 CVE-2025-58859 Cross-Site Request Forgery (CSRF) vulnerability in David Merinas Add to Feedly add-to-feedly allows Stored XSS.This issue affects Add to Feedly: from… Mitigation only Fix from $1,9502025-09-05 HIGH 7.1 CVE-2025-58860 Cross-Site Request Forgery (CSRF) vulnerability in KaizenCoders Enable Latex enable-latex allows Stored XSS.This issue affects Enable Latex: from n/a… Mitigation only Fix from $1,9502025-09-05 HIGH 7.1 CVE-2025-58861 Cross-Site Request Forgery (CSRF) vulnerability in WP Corner Quick Event Calendar quick-event-calendar allows Stored XSS.This issue affects Quick Eve… Mitigation only Fix from $1,9502025-09-05 MEDIUM 6.5 CVE-2025-58856 Cross-Site Request Forgery (CSRF) vulnerability in ablancodev Woocommerce Notify Updated Product woocommerce-notify-updated-product allows Stored XSS… Mitigation only Fix from $1,6002025-09-05 HIGH 7.1 CVE-2025-58849 Cross-Site Request Forgery (CSRF) vulnerability in Deepak S Hide Real Download Path hide-real-download-path allows Stored XSS.This issue affects Hide… Mitigation only Fix from $1,9502025-09-05 HIGH 7.1 CVE-2025-58852 Cross-Site Request Forgery (CSRF) vulnerability in Mark O'Donnell MSTW League Manager mstw-league-manager allows Stored XSS.This issue affects MSTW L… Mitigation only Fix from $1,9502025-09-05 HIGH 7.1 CVE-2025-58853 Cross-Site Request Forgery (CSRF) vulnerability in OTWthemes Popping Sidebars and Widgets Light popping-sidebars-and-widgets-light allows Reflected X… Mitigation only Fix from $1,9502025-09-05 HIGH 7.1 CVE-2025-58854 Cross-Site Request Forgery (CSRF) vulnerability in Samer Bechara Ultimate AJAX Login ultimate-ajax-login allows Reflected XSS.This issue affects Ulti… Mitigation only Fix from $1,9502025-09-05