Vulnerability index

Browse CVEs

7,366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 7.1 CVE-2025-48304 Cross-Site Request Forgery (CSRF) vulnerability in Gary Illyes Google XML News Sitemap plugin gn-xml-sitemap allows Stored XSS.This issue affects Goo… Mitigation only Fix from $1,9502025-08-28 HIGH 7.1 CVE-2025-48306 Cross-Site Request Forgery (CSRF) vulnerability in developers savyour Savyour Affiliate Partner savyour-affiliate-partner allows Stored XSS.This issu… Mitigation only Fix from $1,9502025-08-28 HIGH 8.8 CVE-2025-7812 The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i… Mitigation only Fix from $1,9502025-08-28 HIGH 7.1 CVE-2025-58217 Cross-Site Request Forgery (CSRF) vulnerability in GeroNikolov Instant Breaking News instant-breaking-news allows Stored XSS.This issue affects Insta… Mitigation only Fix from $1,9502025-08-27 MEDIUM 6.5 CVE-2025-54598 The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows CSRF to delete all notifications via the /noti… Bevy after 2025-06-24 Fix from $1,6002025-08-27 HIGH 8.1 CVE-2025-8592 The Inspiro theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.2. This is due to missing or in… Mitigation only Fix from $1,9502025-08-21 HIGH 8.8 CVE-2025-50902 Cross Site Request Forgery (CSRF) vulnerability in old-peanut Open-Shop (aka old-peanut/wechat_applet__open_source) thru 1.0.0 allows attackers to ga… Open Shop after 1.0.0 Fix from $1,9502025-08-20 MEDIUM 6.8 CVE-2025-43748 Insufficient CSRF protection for omni-administrator users in Liferay Portal 7.0.0 through 7.4.3.119, and Liferay DXP 2024.Q1.1 through 2024.Q1.6, 202… Digital Experience Platform 7.4.3.120 / 2024.Q1.7+ Fix from $1,6002025-08-20 MEDIUM 5.4 CVE-2025-8102 The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.5.0. This is due … Mitigation only Fix from $1,6002025-08-20 HIGH 7.5 CVE-2025-54052 Cross-Site Request Forgery (CSRF) vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna-wpl allows PHP Local File Inclus… Mitigation only Fix from $1,9502025-08-20 MEDIUM 5.3 CVE-2025-49896 Cross-Site Request Forgery (CSRF) vulnerability in wptasker WP Discord Post Plus – Supports Unlimited Channels allows Cross Site Request Forgery. Th… Mitigation only Fix from $1,6002025-08-20 HIGH 8.8 CVE-2025-49399 Cross-Site Request Forgery (CSRF) vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows Cross Site Request Forgery.This issue aff… Mitigation only Fix from $1,9502025-08-20 CRITICAL 9.6 CVE-2025-49381 Cross-Site Request Forgery (CSRF) vulnerability in ads.txt Guru ads.txt Guru Connect adstxt-guru-connect allows Cross Site Request Forgery.This issue… Mitigation only Fix from $2,3002025-08-20 HIGH 8.8 CVE-2025-49382 Cross-Site Request Forgery (CSRF) vulnerability in DexignZone JobZilla - Job Board WordPress Theme jobzilla allows Privilege Escalation.This issue af… Mitigation only Fix from $1,9502025-08-20 MEDIUM 6.5 CVE-2025-43745 A CSRF vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.7, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 … Digital Experience Platform 2024.q1.20 / 2025.Q1.16+ Fix from $1,6002025-08-19 MEDIUM 6.1 CVE-2025-7684 The Last.fm Recent Album Artwork plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2. This i… Mitigation only Fix from $1,6002025-08-16 MEDIUM 6.1 CVE-2025-7686 The weichuncai(WP伪春菜) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to m… Mitigation only Fix from $1,6002025-08-16 MEDIUM 6.1 CVE-2025-7683 The LatestCheckins plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1. This is due to missing o… Mitigation only Fix from $1,6002025-08-16 MEDIUM 6.1 CVE-2025-7668 The Linux Promotional Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due … Mitigation only Fix from $1,6002025-08-16 MEDIUM 6.5 CVE-2025-49895 Cross-Site Request Forgery (CSRF) vulnerability in iThemes ServerBuddy by PluginBuddy.Com allows Object Injection.This issue affects ServerBuddy by P… Mitigation only Fix from $1,6002025-08-16 MEDIUM 6.1 CVE-2025-7688 The Add User Meta plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missin… Mitigation only Fix from $1,6002025-08-15 MEDIUM 6.5 CVE-2025-8992 A vulnerability has been found in mtons mblog up to 3.5.0. Affected by this issue is some unknown functionality. The manipulation leads to cross-site… Mblog after 3.5.0 Fix from $1,6002025-08-15 HIGH 8.8 CVE-2025-53587 Cross-Site Request Forgery (CSRF) vulnerability in ApusTheme Findgo findgo allows Cross Site Request Forgery.This issue affects Findgo: from n/a thro… Mitigation only Fix from $1,9502025-08-14 MEDIUM 6.5 CVE-2025-53249 Cross-Site Request Forgery (CSRF) vulnerability in hakeemnala Build App Online build-app-online allows Cross Site Request Forgery.This issue affects … Mitigation only Fix from $1,6002025-08-14 HIGH 8.2 CVE-2025-52797 Cross-Site Request Forgery (CSRF) vulnerability in josepsitjar StoryMap wp-storymap allows SQL Injection.This issue affects StoryMap: from n/a throug… Mitigation only Fix from $1,9502025-08-14 MEDIUM 5.4 CVE-2025-53219 Cross-Site Request Forgery (CSRF) vulnerability in pl4g4 WP-Database-Optimizer-Tools wp-database-optimizer-tools allows Cross Site Request Forgery.Th… Mitigation only Fix from $1,6002025-08-14 HIGH 7.1 CVE-2025-52765 Cross-Site Request Forgery (CSRF) vulnerability in lisensee NetInsight Analytics Implementation Plugin netinsight-analytics-implementation-plugin all… Mitigation only Fix from $1,9502025-08-14 HIGH 8.8 CVE-2024-53946 The KuWFi 4G LTE AC900 router 1.0.13 is vulnerable to Cross-Site Request Forgery (CSRF) on its web management interface. This vulnerability allows an… Mitigation only Fix from $1,9502025-08-14 MEDIUM 5.4 CVE-2025-54682 Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Connector for Gravity Forms and Google Sheets wp-gravity-forms-spreadsheets allows Cross… Mitigation only Fix from $1,6002025-08-14 MEDIUM 5.4 CVE-2025-54674 Cross-Site Request Forgery (CSRF) vulnerability in mklacroix Product Configurator for WooCommerce product-configurator-for-woocommerce allows Cross S… Mitigation only Fix from $1,6002025-08-14