Vulnerability index

Browse CVEs

7,366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 5.4 CVE-2025-53263 Cross-Site Request Forgery (CSRF) vulnerability in PluginsCafe Address Autocomplete via Google for Gravity Forms gf-google-address-autocomplete allow… Mitigation only Fix from $1,6002025-06-27 MEDIUM 5.4 CVE-2025-53265 Cross-Site Request Forgery (CSRF) vulnerability in Virusdie Virusdie virusdie allows Cross Site Request Forgery.This issue affects Virusdie: from n/a… Mitigation only Fix from $1,6002025-06-27 HIGH 8.8 CVE-2025-48921 Cross-Site Request Forgery (CSRF) vulnerability in Drupal Open Social allows Cross Site Request Forgery.This issue affects Open Social: from 0.0.0 be… Open Social 12.3.14 / 12.4.13+ Fix from $1,9502025-06-26 HIGH 8.1 CVE-2024-4994 An issue has been discovered in GitLab CE/EE affecting all versions from 16.1.0 before 16.11.5, all versions starting from 17.0 before 17.0.3, all ve… GitLab 16.11.5 / 17.0.3+ Fix from $1,9502025-06-20 HIGH 8.8 CVE-2025-52825 Cross-Site Request Forgery (CSRF) vulnerability in Rameez Iqbal Real Estate Manager real-estate-manager allows Privilege Escalation.This issue affect… Mitigation only Fix from $1,9502025-06-20 HIGH 7.1 CVE-2025-52790 Cross-Site Request Forgery (CSRF) vulnerability in r-win WP-DownloadCounter wp-downloadcounter allows Stored XSS.This issue affects WP-DownloadCounte… Mitigation only Fix from $1,9502025-06-20 HIGH 7.1 CVE-2025-52791 Cross-Site Request Forgery (CSRF) vulnerability in devfelixmoira Knowledge Base – Knowledge Base Maker knowledge-base-maker allows Stored XSS.This is… Mitigation only Fix from $1,9502025-06-20 HIGH 7.1 CVE-2025-52792 Cross-Site Request Forgery (CSRF) vulnerability in vgstef WP User Stylesheet Switcher wp-user-stylesheet-switcher allows Stored XSS.This issue affect… Mitigation only Fix from $1,9502025-06-20 HIGH 7.1 CVE-2025-52793 Cross-Site Request Forgery (CSRF) vulnerability in Esselink.nu Esselink.nu Settings esselinknu-settings allows Reflected XSS.This issue affects Essel… Mitigation only Fix from $1,9502025-06-20 HIGH 7.1 CVE-2025-52794 Cross-Site Request Forgery (CSRF) vulnerability in Creative-Solutions Creative Contact Form sexy-contact-form allows Stored XSS.This issue affects Cr… Mitigation only Fix from $1,9502025-06-20 HIGH 7.1 CVE-2025-52795 Cross-Site Request Forgery (CSRF) vulnerability in aharonyan WP Front User Submit / Front Editor front-editor allows Cross Site Request Forgery.This … Mitigation only Fix from $1,9502025-06-20 HIGH 7.1 CVE-2025-52772 Cross-Site Request Forgery (CSRF) vulnerability in Adnan Haque (a11n) Virtual Moderator allows Cross-Site Scripting (XSS). This issue affects Virtual… No fix yet Fix from $1,9502025-06-20 HIGH 7.1 CVE-2025-52780 Cross-Site Request Forgery (CSRF) vulnerability in Mohammad Parsa Logo Manager For Samandehi samandehi-logo-manager allows Stored XSS.This issue affe… Mitigation only Fix from $1,9502025-06-20 HIGH 7.1 CVE-2025-52781 Cross-Site Request Forgery (CSRF) vulnerability in Beee TinyNav tinynav allows Stored XSS.This issue affects TinyNav: from n/a through <= 1.4. Mitigation only Fix from $1,9502025-06-20 HIGH 7.1 CVE-2025-52783 Cross-Site Request Forgery (CSRF) vulnerability in themelocation Change Cart button Colors WooCommerce wc-style allows Stored XSS.This issue affects … Mitigation only Fix from $1,9502025-06-20 HIGH 7.1 CVE-2025-52784 Cross-Site Request Forgery (CSRF) vulnerability in hideoguchi Bluff Post bluff-post allows Stored XSS.This issue affects Bluff Post: from n/a through… Mitigation only Fix from $1,9502025-06-20 HIGH 7.1 CVE-2025-52789 Cross-Site Request Forgery (CSRF) vulnerability in George Lewe Lewe ChordPress chordpress allows Stored XSS.This issue affects Lewe ChordPress: from … Mitigation only Fix from $1,9502025-06-20 MEDIUM 6.5 CVE-2025-50044 Cross-Site Request Forgery (CSRF) vulnerability in Rameez Iqbal Real Estate Manager real-estate-manager allows Cross Site Request Forgery.This issue … Mitigation only Fix from $1,6002025-06-20 MEDIUM 6.5 CVE-2025-50036 Cross-Site Request Forgery (CSRF) vulnerability in Yamna Khawaja Mailing Group Listserv wp-mailing-group allows Cross Site Request Forgery.This issue… Mitigation only Fix from $1,6002025-06-20 HIGH 8.8 CVE-2025-6105 A vulnerability has been found in jflyfox jfinal_cms 5.0.1 and classified as problematic. This vulnerability affects unknown code of the file HOME.ja… Jfinal Cms No fix yet Fix from $1,9502025-06-16 MEDIUM 6.1 CVE-2025-6055 The Zen Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.3. This is due to miss… Mitigation only Fix from $1,6002025-06-14 MEDIUM 6.1 CVE-2025-6063 The XiSearch bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6. This is due to missing o… Mitigation only Fix from $1,6002025-06-14 MEDIUM 6.1 CVE-2025-6064 The WP URL Shortener plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missi… Mitigation only Fix from $1,6002025-06-14 MEDIUM 6.1 CVE-2025-5926 The Link Shield plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5.4. This is due to missing … Mitigation only Fix from $1,6002025-06-13 HIGH 8.3 CVE-2025-6001 A Cross-Site Request Forgery (CSRF) vulnerability exists in the product image upload function of VirtueMart that bypasses the CSRF protection token. … Mitigation only Fix from $1,9502025-06-11 HIGH 8.8 CVE-2025-41661 An unauthenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of Cross-Site Request Forgery … Mitigation only Fix from $1,9502025-06-11 HIGH 7.1 CVE-2025-49511 Cross-Site Request Forgery (CSRF) vulnerability in uxper Civi Framework civi-framework allows Cross Site Request Forgery.This issue affects Civi Fram… Mitigation only Fix from $1,9502025-06-10 HIGH 7.1 CVE-2025-5900 A vulnerability, which was classified as problematic, was found in Tenda AC9 15.03.02.13. This affects an unknown part. The manipulation leads to cro… Ac9 Firmware No fix yet Fix from $1,9502025-06-09 MEDIUM 6.5 CVE-2025-5888 A vulnerability was found in jsnjfz WebStack-Guns 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionalit… Webstack Guns No fix yet Fix from $1,6002025-06-09 HIGH 7.1 CVE-2025-49453 Cross-Site Request Forgery (CSRF) vulnerability in Jatinder Pal Singh BP Profile as Homepage bp-profile-as-homepage allows Stored XSS.This issue affe… Mitigation only Fix from $1,9502025-06-06