Vulnerability index

Browse CVEs

7,366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 7.1 CVE-2025-49425 Cross-Site Request Forgery (CSRF) vulnerability in Adrian Hanft Konami Easter Egg konami-easter-egg allows Stored XSS.This issue affects Konami Easte… Mitigation only Fix from $1,9502025-06-06 HIGH 8.8 CVE-2025-49291 Cross-Site Request Forgery (CSRF) vulnerability in codepeople Calculated Fields Form calculated-fields-form allows Cross Site Request Forgery.This is… Calculated Fields Form 5.3.59+ Fix from $1,9502025-06-06 HIGH 7.4 CVE-2025-49237 Cross-Site Request Forgery (CSRF) vulnerability in POEditor POEditor poeditor allows Path Traversal.This issue affects POEditor: from n/a through <= … Mitigation only Fix from $1,9502025-06-06 MEDIUM 5.4 CVE-2025-49239 Cross-Site Request Forgery (CSRF) vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocommerce-delivery-notes allows Cr… Mitigation only Fix from $1,6002025-06-06 MEDIUM 5.4 CVE-2025-30986 Cross-Site Request Forgery (CSRF) vulnerability in _CreativeMedia_ Elite Video Player elite-video-player allows Cross Site Request Forgery.This issue… Mitigation only Fix from $1,6002025-06-06 HIGH 7.1 CVE-2025-30995 Cross-Site Request Forgery (CSRF) vulnerability in OTWthemes Widgetize Pages Light widgetize-pages-light allows Stored XSS.This issue affects Widgeti… Mitigation only Fix from $1,9502025-06-06 MEDIUM 5.4 CVE-2025-30968 Cross-Site Request Forgery (CSRF) vulnerability in jokerbr313 Advanced Post List advanced-post-list allows Cross Site Request Forgery.This issue affe… Mitigation only Fix from $1,6002025-06-06 MEDIUM 6.3 CVE-2025-30981 Cross-Site Request Forgery (CSRF) vulnerability in tggfref WP-Recall allows Privilege Escalation. This issue affects WP-Recall: from n/a through 16.2… Mitigation only Fix from $1,6002025-06-06 MEDIUM 5.4 CVE-2025-30632 Cross-Site Request Forgery (CSRF) vulnerability in pozzad Global Translator global-translator allows Cross Site Request Forgery.This issue affects Gl… Mitigation only Fix from $1,6002025-06-06 HIGH 8.2 CVE-2025-28986 Cross-Site Request Forgery (CSRF) vulnerability in Webaholicson Epicwin Plugin epicwin-subscribers allows SQL Injection.This issue affects Epicwin Pl… Mitigation only Fix from $1,9502025-06-06 HIGH 7.4 CVE-2025-28954 Cross-Site Request Forgery (CSRF) vulnerability in wphobby Backwp backwp allows Path Traversal.This issue affects Backwp: from n/a through <= 2.0.2. Mitigation only Fix from $1,9502025-06-06 HIGH 7.1 CVE-2025-28958 Cross-Site Request Forgery (CSRF) vulnerability in Vadim Bogaiskov Bg Orthodox Calendar bg-orthodox-calendar allows Stored XSS.This issue affects Bg … Mitigation only Fix from $1,9502025-06-06 HIGH 7.1 CVE-2025-28964 Cross-Site Request Forgery (CSRF) vulnerability in mangup Personal Favicon personal-favicon allows Stored XSS.This issue affects Personal Favicon: fr… Mitigation only Fix from $1,9502025-06-06 HIGH 7.1 CVE-2025-28966 Cross-Site Request Forgery (CSRF) vulnerability in dilemma123 Recent Posts Slider Responsive recent-posts-slider-responsive allows Stored XSS.This is… Mitigation only Fix from $1,9502025-06-06 HIGH 7.1 CVE-2025-28974 Cross-Site Request Forgery (CSRF) vulnerability in mail250 Free WP Mail SMTP free-wp-mail-smtp allows Stored XSS.This issue affects Free WP Mail SMTP… Mitigation only Fix from $1,9502025-06-06 HIGH 7.1 CVE-2025-28981 Cross-Site Request Forgery (CSRF) vulnerability in Soli WP Mail Options wp-mail-options allows Stored XSS.This issue affects WP Mail Options: from n/… Mitigation only Fix from $1,9502025-06-06 HIGH 7.1 CVE-2025-28948 Cross-Site Request Forgery (CSRF) vulnerability in codedraft Mediabay - WordPress Media Library Folders allows Reflected XSS. This issue affects Medi… Mitigation only Fix from $1,9502025-06-06 HIGH 7.1 CVE-2025-28950 Cross-Site Request Forgery (CSRF) vulnerability in David Shabtai Post Author post-author allows Stored XSS.This issue affects Post Author: from n/a t… Mitigation only Fix from $1,9502025-06-06 MEDIUM 5.4 CVE-2025-24772 Cross-Site Request Forgery (CSRF) vulnerability in cmsMinds Pay with Contact Form 7 pay-with-contact-form-7 allows Cross Site Request Forgery.This is… Mitigation only Fix from $1,6002025-06-06 HIGH 8.8 CVE-2025-5732 A vulnerability, which was classified as problematic, was found in code-projects Traffic Offense Reporting System 1.0. This affects an unknown part. … Traffic Offense Reporting System No fix yet Fix from $1,9502025-06-06 MEDIUM 5.4 CVE-2025-5019 The Hive Support | AI-Powered Help Desk, Live Chat & AI Chat Bot Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forger… Mitigation only Fix from $1,6002025-06-06 MEDIUM 6.1 CVE-2025-4966 The WP Online Users Stats plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due t… Wp Online Users Stats after 1.0.0 Fix from $1,6002025-06-06 MEDIUM 5.4 CVE-2025-2935 The Anti-Spam: Spam Protection | Block Spam Users, Comments, Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u… Mitigation only Fix from $1,6002025-06-06 HIGH 8.8 CVE-2025-5521 A vulnerability was found in WuKongOpenSource WukongCRM 9.0. It has been declared as problematic. Affected by this vulnerability is an unknown functi… Wukong Crm No fix yet Fix from $1,9502025-06-03 MEDIUM 5.7 CVE-2025-48885 application-urlshortener create shortened URLs for XWiki pages. Versions prior to 1.2.4 are vulnerable to users with view access being able to create… Patch available Fix from $1,6002025-05-30 MEDIUM 6.5 CVE-2025-5142 The Simple Page Access Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.31. Thi… Simple Page Access Restriction 1.0.32+ Fix from $1,6002025-05-30 MEDIUM 5.4 CVE-2025-48483 FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to Cross-Site Scripting (XSS) a… Freescout 1.8.180+ Fix from $1,6002025-05-30 HIGH 8.8 CVE-2024-12224 Improper Validation of Unsafe Equivalence in punycode by the idna crate from Servo rust-url allows an attacker to create a punycode hostname that one… Idna 1.0.0+ Fix from $1,9502025-05-30 HIGH 8.8 CVE-2025-26211 Gibbon before 29.0.00 allows CSRF. Gibbon 29.0.00+ Fix from $1,9502025-05-27 HIGH 8.8 CVE-2025-5132 A vulnerability was found in Tmall Demo up to 20250505. It has been rated as problematic. This issue affects some unknown processing of the file tmal… Tmall Demo after 2025-05-05 Fix from $1,9502025-05-24