Vulnerability index

Browse CVEs

7,366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 5.9 CVE-2025-48740 A Cross-Site Request Forgery (CSRF) vulnerability in StrangeBee TheHive 5.2.0 before 5.2.16, 5.3.0 before 5.3.11, 5.4.0 before 5.4.10, and 5.5.0 befo… Mitigation only Fix from $1,6002025-05-23 HIGH 8.2 CVE-2025-46458 Cross-Site Request Forgery (CSRF) vulnerability in x000x occupancyplan occupancyplan allows SQL Injection.This issue affects occupancyplan: from n/a … Mitigation only Fix from $1,9502025-05-23 CRITICAL 9.8 CVE-2025-48340 Cross-Site Request Forgery (CSRF) vulnerability in Danny Vink User Profile Meta Manager user-profile-meta allows Privilege Escalation.This issue affe… Mitigation only Fix from $2,3002025-05-19 HIGH 7.1 CVE-2025-43840 Cross-Site Request Forgery (CSRF) vulnerability in ref CheckBot checkbot allows Stored XSS.This issue affects CheckBot: from n/a through <= 1.05. Mitigation only Fix from $1,9502025-05-19 MEDIUM 5.4 CVE-2025-47583 Cross-Site Request Forgery (CSRF) vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Cross Site Request Forgery.This is… Mitigation only Fix from $1,6002025-05-19 HIGH 7.1 CVE-2025-39374 Cross-Site Request Forgery (CSRF) vulnerability in aseem1234 Best Posts Summary best-posts-summary allows Stored XSS.This issue affects Best Posts Su… Mitigation only Fix from $1,9502025-05-19 MEDIUM 5.4 CVE-2025-48342 Cross-Site Request Forgery (CSRF) vulnerability in RedefiningTheWeb Dynamic Pricing & Discounts Lite for WooCommerce woo-dynamic-pricing-discounts-li… Mitigation only Fix from $1,6002025-05-19 MEDIUM 5.4 CVE-2025-48344 Cross-Site Request Forgery (CSRF) vulnerability in ed4becky Rootspersona rootspersona allows Cross Site Request Forgery.This issue affects Rootsperso… Mitigation only Fix from $1,6002025-05-19 MEDIUM 5.4 CVE-2025-48284 Cross-Site Request Forgery (CSRF) vulnerability in shohei.tanaka Japanized For WooCommerce woocommerce-for-japan allows Cross Site Request Forgery.Th… Mitigation only Fix from $1,6002025-05-19 HIGH 8.8 CVE-2025-48255 Cross-Site Request Forgery (CSRF) vulnerability in videowhisper Broadcast Live Video videowhisper-live-streaming-integration allows Cross Site Reques… Videowhisper Live Streaming Integration after 6.2.4 Fix from $1,9502025-05-19 HIGH 7.1 CVE-2025-48238 Cross-Site Request Forgery (CSRF) vulnerability in awcode AWcode Toolkit awcode-toolkit allows Stored XSS.This issue affects AWcode Toolkit: from n/a… Mitigation only Fix from $1,9502025-05-19 HIGH 7.1 CVE-2025-48233 Cross-Site Request Forgery (CSRF) vulnerability in affmngr Affiliates Manager Google reCAPTCHA Integration affiliates-manager-google-recaptcha-integr… Mitigation only Fix from $1,9502025-05-19 HIGH 8.8 CVE-2025-4887 A vulnerability, which was classified as problematic, has been found in SourceCodester Online Student Clearance System 1.0. Affected by this issue is… Online Student Clearance System No fix yet Fix from $1,9502025-05-18 MEDIUM 6.1 CVE-2025-4194 The AlT Monitoring plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to missi… Mitigation only Fix from $1,6002025-05-17 MEDIUM 6.1 CVE-2025-4189 The Audio Comments Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. This is due t… Mitigation only Fix from $1,6002025-05-17 MEDIUM 6.5 CVE-2022-4363 The Wholesale Market WordPress plugin before 2.2.2, Wholesale Market for WooCommerce WordPress plugin before 2.0.1 have a flawed CSRF check when upda… Wholesale Market 2.0.1 / 2.2.2+ Fix from $1,6002025-05-16 MEDIUM 6.1 CVE-2025-48146 Cross-Site Request Forgery (CSRF) vulnerability in Michael Lups SEO Flow by LupsOnline lupsonline-link-netwerk allows Stored XSS.This issue affects S… Seo Flow after 2.2.0 Fix from $1,6002025-05-16 MEDIUM 6.1 CVE-2025-48144 Cross-Site Request Forgery (CSRF) vulnerability in sidngr Import Export For WooCommerce import-export-for-woocommerce allows Stored XSS.This issue af… Import Export For Woocommerce after 1.6.2 Fix from $1,6002025-05-16 HIGH 7.1 CVE-2025-48114 Cross-Site Request Forgery (CSRF) vulnerability in Shayan Farhang Pazhooh ShayanWeb Admin FontChanger shayanweb-admin-fontchanger allows Stored XSS.T… Mitigation only Fix from $1,9502025-05-16 HIGH 8.8 CVE-2025-32310 Cross-Site Request Forgery (CSRF) vulnerability in ThemeMove QuickCal - Appointment Booking Calendar for WordPress quickcal allows Privilege Escalati… Mitigation only Fix from $1,9502025-05-16 HIGH 7.1 CVE-2025-31922 Cross-Site Request Forgery (CSRF) vulnerability in QuanticaLabs CSS3 Accordions for WordPress css3_accordions allows Stored XSS.This issue affects CS… Mitigation only Fix from $1,9502025-05-16 MEDIUM 6.5 CVE-2025-32245 Cross-Site Request Forgery (CSRF) vulnerability in Chaser324 Featured Posts Scroll featured-posts-scroll allows Stored XSS.This issue affects Feature… Mitigation only Fix from $1,6002025-05-16 MEDIUM 5.4 CVE-2025-31915 Cross-Site Request Forgery (CSRF) vulnerability in kamleshyadav Pixel WordPress Form BuilderPlugin & Autoresponder pixel-formbuilder allows Cross Sit… Mitigation only Fix from $1,6002025-05-16 MEDIUM 5.4 CVE-2025-2247 The WP-PManager WordPress plugin through 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logg… Wp Pmanager after 1.2 Fix from $1,6002025-05-15 MEDIUM 6.1 CVE-2025-1288 The WOOEXIM WordPress plugin through 5.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could all… Wooexim after 5.0.0 Fix from $1,6002025-05-15 MEDIUM 5.4 CVE-2024-9709 The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to… Ekc Tournament Manager 2.2.2+ Fix from $1,6002025-05-15 MEDIUM 5.4 CVE-2024-9711 The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to… Ekc Tournament Manager 2.2.2+ Fix from $1,6002025-05-15 MEDIUM 6.5 CVE-2024-9450 The Free Booking Plugin for Hotels, Restaurants and Car Rentals WordPress plugin before 1.3.15 does not have CSRF check in place when updating its s… Easync 1.3.15+ Fix from $1,6002025-05-15 MEDIUM 6.5 CVE-2024-8286 The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not have CSRF checks in some bulk actions, which could allow attackers to make l… Gdpr Cookie Consent 2.6.1+ Fix from $1,6002025-05-15 MEDIUM 6.1 CVE-2024-8032 The Smooth Gallery Replacement WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping,… Smooth Gallery Replacement after 1.0 Fix from $1,6002025-05-15