Vulnerability index

Browse CVEs

7,366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.1 CVE-2024-8085 The PeoplePond WordPress plugin through 1.1.9 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could a… Peoplepond after 1.1.9 Fix from $1,6002025-05-15 MEDIUM 6.1 CVE-2024-8090 The JavaScript Logic WordPress plugin through 0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which cou… Javascript Logic No fix yet Fix from $1,6002025-05-15 MEDIUM 6.5 CVE-2024-8094 The Ntz Antispam WordPress plugin through 2.0e does not have CSRF check in place when updating its settings, which could allow attackers to make a lo… Ntz Atispam after 2.0e Fix from $1,6002025-05-15 HIGH 8.1 CVE-2024-6719 The Offload Videos WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow low privilege users… Offload Videos 1.0.1+ Fix from $1,9502025-05-15 MEDIUM 6.1 CVE-2024-11719 The tarteaucitron-wp WordPress plugin before 0.3.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which co… Tarteaucitron Wp 0.3.0+ Fix from $1,6002025-05-15 MEDIUM 6.1 CVE-2024-12282 The WordPress连接微博 WordPress plugin through 2.5.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which … Wp Connect after 2.5.6 Fix from $1,6002025-05-15 MEDIUM 6.5 CVE-2024-12301 The JSP Store Locator WordPress plugin through 1.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perf… Jsp Store Locator after 1.0 Fix from $1,6002025-05-15 HIGH 7.1 CVE-2023-7174 The aBitGone CommentSafe WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, whi… Abitgone Commentsafe after 1.0.0 Fix from $1,9502025-05-15 HIGH 7.1 CVE-2023-7197 The Marketing Twitter Bot WordPress plugin through 1.11 does not have CSRF check in some places, and is missing sanitisation as well as escaping, whi… Marketing Twitter Bot after 1.11 Fix from $1,9502025-05-15 MEDIUM 5.5 CVE-2023-7229 The illi Link Party! WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a… Illi Link Party\! after 1.0 Fix from $1,6002025-05-15 HIGH 7.3 CVE-2023-5934 The Travelpayouts: All Travel Brands in One Place WordPress plugin before 1.1.13 does not have CSRF check in place when importing settings from the v… Travelpayouts 1.1.13+ Fix from $1,9502025-05-15 MEDIUM 5.4 CVE-2023-2334 The edd-google-sheet-connector-pro WordPress plugin before 1.4, Easy Digital Downloads Google Sheet Connector WordPress plugin before 1.6.6 does not … Easy Digital Downloads Google Sheet Connector 1.4 / 1.6.6+ Fix from $1,6002025-05-15 HIGH 7.1 CVE-2025-32922 Cross-Site Request Forgery (CSRF) vulnerability in Saleswonder Team: Tobias WP2LEADS wp2leads allows Stored XSS.This issue affects WP2LEADS: from n/a… Mitigation only Fix from $1,9502025-05-15 MEDIUM 5.4 CVE-2025-44185 SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/change_pass.php via the password par… Best Employee Management System No fix yet Fix from $1,6002025-05-15 HIGH 8.8 CVE-2025-47708 Cross-Site Request Forgery (CSRF) vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Cross Site Request Forgery.This issue affects Enterp… Miniorange 2fa 5.2.0 / 8.x-4.7+ Fix from $1,9502025-05-14 MEDIUM 5.4 CVE-2025-44186 SourceCodester Best Employee Management System 1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/Operation/User.php page. Best Employee Management System No fix yet Fix from $1,6002025-05-14 HIGH 8.8 CVE-2025-47701 Cross-Site Request Forgery (CSRF) vulnerability in Drupal Restrict route by IP allows Cross Site Request Forgery.This issue affects Restrict route by… Restrict Route By Ip 1.3.0+ Fix from $1,9502025-05-14 MEDIUM 6.1 CVE-2025-46721 nosurf is cross-site request forgery (CSRF) protection middleware for Go. A vulnerability in versions prior to 1.2.0 allows an attacker who controls … Nosurf 1.2.0+ Fix from $1,6002025-05-13 MEDIUM 6.1 CVE-2025-47204 An issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Multiselect) 1.1.2. A PHP script in the source code echoes arbitrary POST… Bootstrap Multiselect Patch available Fix from $1,6002025-05-13 MEDIUM 6.5 CVE-2025-31205 The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2… Safari 2.5 / 11.5+ Fix from $1,6002025-05-12 HIGH 8.0 CVE-2025-24223 The issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, v… Safari 2.5 / 11.5+ Fix from $1,9502025-05-12 MEDIUM 6.3 CVE-2025-46743 An authenticated user's token could be used by another source after the user had logged out prior to the token expiring. Mitigation only Fix from $1,6002025-05-12 HIGH 8.8 CVE-2025-46610 ARTEC EMA Mail 6.92 allows CSRF. Enterprise Mail Archive Mitigation only Fix from $1,9502025-05-12 MEDIUM 6.9 CVE-2025-4375 Cross-Site Request Forgery (CSRF) vulnerability in Sparx Systems Pro Cloud Server allows Cross-Site Request Forgery to perform Session Hijacking. Cro… Mitigation only Fix from $1,6002025-05-09 MEDIUM 5.4 CVE-2025-47684 Cross-Site Request Forgery (CSRF) vulnerability in Smaily Smaily for WP smaily-for-wp allows Cross Site Request Forgery.This issue affects Smaily for… Mitigation only Fix from $1,6002025-05-07 HIGH 7.1 CVE-2025-47685 Cross-Site Request Forgery (CSRF) vulnerability in Moloni Contribuinte Checkout contribuinte-checkout allows Stored XSS.This issue affects Contribuin… Mitigation only Fix from $1,9502025-05-07 MEDIUM 5.4 CVE-2025-47667 Cross-Site Request Forgery (CSRF) vulnerability in qusupport LiveAgent liveagent allows Cross Site Request Forgery.This issue affects LiveAgent: from… Mitigation only Fix from $1,6002025-05-07 MEDIUM 5.4 CVE-2025-47661 Cross-Site Request Forgery (CSRF) vulnerability in codemstory 워드프레스 결제 심플페이 pgall-for-woocommerce allows Cross Site Request Forgery.This i… Mitigation only Fix from $1,6002025-05-07 HIGH 7.1 CVE-2025-47639 Cross-Site Request Forgery (CSRF) vulnerability in Supertext Supertext Translation and Proofreading polylang-supertext allows Stored XSS.This issue a… Mitigation only Fix from $1,9502025-05-07 HIGH 7.1 CVE-2025-47648 Cross-Site Request Forgery (CSRF) vulnerability in axima Pays – WooCommerce Payment Gateway axima-payment-gateway allows Stored XSS.This issue affect… Mitigation only Fix from $1,9502025-05-07