Vulnerability index

Browse CVEs

7,366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 7.1 CVE-2025-47655 Cross-Site Request Forgery (CSRF) vulnerability in themarketer2023 theMarketer themarketer allows Stored XSS.This issue affects theMarketer: from n/a… Mitigation only Fix from $1,9502025-05-07 HIGH 8.8 CVE-2025-47633 Cross-Site Request Forgery (CSRF) vulnerability in Awin Awin – Advertiser Tracking for WooCommerce awin-advertiser-tracking allows Cross Site Request… Awin Advertiser Tracking For Woocommerce after 2.0.0 Fix from $1,9502025-05-07 HIGH 7.1 CVE-2025-47620 Cross-Site Request Forgery (CSRF) vulnerability in bundgaard Martins Free Monetized Ad Exchange Network martins-free-and-easy-ad-network-get-more-vis… Mitigation only Fix from $1,9502025-05-07 HIGH 8.8 CVE-2025-47624 Cross-Site Request Forgery (CSRF) vulnerability in apasionados DoFollow Case by Case dofollow-case-by-case allows Cross Site Request Forgery.This iss… Dofollow Case By Case after 3.5.1 Fix from $1,9502025-05-07 HIGH 8.8 CVE-2025-47546 Cross-Site Request Forgery (CSRF) vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Cross Site Request Forgery.This issue affect… Wp Compress after 6.30.30 Fix from $1,9502025-05-07 HIGH 8.1 CVE-2025-47533 Cross-Site Request Forgery (CSRF) vulnerability in Iqonic Design Graphina graphina-elementor-charts-and-graphs allows PHP Local File Inclusion.This i… Mitigation only Fix from $1,9502025-05-07 MEDIUM 6.1 CVE-2025-47517 Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Accept Donations with PayPal & Stripe easy-paypal-donation allows Stored XSS.This i… Accept Donations With Paypal 1.5+ Fix from $1,6002025-05-07 HIGH 7.1 CVE-2025-47514 Cross-Site Request Forgery (CSRF) vulnerability in Eli ELI's Related Posts Footer Links and Widget spostarbust allows Stored XSS.This issue affects E… Mitigation only Fix from $1,9502025-05-07 HIGH 7.4 CVE-2025-47491 Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Contact Form Widget new-contact-form-widget allows Cross Site Request Forgery.This issue… Mitigation only Fix from $1,9502025-05-07 MEDIUM 5.4 CVE-2025-47473 Cross-Site Request Forgery (CSRF) vulnerability in pimwick PW WooCommerce Bulk Edit pw-bulk-edit allows Cross Site Request Forgery.This issue affects… Mitigation only Fix from $1,6002025-05-07 HIGH 8.8 CVE-2025-47462 Cross-Site Request Forgery (CSRF) vulnerability in WebAppick Challan webappick-pdf-invoice-for-woocommerce allows Privilege Escalation.This issue aff… Mitigation only Fix from $1,9502025-05-07 MEDIUM 5.4 CVE-2025-47466 Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Ultimate WP Mail ultimate-wp-mail allows Cross Site Request Forgery.This issue affects … Mitigation only Fix from $1,6002025-05-07 HIGH 8.8 CVE-2025-0669 Cross-Site Request Forgery (CSRF) vulnerability in BOINC Server allows Cross Site Request Forgery.This issue affects BOINC Server: before 1.4.3. Boinc Server 1.4.3+ Fix from $1,9502025-05-07 HIGH 8.8 CVE-2025-4282 A vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as problematic. This vulnerability affects unkn… Stock Management System No fix yet Fix from $1,9502025-05-05 HIGH 8.1 CVE-2025-28062 A Cross-Site Request Forgery (CSRF) vulnerability was discovered in ERPNEXT 14.82.1 and 14.74.3. The vulnerability allows an attacker to perform unau… Erpnext No fix yet Fix from $1,9502025-05-05 MEDIUM 6.1 CVE-2025-4199 The Abundatrade Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.02. This is due to … Mitigation only Fix from $1,6002025-05-03 MEDIUM 6.1 CVE-2025-4188 The Advanced Reorder Image Text Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. Th… Mitigation only Fix from $1,6002025-05-03 MEDIUM 6.1 CVE-2025-4198 The Alink Tap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.1. This is due to missing or… Mitigation only Fix from $1,6002025-05-03 HIGH 8.8 CVE-2024-11142 Cross-Site Request Forgery (CSRF) vulnerability in Gosoft Software Proticaret E-Commerce allows Cross Site Request Forgery. This issue affects Proti… Proticaret 6.0+ Fix from $1,9502025-05-02 HIGH 8.8 CVE-2025-1305 The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2.5.4. This is due to missing… Newsblogger 0.2.5.5+ Fix from $1,9502025-05-01 HIGH 8.8 CVE-2025-32354 In Zimbra Collaboration (ZCS) 9.0 through 10.1, a Cross-Site Request Forgery (CSRF) vulnerability exists in the GraphQL endpoint (/service/extension/… Zimbra Collaboration Suite 10.1.4+ Fix from $1,9502025-04-29 MEDIUM 6.5 CVE-2025-4088 A security vulnerability in Thunderbird allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site tha… Firefox 138.0+ Fix from $1,6002025-04-29 MEDIUM 6.5 CVE-2025-3979 A vulnerability classified as problematic has been found in dazhouda lecms 3.0.3. This affects an unknown part of the file /index.php?my-password-aja… Lecms No fix yet Fix from $1,6002025-04-27 CRITICAL 9.8 CVE-2025-2907 The Order Delivery Date WordPress plugin before 12.3.1 does not have authorization and CSRF checks when importing settings. Furthermore it also lacks… Order Delivery Date Pro For Woocommerce 12.3.1+ Fix from $2,3002025-04-26 HIGH 8.8 CVE-2025-3638 A flaw was found in Moodle. The analysis request action in the Brickfield tool did not include the necessary token to prevent a Cross-site request fo… Moodle 4.1.18 / 4.3.12+ Fix from $1,9502025-04-25 MEDIUM 6.1 CVE-2025-46547 In Sherpa Orchestrator 141851, the web application lacks protection against CSRF attacks, with resultant effects of an attacker conducting XSS attack… Sherpa Orchestrator Mitigation only Fix from $1,6002025-04-25 HIGH 7.1 CVE-2025-46528 Cross-Site Request Forgery (CSRF) vulnerability in Steve Availability Calendar availability allows Stored XSS.This issue affects Availability Calenda… Mitigation only Fix from $1,9502025-04-24 HIGH 7.1 CVE-2025-46530 Cross-Site Request Forgery (CSRF) vulnerability in HuangYe WuDeng Hacklog Remote Attachment hacklog-remote-attachment allows Stored XSS.This issue af… Mitigation only Fix from $1,9502025-04-24 HIGH 7.1 CVE-2025-46520 Cross-Site Request Forgery (CSRF) vulnerability in alphasis Related Posts via Taxonomies related-posts-via-taxonomies allows Stored XSS.This issue af… Mitigation only Fix from $1,9502025-04-24 HIGH 7.1 CVE-2025-46522 Cross-Site Request Forgery (CSRF) vulnerability in Billy Bryant Tabs gt-tabs allows Stored XSS.This issue affects Tabs: from n/a through <= 4.0.3. Mitigation only Fix from $1,9502025-04-24