Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
CRITICAL 9.3 CVE-2025-30528 Cross-Site Request Forgery (CSRF) vulnerability in wpshopee Awesome Logos awesome-logos allows SQL Injection.This issue affects Awesome Logos: from n… Mitigation only Fix from $2,3002025-03-24 HIGH 7.1 CVE-2025-30522 Cross-Site Request Forgery (CSRF) vulnerability in Damian Orzol Contact Form 7 Material Design cf7-material-design allows Stored XSS.This issue affec… Mitigation only Fix from $1,9502025-03-24 HIGH 7.1 CVE-2025-1473 A Cross-Site Request Forgery (CSRF) vulnerability exists in the Signup feature of mlflow/mlflow versions 2.17.0 to 2.20.1. This vulnerability allows … Mlflow 2.20.1+ Fix from $1,9502025-03-20 HIGH 8.0 CVE-2024-9847 FlatPress CMS version latest is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow an attacker to enable or disable plugins on behalf… Flatpress 1.4+ Fix from $1,9502025-03-20 MEDIUM 6.5 CVE-2024-9365 A Cross-Site Request Forgery (CSRF) vulnerability in polyaxon/polyaxon v2.4.0 allows attackers to perform unauthorized actions in the context of the … Mitigation only Fix from $1,6002025-03-20 MEDIUM 6.1 CVE-2024-9311 A Cross-Site Request Forgery (CSRF) vulnerability in haotian-liu/llava v1.2.0 (LLaVA-1.6) allows an attacker to upload files with malicious content w… Large Language And Vision Assistant No fix yet Fix from $1,6002025-03-20 MEDIUM 6.5 CVE-2024-8736 A Denial of Service (DoS) vulnerability exists in multiple file upload endpoints of parisneo/lollms-webui version V12 (Strawberry). The vulnerability… Lollms Web Ui No fix yet Fix from $1,6002025-03-20 HIGH 8.8 CVE-2024-8489 A vulnerability in modelscope/agentscope, specifically in the AgentScope Studio backend server, allows for Cross-Site Request Forgery (CSRF) due to o… Mitigation only Fix from $1,9502025-03-20 HIGH 8.1 CVE-2024-8065 A Cross-Site Request Forgery (CSRF) vulnerability in version v1.4.1 of danswer-ai/danswer allows attackers to perform unauthorized actions in the con… Mitigation only Fix from $1,9502025-03-20 HIGH 8.1 CVE-2024-8026 A Cross-Site Request Forgery (CSRF) vulnerability exists in the backend API of netease-youdao/qanything, as of commit d9ab8bc. The backend server has… Qanything after 2024-06-24 Fix from $1,9502025-03-20 HIGH 8.8 CVE-2024-7806 A vulnerability in open-webui/open-webui versions <= 0.3.8 allows remote code execution by non-admin users via Cross-Site Request Forgery (CSRF). The… Open Webui after 0.3.8 Fix from $1,9502025-03-20 CRITICAL 9.6 CVE-2024-7760 aimhubio/aim version 3.22.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the tracking server. The vulnerability is due to overly per… Aim No fix yet Fix from $2,3002025-03-20 MEDIUM 6.9 CVE-2024-7035 In version v0.3.8 of open-webui/open-webui, sensitive actions such as deleting and resetting are performed using the GET method. This vulnerability a… Open Webui No fix yet Fix from $1,6002025-03-20 MEDIUM 6.5 CVE-2024-6841 A Cross-Site Request Forgery (CSRF) vulnerability exists in the latest commit (56b782bcefd2e59b19cd7ba7878b95f54884f502) of the vanna-ai/vanna reposi… Mitigation only Fix from $1,6002025-03-20 HIGH 8.1 CVE-2024-10906 In version 0.6.0 of eosphoros-ai/db-gpt, the `uvicorn` app created by `dbgpt_server` uses an overly permissive instance of `CORSMiddleware` which set… Db Gpt No fix yet Fix from $1,9502025-03-20 HIGH 8.8 CVE-2024-10819 A Cross-Site Request Forgery (CSRF) vulnerability in version 3.83 of binary-husky/gpt_academic allows an attacker to trick a user into uploading file… Gpt Academic No fix yet Fix from $1,9502025-03-20 MEDIUM 6.5 CVE-2024-10481 A CSRF vulnerability exists in comfyanonymous/comfyui versions up to v0.2.2. This vulnerability allows attackers to host malicious websites that, whe… Comfyui after 0.2.2 Fix from $1,6002025-03-20 HIGH 8.8 CVE-2024-13933 The FoodBakery | Delivery Restaurant Directory WordPress Theme theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… Mitigation only Fix from $1,9502025-03-19 MEDIUM 6.5 CVE-2025-26899 Cross-Site Request Forgery (CSRF) vulnerability in Recapture Cart Recovery and Email Marketing Recapture for WooCommerce recapture-for-woocommerce al… Mitigation only Fix from $1,6002025-03-15 MEDIUM 5.4 CVE-2025-2163 The Zoorum Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9. This is due to missin… Zoorum Comments after 0.9 Fix from $1,6002025-03-15 MEDIUM 5.5 CVE-2025-25873 Cross Site Request Forgery vulnerability in Open Panel OpenAdmin v.0.3.4 allows a remote attacker to escalate privileges via the Change Root Password… Openadmin No fix yet Fix from $1,6002025-03-14 HIGH 8.8 CVE-2024-13913 The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… Mitigation only Fix from $1,9502025-03-14 HIGH 7.5 CVE-2025-1764 The LoginPress | wp-login Custom Login Page Customizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… Mitigation only Fix from $1,9502025-03-14 HIGH 7.1 CVE-2025-1436 The Limit Bio WordPress plugin through 1.0 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, whic… Limit Bio No fix yet Fix from $1,9502025-03-13 HIGH 7.7 CVE-2025-27792 Opal is OBiBa’s core database application for biobanks or epidemiological studies. Prior to version 5.1.1, the protections against cross-site request… Mitigation only Fix from $1,9502025-03-11 HIGH 7.1 CVE-2025-28931 Cross-Site Request Forgery (CSRF) vulnerability in DevriX Hashtags wp-hashtags allows Stored XSS.This issue affects Hashtags: from n/a through <= 0.3… Mitigation only Fix from $1,9502025-03-11 HIGH 7.1 CVE-2025-28932 Cross-Site Request Forgery (CSRF) vulnerability in BCS Website Solutions Insert Code insert-code allows Stored XSS.This issue affects Insert Code: fr… Mitigation only Fix from $1,9502025-03-11 HIGH 7.1 CVE-2025-28933 Cross-Site Request Forgery (CSRF) vulnerability in maxfoundry MaxA/B maxab allows Stored XSS.This issue affects MaxA/B: from n/a through <= 2.2.2. Mitigation only Fix from $1,9502025-03-11 HIGH 7.1 CVE-2025-28923 Cross-Site Request Forgery (CSRF) vulnerability in philippe No Disposable Email no-disposable-email allows Stored XSS.This issue affects No Disposabl… Mitigation only Fix from $1,9502025-03-11 HIGH 7.1 CVE-2025-28925 Cross-Site Request Forgery (CSRF) vulnerability in Hieu Nguyen WATI Chat and Notification wati-chat-and-notification allows Stored XSS.This issue aff… Mitigation only Fix from $1,9502025-03-11