Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 7.1 CVE-2025-28922 Cross-Site Request Forgery (CSRF) vulnerability in Terence D. Go To Top go-to-top allows Stored XSS.This issue affects Go To Top: from n/a through <=… Mitigation only Fix from $1,9502025-03-11 HIGH 7.1 CVE-2025-28897 Cross-Site Request Forgery (CSRF) vulnerability in Steveorevo Domain Theme domain-theme allows Stored XSS.This issue affects Domain Theme: from n/a t… Mitigation only Fix from $1,9502025-03-11 HIGH 7.1 CVE-2025-28900 Cross-Site Request Forgery (CSRF) vulnerability in webgarb TabGarb Pro tabgarb allows Stored XSS.This issue affects TabGarb Pro: from n/a through <= … Mitigation only Fix from $1,9502025-03-11 HIGH 7.1 CVE-2025-28901 Cross-Site Request Forgery (CSRF) vulnerability in Naren Members page only for logged in users members-page-only-for-logged-in-users allows Stored XS… Mitigation only Fix from $1,9502025-03-11 HIGH 7.1 CVE-2025-28891 Cross-Site Request Forgery (CSRF) vulnerability in jazzigor price-calc price-calc allows Stored XSS.This issue affects price-calc: from n/a through <… Mitigation only Fix from $1,9502025-03-11 HIGH 7.1 CVE-2025-28892 Cross-Site Request Forgery (CSRF) vulnerability in a2rocklobster FTP Sync ftp-sync allows Stored XSS.This issue affects FTP Sync: from n/a through <=… Mitigation only Fix from $1,9502025-03-11 HIGH 7.1 CVE-2025-28894 Cross-Site Request Forgery (CSRF) vulnerability in frucomerci List of Posts from each Category plugin for WordPress list-posts-by-category allows Sto… Mitigation only Fix from $1,9502025-03-11 HIGH 8.8 CVE-2025-28876 Cross-Site Request Forgery (CSRF) vulnerability in Skrill_Team Skrill Official official-skrill-woocommerce allows Cross Site Request Forgery.This iss… Skrill 1.0.67+ Fix from $1,9502025-03-11 HIGH 7.1 CVE-2025-28883 Cross-Site Request Forgery (CSRF) vulnerability in Martin WP Compare Tables wp-compare-tables allows Stored XSS.This issue affects WP Compare Tables:… Mitigation only Fix from $1,9502025-03-11 HIGH 8.8 CVE-2025-28867 Cross-Site Request Forgery (CSRF) vulnerability in stesvis Frontpage category filter frontpage-category-filter allows Cross Site Request Forgery.This… Frontpage Category Filter after 1.0.2 Fix from $1,9502025-03-11 HIGH 8.8 CVE-2025-28868 Cross-Site Request Forgery (CSRF) vulnerability in ZipList ZipList Recipe ziplist-recipe-plugin allows Cross Site Request Forgery.This issue affects … Ziplist Recipe after 3.1 Fix from $1,9502025-03-11 HIGH 8.8 CVE-2025-28859 Cross-Site Request Forgery (CSRF) vulnerability in CodeVibrant Maintenance Notice maintenance-notice allows Cross Site Request Forgery.This issue aff… Maintenance Notice after 1.0.5 Fix from $1,9502025-03-11 MEDIUM 6.1 CVE-2025-28860 Cross-Site Request Forgery (CSRF) vulnerability in PPDPurveyor Google News Editors Picks Feed Generator google-news-editors-picks-news-feeds allows S… Google News Editors Picks Feed Generator after 2.1 Fix from $1,6002025-03-11 MEDIUM 6.1 CVE-2025-28861 Cross-Site Request Forgery (CSRF) vulnerability in bhzad WP jQuery Persian Datepicker wpjqp-datepicker allows Stored XSS.This issue affects WP jQuery… Wp Jquery Persian Datepicker after 0.1.0 Fix from $1,6002025-03-11 HIGH 8.8 CVE-2025-28862 Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Comment Date and Gravatar remover remove-date-and-gravatar-under-comment allows Cross Si… Comment Date And Gravatar Remover Mitigation only Fix from $1,9502025-03-11 HIGH 8.8 CVE-2025-28863 Cross-Site Request Forgery (CSRF) vulnerability in Carlos Minatti Delete Original Image delete-original-image allows Cross Site Request Forgery.This … Delete Original Image after 0.4 Fix from $1,9502025-03-11 HIGH 8.8 CVE-2025-28864 Cross-Site Request Forgery (CSRF) vulnerability in planetstudio Builder for Contact Form 7 by Webconstruct cf7-builder allows Cross Site Request Forg… Builder For Contact Form 7 after 1.2.2 Fix from $1,9502025-03-11 HIGH 8.8 CVE-2025-28866 Cross-Site Request Forgery (CSRF) vulnerability in smerriman Login Logger login-logger allows Cross Site Request Forgery.This issue affects Login Log… Login Logger after 1.2.1 Fix from $1,9502025-03-11 HIGH 8.8 CVE-2025-28856 Cross-Site Request Forgery (CSRF) vulnerability in dangrossman W3Counter Free Real-Time Web Stats blog-stats-by-w3counter allows Cross Site Request F… W3counter after 4.1 Fix from $1,9502025-03-11 MEDIUM 6.1 CVE-2025-28857 Cross-Site Request Forgery (CSRF) vulnerability in rankchecker Rankchecker.io Integration rankchecker-io-integration allows Stored XSS.This issue aff… Rankchecker after 1.0.9 Fix from $1,6002025-03-11 MEDIUM 6.8 CVE-2025-25927 A Cross-Site Request Forgery (CSRF) in Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary operations via a crafted GET request. Openmrs No fix yet Fix from $1,6002025-03-11 HIGH 8.0 CVE-2025-25928 A Cross-Site Request Forgery (CSRF) in the component /admin/users/user.form of Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary opera… Openmrs No fix yet Fix from $1,9502025-03-11 HIGH 7.3 CVE-2025-25748 A CSRF vulnerability in the gestione_utenti.php endpoint of HotelDruid 3.0.7 allows attackers to perform unauthorized actions (e.g., modifying user p… Hoteldruid Mitigation only Fix from $1,9502025-03-11 HIGH 8.8 CVE-2023-48790 A cross site request forgery vulnerability [CWE-352] in Fortinet FortiNDR version 7.4.0, 7.2.0 through 7.2.1 and 7.1.0 through 7.1.1 and before 7.0.5… Fortindr 7.0.6 / 7.1.2+ Fix from $1,9502025-03-11 HIGH 8.8 CVE-2025-27912 An issue was discovered in Datalust Seq before 2024.3.13545. Missing Content-Type validation can lead to CSRF when (1) Entra ID or OpenID Connect aut… Seq 2024.3.13545+ Fix from $1,9502025-03-11 MEDIUM 6.1 CVE-2024-13436 The Appsero Helper plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.2. This is due to missi… Mitigation only Fix from $1,6002025-03-11 HIGH 8.0 CVE-2025-27910 tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/upd/status. This vulnerability allows attacker… Tianti No fix yet Fix from $1,9502025-03-10 HIGH 8.8 CVE-2025-25907 tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/save. This vulnerability allows attackers to e… Tianti No fix yet Fix from $1,9502025-03-10 MEDIUM 6.1 CVE-2025-26910 Cross-Site Request Forgery (CSRF) vulnerability in Iqonic Design WPBookit wpbookit allows Stored XSS.This issue affects WPBookit: from n/a through <=… Wpbookit 1.0.2+ Fix from $1,6002025-03-10 MEDIUM 6.5 CVE-2025-24387 A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive cookie settings in HTTPS sessions. A req… Otrs after 2025.1.2 Fix from $1,6002025-03-10