Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.1
CVE-2025-28922
Cross-Site Request Forgery (CSRF) vulnerability in Terence D. Go To Top go-to-top allows Stored XSS.This issue affects Go To Top: from n/a through <=…
Mitigation only
HIGH 7.1
CVE-2025-28897
Cross-Site Request Forgery (CSRF) vulnerability in Steveorevo Domain Theme domain-theme allows Stored XSS.This issue affects Domain Theme: from n/a t…
Mitigation only
HIGH 7.1
CVE-2025-28900
Cross-Site Request Forgery (CSRF) vulnerability in webgarb TabGarb Pro tabgarb allows Stored XSS.This issue affects TabGarb Pro: from n/a through <= …
Mitigation only
HIGH 7.1
CVE-2025-28901
Cross-Site Request Forgery (CSRF) vulnerability in Naren Members page only for logged in users members-page-only-for-logged-in-users allows Stored XS…
Mitigation only
HIGH 7.1
CVE-2025-28891
Cross-Site Request Forgery (CSRF) vulnerability in jazzigor price-calc price-calc allows Stored XSS.This issue affects price-calc: from n/a through <…
Mitigation only
HIGH 7.1
CVE-2025-28892
Cross-Site Request Forgery (CSRF) vulnerability in a2rocklobster FTP Sync ftp-sync allows Stored XSS.This issue affects FTP Sync: from n/a through <=…
Mitigation only
HIGH 7.1
CVE-2025-28894
Cross-Site Request Forgery (CSRF) vulnerability in frucomerci List of Posts from each Category plugin for WordPress list-posts-by-category allows Sto…
Mitigation only
HIGH 8.8
CVE-2025-28876
Cross-Site Request Forgery (CSRF) vulnerability in Skrill_Team Skrill Official official-skrill-woocommerce allows Cross Site Request Forgery.This iss…
Skrill
1.0.67+
HIGH 7.1
CVE-2025-28883
Cross-Site Request Forgery (CSRF) vulnerability in Martin WP Compare Tables wp-compare-tables allows Stored XSS.This issue affects WP Compare Tables:…
Mitigation only
HIGH 8.8
CVE-2025-28867
Cross-Site Request Forgery (CSRF) vulnerability in stesvis Frontpage category filter frontpage-category-filter allows Cross Site Request Forgery.This…
Frontpage Category Filter
after 1.0.2
HIGH 8.8
CVE-2025-28868
Cross-Site Request Forgery (CSRF) vulnerability in ZipList ZipList Recipe ziplist-recipe-plugin allows Cross Site Request Forgery.This issue affects …
Ziplist Recipe
after 3.1
HIGH 8.8
CVE-2025-28859
Cross-Site Request Forgery (CSRF) vulnerability in CodeVibrant Maintenance Notice maintenance-notice allows Cross Site Request Forgery.This issue aff…
Maintenance Notice
after 1.0.5
MEDIUM 6.1
CVE-2025-28860
Cross-Site Request Forgery (CSRF) vulnerability in PPDPurveyor Google News Editors Picks Feed Generator google-news-editors-picks-news-feeds allows S…
Google News Editors Picks Feed Generator
after 2.1
MEDIUM 6.1
CVE-2025-28861
Cross-Site Request Forgery (CSRF) vulnerability in bhzad WP jQuery Persian Datepicker wpjqp-datepicker allows Stored XSS.This issue affects WP jQuery…
Wp Jquery Persian Datepicker
after 0.1.0
HIGH 8.8
CVE-2025-28862
Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Comment Date and Gravatar remover remove-date-and-gravatar-under-comment allows Cross Si…
Comment Date And Gravatar Remover
Mitigation only
HIGH 8.8
CVE-2025-28863
Cross-Site Request Forgery (CSRF) vulnerability in Carlos Minatti Delete Original Image delete-original-image allows Cross Site Request Forgery.This …
Delete Original Image
after 0.4
HIGH 8.8
CVE-2025-28864
Cross-Site Request Forgery (CSRF) vulnerability in planetstudio Builder for Contact Form 7 by Webconstruct cf7-builder allows Cross Site Request Forg…
Builder For Contact Form 7
after 1.2.2
HIGH 8.8
CVE-2025-28866
Cross-Site Request Forgery (CSRF) vulnerability in smerriman Login Logger login-logger allows Cross Site Request Forgery.This issue affects Login Log…
Login Logger
after 1.2.1
HIGH 8.8
CVE-2025-28856
Cross-Site Request Forgery (CSRF) vulnerability in dangrossman W3Counter Free Real-Time Web Stats blog-stats-by-w3counter allows Cross Site Request F…
W3counter
after 4.1
MEDIUM 6.1
CVE-2025-28857
Cross-Site Request Forgery (CSRF) vulnerability in rankchecker Rankchecker.io Integration rankchecker-io-integration allows Stored XSS.This issue aff…
Rankchecker
after 1.0.9
MEDIUM 6.8
CVE-2025-25927
A Cross-Site Request Forgery (CSRF) in Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary operations via a crafted GET request.
Openmrs
No fix yet
HIGH 8.0
CVE-2025-25928
A Cross-Site Request Forgery (CSRF) in the component /admin/users/user.form of Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary opera…
Openmrs
No fix yet
HIGH 7.3
CVE-2025-25748
A CSRF vulnerability in the gestione_utenti.php endpoint of HotelDruid 3.0.7 allows attackers to perform unauthorized actions (e.g., modifying user p…
Hoteldruid
Mitigation only
HIGH 8.8
CVE-2023-48790
A cross site request forgery vulnerability [CWE-352] in Fortinet FortiNDR version 7.4.0, 7.2.0 through 7.2.1 and 7.1.0 through 7.1.1 and before 7.0.5…
Fortindr
7.0.6 / 7.1.2+
HIGH 8.8
CVE-2025-27912
An issue was discovered in Datalust Seq before 2024.3.13545. Missing Content-Type validation can lead to CSRF when (1) Entra ID or OpenID Connect aut…
Seq
2024.3.13545+
MEDIUM 6.1
CVE-2024-13436
The Appsero Helper plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.2. This is due to missi…
Mitigation only
HIGH 8.0
CVE-2025-27910
tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/upd/status. This vulnerability allows attacker…
Tianti
No fix yet
HIGH 8.8
CVE-2025-25907
tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/save. This vulnerability allows attackers to e…
Tianti
No fix yet
MEDIUM 6.1
CVE-2025-26910
Cross-Site Request Forgery (CSRF) vulnerability in Iqonic Design WPBookit wpbookit allows Stored XSS.This issue affects WPBookit: from n/a through <=…
Wpbookit
1.0.2+
MEDIUM 6.5
CVE-2025-24387
A vulnerability in OTRS Application Server allows session hijacking due to missing attributes for sensitive
cookie settings in HTTPS sessions. A req…
Otrs
after 2025.1.2