Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.1
CVE-2025-1382
The Contact Us By Lord Linus WordPress plugin through 2.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, w…
Contact Us
after 2.6
HIGH 8.8
CVE-2024-11640
The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.…
Vikrentcar
1.4.3+
MEDIUM 5.4
CVE-2024-13826
The Email Keep WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logge…
Email Keep
after 1.1
MEDIUM 6.5
CVE-2024-13774
The Wishlist for WooCommerce: Multi Wishlists Per Customer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an…
Wishlist For Woocommerce
3.1.8+
MEDIUM 6.1
CVE-2024-12634
The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress is vulnerable to Cross-Site Re…
Mitigation only
MEDIUM 6.5
CVE-2025-2042
A vulnerability has been found in huang-yk student-manage 1.0 and classified as problematic. This vulnerability affects unknown code. The manipulatio…
Student Manage
Mitigation only
MEDIUM 5.4
CVE-2025-27624
A cross-site request forgery (CSRF) vulnerability in Jenkins 2.499 and earlier, LTS 2.492.1 and earlier allows attackers to have users toggle their c…
Jenkins
2.492.2 / 2.500+
HIGH 8.8
CVE-2024-51144
Cross Site Request Forgery (CSRF) vulnerability exists in the 'pvmsg.php?action=add_message', pvmsg.php?action=confirm_delete , and ajax.server.php?p…
Mitigation only
MEDIUM 6.3
CVE-2025-1435
The bbPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.11. This is due to missing or …
Mitigation only
HIGH 8.8
CVE-2025-27664
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Insufficient CSRF Protection OVE-20230524-00…
Vasion Print
20.0.1923 / 22.0.843+
HIGH 7.1
CVE-2024-50705
Unauthenticated reflected cross-site scripting (XSS) vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary …
Tripleplay
24.1.2+
HIGH 8.8
CVE-2025-1306
The Newscrunch theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.4. This is due to missing or…
Newscrunch
1.8.4.1+
HIGH 8.8
CVE-2025-25967
Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF). This flaw enables attackers to trick authenticated users into performing…
Acora Cms
Mitigation only
CRITICAL 9.0
CVE-2025-26206
Cross Site Request Forgery vulnerability in sell done storefront v.1.0 allows a remote attacker to escalate privileges via the index.html component
Storefront
No fix yet
MEDIUM 5.7
CVE-2024-30154
HCL SX is vulnerable to cross-site request forgery vulnerability which could allow an attacker to execute malicious and unauthorized actions transmit…
Hcl Sx
Mitigation only
MEDIUM 6.5
CVE-2025-25137
Cross-Site Request Forgery (CSRF) vulnerability in kareemsultan Social Links social-links allows Cross Site Request Forgery.
This issue affects Soci…
Mitigation only
HIGH 7.1
CVE-2025-25121
Cross-Site Request Forgery (CSRF) vulnerability in shyammakwana Theme Options Z theme-options-z allows Cross Site Request Forgery.This issue affects …
Mitigation only
HIGH 7.1
CVE-2025-23502
Cross-Site Request Forgery (CSRF) vulnerability in Ned Curated Search curated-search allows Stored XSS.This issue affects Curated Search: from n/a th…
Mitigation only
HIGH 7.1
CVE-2025-23446
Cross-Site Request Forgery (CSRF) vulnerability in KokoenDE WP SpaceContent wp-spacecontent allows Stored XSS.This issue affects WP SpaceContent: fro…
Mitigation only
MEDIUM 5.4
CVE-2025-27579
In Bitaxe ESP-Miner before 2.5.0 with AxeOS, one can use an /api/system CSRF attack to update the payout address (aka stratumUser) for a Bitaxe Bitco…
Patch available
MEDIUM 6.5
CVE-2025-1813
A vulnerability classified as problematic was found in zj1983 zz up to 2024-08. Affected by this vulnerability is an unknown functionality. The manip…
Zz
after 2024-8
CRITICAL 9.6
CVE-2025-25379
Cross Site Request Forgery vulnerability in 07FLYCMS v.1.3.9 allows a remote attacker to execute arbitrary code via the id parameter of the del.html …
07flycms
Mitigation only
HIGH 8.8
CVE-2025-1687
The Cardealer theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.4. This is due to missing nonce v…
Mitigation only
MEDIUM 5.4
CVE-2024-0392
A Cross-Site Request Forgery (CSRF) vulnerability exists in the management console of WSO2 Enterprise Integrator 6.6.0 due to the absence of CSRF tok…
Enterprise Integrator
Mitigation only
HIGH 8.8
CVE-2025-26963
Cross-Site Request Forgery (CSRF) vulnerability in ClickWhale ClickWhale clickwhale allows Cross Site Request Forgery.This issue affects ClickWhale: …
Clickwhale
2.4.4+
HIGH 7.1
CVE-2025-26931
Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Software Tribulant Gallery Voting gallery-voting allows Stored XSS.This issue affects Tr…
Mitigation only
MEDIUM 6.5
CVE-2025-1644
A vulnerability classified as problematic has been found in Benner ModernaNet up to 1.2.0. Affected is an unknown function of the file /DadosPessoais…
Modernanet
1.2.1+
HIGH 8.8
CVE-2025-1643
A vulnerability was found in Benner ModernaNet up to 1.1.0. It has been rated as problematic. This issue affects some unknown processing of the file …
Modernanet
1.1.1+
HIGH 7.1
CVE-2025-27355
Cross-Site Request Forgery (CSRF) vulnerability in Nicolas GRILLET Woocommerce – Loi Hamon loi-hamon allows Stored XSS.This issue affects Woocommerce…
Mitigation only
MEDIUM 5.4
CVE-2025-27340
Cross-Site Request Forgery (CSRF) vulnerability in Forge12 Interactive GmbH F12-Profiler f12-profiler allows Cross Site Request Forgery.This issue af…
Mitigation only