Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.1
CVE-2025-27332
Cross-Site Request Forgery (CSRF) vulnerability in gmnazmul Smart Maintenance & Countdown smart-maintenance-countdown allows Stored XSS.This issue af…
Mitigation only
HIGH 7.1
CVE-2025-27321
Cross-Site Request Forgery (CSRF) vulnerability in Blighty Blightly Explorer blighty-explorer allows Stored XSS.This issue affects Blightly Explorer:…
Mitigation only
HIGH 8.3
CVE-2025-27298
Cross-Site Request Forgery (CSRF) vulnerability in cmstactics WP Video Posts wp-video-posts allows OS Command Injection.This issue affects WP Video P…
Mitigation only
HIGH 8.8
CVE-2025-27276
Cross-Site Request Forgery (CSRF) vulnerability in lizeipe Photo Gallery ( Responsive ) photo-gallery-pearlbells allows Privilege Escalation.This iss…
Mitigation only
HIGH 7.1
CVE-2025-27277
Cross-Site Request Forgery (CSRF) vulnerability in tiefpunkt Add Linked Images To Gallery add-linked-images-to-gallery-v01 allows Cross Site Request …
Mitigation only
HIGH 8.8
CVE-2025-27012
Cross-Site Request Forgery (CSRF) vulnerability in a1post A1POST.BG Shipping for Woo a1post-bg-shipping-for-woocommerce allows Privilege Escalation.T…
Mitigation only
HIGH 8.0
CVE-2025-25769
Wangmarket v4.10 to v5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /controller/UserController.java.
Wangmarket
after 5.0
MEDIUM 6.8
CVE-2025-25770
Wangmarket v4.10 to v5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /agency/AgencyUserController.java.
Wangmarket
after 5.0
MEDIUM 5.1
CVE-2025-25772
A Cross-Site Request Forgery (CSRF) in the component /back/UserController.java of Jspxcms v9.0 to v9.5 allows attackers to arbitrarily add Administra…
Jspxcms
after 9.5.0
MEDIUM 5.9
CVE-2024-7141
Versions of Gliffy Online prior to versions 4.14.0-7 contains a Cross Site Request Forgery (CSRF) flaw.
Mitigation only
HIGH 8.8
CVE-2024-49779
IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages
could allow a remote attacker to bypass security restrictions, caused by improper validation an…
Openpages With Watson
8.3.0.3 / 9.0.0.5+
HIGH 8.8
CVE-2024-13753
The Ultimate Classified Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is …
Ultimate Classified Listings
after 1.4
HIGH 8.1
CVE-2020-10095
Various Lexmark devices have CSRF that allows an attacker to modify the configuration of the device.
Mitigation only
MEDIUM 5.4
CVE-2024-13339
The DeBounce Email Validator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.8.0. This is du…
Email Validator
after 5.6.6
MEDIUM 6.5
CVE-2025-0865
The WP Media Category Management plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.0 to 2.3.3. This is due to missing or…
Wp Media Category Management
2.4.0+
HIGH 8.8
CVE-2025-1441
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1…
Royal Elementor Addons
after 1.7.1007
MEDIUM 5.4
CVE-2024-13523
The MemorialDay plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. This is due to missing …
Memorialday
1.1.0+
HIGH 8.8
CVE-2024-13315
The Shopwarden – Automated WooCommerce monitoring & testing plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a…
Shopwarden
1.0.12+
HIGH 8.8
CVE-2024-13852
The Option Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing nonce validation on the plu…
Option Editor
after 1.0
HIGH 8.1
CVE-2024-13684
The Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6. This is due to missing or incor…
Reset
after 1.6
MEDIUM 5.4
CVE-2024-13522
The magayo Lottery Results plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.12. This is due…
Magayo Lottery Results
after 2.0.12
HIGH 7.1
CVE-2025-26768
Cross-Site Request Forgery (CSRF) vulnerability in what3words what3words Address Field 3-word-address-validation-field allows Stored XSS.This issue a…
Mitigation only
HIGH 7.1
CVE-2025-26759
Cross-Site Request Forgery (CSRF) vulnerability in alexvtn Content Snippet Manager content-snippet-manager allows Stored XSS.This issue affects Conte…
Mitigation only
HIGH 7.1
CVE-2025-24699
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company WP Coder wp-coder allows Cross-Site Scripting (XSS).This issue affects WP Coder: from …
Mitigation only
HIGH 7.1
CVE-2025-22705
Cross-Site Request Forgery (CSRF) vulnerability in godthor Disqus Popular Posts disqus-popular-posts allows Reflected XSS.This issue affects Disqus P…
Mitigation only
MEDIUM 6.5
CVE-2025-23411
mySCADA myPRO Manager
is vulnerable to cross-site request forgery (CSRF), which could allow
an attacker to obtain sensitive information. An attacke…
Mypro
1.4+
HIGH 7.1
CVE-2025-26580
Cross-Site Request Forgery (CSRF) vulnerability in Complete SEO Page/Post Specific Social Share Buttons pagepost-specific-social-share-buttons allows…
Mitigation only
HIGH 7.1
CVE-2025-26582
Cross-Site Request Forgery (CSRF) vulnerability in Blackbam TinyMCE Advanced qTranslate fix editor problems tinymce-advanced-qtranslate-fix-editor-pr…
Mitigation only
HIGH 7.1
CVE-2025-26569
Cross-Site Request Forgery (CSRF) vulnerability in Callmeforsox Post Thumbs allows Stored XSS.
This issue affects Post Thumbs: from n/a through 1.5.
Mitigation only
HIGH 7.1
CVE-2025-26570
Cross-Site Request Forgery (CSRF) vulnerability in uamv Glance That allows Cross Site Request Forgery.
This issue affects Glance That: from n/a thro…
No fix yet