Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 7.1 CVE-2025-27332 Cross-Site Request Forgery (CSRF) vulnerability in gmnazmul Smart Maintenance & Countdown smart-maintenance-countdown allows Stored XSS.This issue af… Mitigation only Fix from $1,9502025-02-24 HIGH 7.1 CVE-2025-27321 Cross-Site Request Forgery (CSRF) vulnerability in Blighty Blightly Explorer blighty-explorer allows Stored XSS.This issue affects Blightly Explorer:… Mitigation only Fix from $1,9502025-02-24 HIGH 8.3 CVE-2025-27298 Cross-Site Request Forgery (CSRF) vulnerability in cmstactics WP Video Posts wp-video-posts allows OS Command Injection.This issue affects WP Video P… Mitigation only Fix from $1,9502025-02-24 HIGH 8.8 CVE-2025-27276 Cross-Site Request Forgery (CSRF) vulnerability in lizeipe Photo Gallery ( Responsive ) photo-gallery-pearlbells allows Privilege Escalation.This iss… Mitigation only Fix from $1,9502025-02-24 HIGH 7.1 CVE-2025-27277 Cross-Site Request Forgery (CSRF) vulnerability in tiefpunkt Add Linked Images To Gallery add-linked-images-to-gallery-v01 allows Cross Site Request … Mitigation only Fix from $1,9502025-02-24 HIGH 8.8 CVE-2025-27012 Cross-Site Request Forgery (CSRF) vulnerability in a1post A1POST.BG Shipping for Woo a1post-bg-shipping-for-woocommerce allows Privilege Escalation.T… Mitigation only Fix from $1,9502025-02-22 HIGH 8.0 CVE-2025-25769 Wangmarket v4.10 to v5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /controller/UserController.java. Wangmarket after 5.0 Fix from $1,9502025-02-21 MEDIUM 6.8 CVE-2025-25770 Wangmarket v4.10 to v5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /agency/AgencyUserController.java. Wangmarket after 5.0 Fix from $1,6002025-02-21 MEDIUM 5.1 CVE-2025-25772 A Cross-Site Request Forgery (CSRF) in the component /back/UserController.java of Jspxcms v9.0 to v9.5 allows attackers to arbitrarily add Administra… Jspxcms after 9.5.0 Fix from $1,6002025-02-21 MEDIUM 5.9 CVE-2024-7141 Versions of Gliffy Online prior to versions 4.14.0-7 contains a Cross Site Request Forgery (CSRF) flaw. Mitigation only Fix from $1,6002025-02-20 HIGH 8.8 CVE-2024-49779 IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages could allow a remote attacker to bypass security restrictions, caused by improper validation an… Openpages With Watson 8.3.0.3 / 9.0.0.5+ Fix from $1,9502025-02-20 HIGH 8.8 CVE-2024-13753 The Ultimate Classified Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is … Ultimate Classified Listings after 1.4 Fix from $1,9502025-02-20 HIGH 8.1 CVE-2020-10095 Various Lexmark devices have CSRF that allows an attacker to modify the configuration of the device. Mitigation only Fix from $1,9502025-02-19 MEDIUM 5.4 CVE-2024-13339 The DeBounce Email Validator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.8.0. This is du… Email Validator after 5.6.6 Fix from $1,6002025-02-19 MEDIUM 6.5 CVE-2025-0865 The WP Media Category Management plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.0 to 2.3.3. This is due to missing or… Wp Media Category Management 2.4.0+ Fix from $1,6002025-02-19 HIGH 8.8 CVE-2025-1441 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1… Royal Elementor Addons after 1.7.1007 Fix from $1,9502025-02-19 MEDIUM 5.4 CVE-2024-13523 The MemorialDay plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. This is due to missing … Memorialday 1.1.0+ Fix from $1,6002025-02-18 HIGH 8.8 CVE-2024-13315 The Shopwarden – Automated WooCommerce monitoring & testing plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… Shopwarden 1.0.12+ Fix from $1,9502025-02-18 HIGH 8.8 CVE-2024-13852 The Option Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing nonce validation on the plu… Option Editor after 1.0 Fix from $1,9502025-02-18 HIGH 8.1 CVE-2024-13684 The Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6. This is due to missing or incor… Reset after 1.6 Fix from $1,9502025-02-18 MEDIUM 5.4 CVE-2024-13522 The magayo Lottery Results plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.12. This is due… Magayo Lottery Results after 2.0.12 Fix from $1,6002025-02-18 HIGH 7.1 CVE-2025-26768 Cross-Site Request Forgery (CSRF) vulnerability in what3words what3words Address Field 3-word-address-validation-field allows Stored XSS.This issue a… Mitigation only Fix from $1,9502025-02-16 HIGH 7.1 CVE-2025-26759 Cross-Site Request Forgery (CSRF) vulnerability in alexvtn Content Snippet Manager content-snippet-manager allows Stored XSS.This issue affects Conte… Mitigation only Fix from $1,9502025-02-16 HIGH 7.1 CVE-2025-24699 Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company WP Coder wp-coder allows Cross-Site Scripting (XSS).This issue affects WP Coder: from … Mitigation only Fix from $1,9502025-02-14 HIGH 7.1 CVE-2025-22705 Cross-Site Request Forgery (CSRF) vulnerability in godthor Disqus Popular Posts disqus-popular-posts allows Reflected XSS.This issue affects Disqus P… Mitigation only Fix from $1,9502025-02-14 MEDIUM 6.5 CVE-2025-23411 mySCADA myPRO Manager is vulnerable to cross-site request forgery (CSRF), which could allow an attacker to obtain sensitive information. An attacke… Mypro 1.4+ Fix from $1,6002025-02-13 HIGH 7.1 CVE-2025-26580 Cross-Site Request Forgery (CSRF) vulnerability in Complete SEO Page/Post Specific Social Share Buttons pagepost-specific-social-share-buttons allows… Mitigation only Fix from $1,9502025-02-13 HIGH 7.1 CVE-2025-26582 Cross-Site Request Forgery (CSRF) vulnerability in Blackbam TinyMCE Advanced qTranslate fix editor problems tinymce-advanced-qtranslate-fix-editor-pr… Mitigation only Fix from $1,9502025-02-13 HIGH 7.1 CVE-2025-26569 Cross-Site Request Forgery (CSRF) vulnerability in Callmeforsox Post Thumbs allows Stored XSS. This issue affects Post Thumbs: from n/a through 1.5. Mitigation only Fix from $1,9502025-02-13 HIGH 7.1 CVE-2025-26570 Cross-Site Request Forgery (CSRF) vulnerability in uamv Glance That allows Cross Site Request Forgery. This issue affects Glance That: from n/a thro… No fix yet Fix from $1,9502025-02-13