Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 7.1 CVE-2025-26571 Cross-Site Request Forgery (CSRF) vulnerability in wibiya Wibiya Toolbar wibiya allows Cross Site Request Forgery.This issue affects Wibiya Toolbar: … Mitigation only Fix from $1,9502025-02-13 HIGH 7.1 CVE-2025-26572 Cross-Site Request Forgery (CSRF) vulnerability in jesseheap WP PHPList phplist-form-integration allows Cross Site Request Forgery.This issue affects… Mitigation only Fix from $1,9502025-02-13 HIGH 7.1 CVE-2025-26577 Cross-Site Request Forgery (CSRF) vulnerability in daxiawp DX-auto-publish dx-auto-publish allows Stored XSS.This issue affects DX-auto-publish: from… Mitigation only Fix from $1,9502025-02-13 HIGH 7.1 CVE-2025-26578 Cross-Site Request Forgery (CSRF) vulnerability in mathieuhays Simple Documentation client-documentation allows Stored XSS.This issue affects Simple … Mitigation only Fix from $1,9502025-02-13 HIGH 7.1 CVE-2025-26562 Cross-Site Request Forgery (CSRF) vulnerability in Shambhu Patnaik RSS Filter rss-filter allows Stored XSS.This issue affects RSS Filter: from n/a th… Mitigation only Fix from $1,9502025-02-13 HIGH 7.1 CVE-2025-26568 Cross-Site Request Forgery (CSRF) vulnerability in jensmueller Easy Amazon Product Information easy-amazon-product-information allows Stored XSS.This… Mitigation only Fix from $1,9502025-02-13 HIGH 7.1 CVE-2025-26545 Cross-Site Request Forgery (CSRF) vulnerability in shisuh Related Posts Line-up-Exactly by Milliard related-posts-line-up-exactry-by-milliard allows … Mitigation only Fix from $1,9502025-02-13 HIGH 7.1 CVE-2025-26547 Cross-Site Request Forgery (CSRF) vulnerability in nagarjunsonti My Login Logout Plugin my-loginlogout allows Stored XSS.This issue affects My Login … Mitigation only Fix from $1,9502025-02-13 HIGH 7.1 CVE-2025-26549 Cross-Site Request Forgery (CSRF) vulnerability in pa1 WP Html Page Sitemap wp-html-page-sitemap allows Stored XSS.This issue affects WP Html Page Si… Mitigation only Fix from $1,9502025-02-13 HIGH 7.1 CVE-2025-26550 Cross-Site Request Forgery (CSRF) vulnerability in Kunal Shivale Global Meta Keyword & Description global-meta-keyword-and-description allows Stored … Mitigation only Fix from $1,9502025-02-13 HIGH 7.1 CVE-2025-26543 Cross-Site Request Forgery (CSRF) vulnerability in Pukhraj Suthar Simple Responsive Menu simple-responsive-menu allows Stored XSS.This issue affects … Mitigation only Fix from $1,9502025-02-13 MEDIUM 5.4 CVE-2024-12386 The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.3. This is due to missing… Wp Abstracts 2.7.4+ Fix from $1,6002025-02-12 MEDIUM 5.4 CVE-2025-0808 The Houzez Property Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.21. This is due t… Houzez Property Feed 2.4.22+ Fix from $1,6002025-02-12 HIGH 8.2 CVE-2025-24897 Misskey is an open source, federated social media platform. Starting in version 12.109.0 and prior to version 2025.2.0-alpha.0, due to a lack of CSRF… Misskey 2025.2.0+ Fix from $1,9502025-02-11 HIGH 8.6 CVE-2025-24900 Concorde, formerly know as Nexkey, is a fork of the federated microblogging platform Misskey. Due to a lack of CSRF countermeasures and improper sett… Patch available Fix from $1,9502025-02-11 MEDIUM 6.8 CVE-2025-24875 SAP Commerce, by default, sets certain cookies with the SameSite attribute configured to None (SameSite=None). This includes authentication cookies u… Mitigation only Fix from $1,6002025-02-11 MEDIUM 6.1 CVE-2025-25166 Cross-Site Request Forgery (CSRF) vulnerability in gabrieldarezzo InLocation inlocation allows Stored XSS.This issue affects InLocation: from n/a thr… Inlocation after 1.8 Fix from $1,6002025-02-07 MEDIUM 6.1 CVE-2025-25168 Cross-Site Request Forgery (CSRF) vulnerability in Black and White BookPress – For Book Authors book-press allows Cross-Site Scripting (XSS).This iss… Bookpress after 1.2.7 Fix from $1,6002025-02-07 HIGH 7.1 CVE-2025-25154 Cross-Site Request Forgery (CSRF) vulnerability in scweber Custom Comment Notifications custom-comment-notifications allows Stored XSS.This issue aff… Mitigation only Fix from $1,9502025-02-07 HIGH 7.1 CVE-2025-25156 Cross-Site Request Forgery (CSRF) vulnerability in Stanko Metodiev Quote Comments quote-comments allows Stored XSS.This issue affects Quote Comments:… Mitigation only Fix from $1,9502025-02-07 MEDIUM 6.1 CVE-2025-25160 Cross-Site Request Forgery (CSRF) vulnerability in Mark Barnes Style Tweaker style-tweaker allows Stored XSS.This issue affects Style Tweaker: from n… Style Tweaker after 0.11 Fix from $1,6002025-02-07 HIGH 7.1 CVE-2025-25147 Cross-Site Request Forgery (CSRF) vulnerability in Phillip.Gooch Auto SEO auto-seo allows Stored XSS.This issue affects Auto SEO: from n/a through <=… Mitigation only Fix from $1,9502025-02-07 HIGH 7.1 CVE-2025-25148 Cross-Site Request Forgery (CSRF) vulnerability in ElbowRobo Read More Copy Link read-more-copy-link allows Stored XSS.This issue affects Read More C… Mitigation only Fix from $1,9502025-02-07 HIGH 7.1 CVE-2025-25149 Cross-Site Request Forgery (CSRF) vulnerability in Danillo Nunes Login-box login-box allows Stored XSS.This issue affects Login-box: from n/a through… Mitigation only Fix from $1,9502025-02-07 HIGH 7.1 CVE-2025-25152 Cross-Site Request Forgery (CSRF) vulnerability in LukaszWiecek Smart DoFollow smart-dofollow allows Stored XSS.This issue affects Smart DoFollow: fr… Mitigation only Fix from $1,9502025-02-07 HIGH 7.1 CVE-2025-25153 Cross-Site Request Forgery (CSRF) vulnerability in djjmz Simple Auto Tag simple-auto-tag allows Stored XSS.This issue affects Simple Auto Tag: from n… Mitigation only Fix from $1,9502025-02-07 HIGH 7.1 CVE-2025-25140 Cross-Site Request Forgery (CSRF) vulnerability in Scriptonite Simple User Profile simple-user-profile allows Stored XSS.This issue affects Simple Us… Mitigation only Fix from $1,9502025-02-07 MEDIUM 5.4 CVE-2025-25145 Cross-Site Request Forgery (CSRF) vulnerability in jordan.hatch Infusionsoft Analytics infusionsoft-web-tracker allows Cross Site Request Forgery.Thi… Mitigation only Fix from $1,6002025-02-07 HIGH 7.1 CVE-2025-25128 Cross-Site Request Forgery (CSRF) vulnerability in orlandolac Facilita Form Tracker facilita-form-tracker allows Stored XSS.This issue affects Facili… Mitigation only Fix from $1,9502025-02-07 HIGH 7.1 CVE-2025-25135 Cross-Site Request Forgery (CSRF) vulnerability in Victor Barkalov Custom Links On Admin Dashboard Toolbar customize-wpadmin allows Stored XSS.This i… Mitigation only Fix from $1,9502025-02-07