Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 5.4 CVE-2025-23985 Cross-Site Request Forgery (CSRF) vulnerability in brainvireinfo Dynamic URL SEO dynamic-url-seo allows Cross Site Request Forgery.This issue affects… Mitigation only Fix from $1,6002025-01-31 HIGH 7.1 CVE-2025-23989 Cross-Site Request Forgery (CSRF) vulnerability in Alessandro Piconi Internal Link Builder internal-link-builder allows Cross Site Request Forgery.Th… Mitigation only Fix from $1,9502025-01-31 HIGH 7.1 CVE-2025-23990 Cross-Site Request Forgery (CSRF) vulnerability in jablonczay Scroll Styler scroll-styler.This issue affects Scroll Styler: from n/a through <= 1.1. Mitigation only Fix from $1,9502025-01-31 HIGH 7.1 CVE-2025-23976 Cross-Site Request Forgery (CSRF) vulnerability in operationsissuu Issuu Panel issuu-panel allows Stored XSS.This issue affects Issuu Panel: from n/a… Mitigation only Fix from $1,9502025-01-31 HIGH 7.1 CVE-2025-23977 Cross-Site Request Forgery (CSRF) vulnerability in Bhaskar Dhote Post Carousel Slider post-carousel-slider allows Stored XSS.This issue affects Post … Mitigation only Fix from $1,9502025-01-31 HIGH 7.1 CVE-2025-23978 Cross-Site Request Forgery (CSRF) vulnerability in Ninos FlashCounter flashcounter allows Stored XSS.This issue affects FlashCounter: from n/a throug… Mitigation only Fix from $1,9502025-01-31 HIGH 7.1 CVE-2025-23980 Cross-Site Request Forgery (CSRF) vulnerability in James Andrews Full Circle full-circle allows Stored XSS.This issue affects Full Circle: from n/a t… Mitigation only Fix from $1,9502025-01-31 HIGH 8.8 CVE-2024-1211 An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.6 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and sta… GitLab 16.9.7 / 16.10.5+ Fix from $1,9502025-01-31 HIGH 8.1 CVE-2024-13707 The WP Image Uploader plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to mi… Wp Image Uploader after 1.0.1 Fix from $1,9502025-01-30 CRITICAL 9.1 CVE-2024-13720 The WP Image Uploader plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the gky_image_uploade… Wp Image Uploader after 1.0.1 Fix from $2,3002025-01-30 MEDIUM 5.4 CVE-2024-13512 The Wonder FontAwesome plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.8. This is due to mis… Wonder Fontawesome after 0.8 Fix from $1,6002025-01-30 MEDIUM 6.5 CVE-2024-13758 The CP Contact Form with PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.52. This i… Cp Contact Form 1.3.53+ Fix from $1,6002025-01-30 HIGH 8.8 CVE-2024-54851 Teedy <= 1.12 is vulnerable to Cross Site Request Forgery (CSRF), due to the lack of CSRF protection. Teedy after 1.12 Fix from $1,9502025-01-29 MEDIUM 5.4 CVE-2024-13521 The MailUp Auto Subscription plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is du… Mailup Auto Subscription 1.2.0+ Fix from $1,6002025-01-28 HIGH 8.1 CVE-2024-57373 Cross Site Request Forgery (CSRF) vulnerability in LifestyleStore v1.0 allows a remote attacker to execute unauthorized actions on behalf of an authe… Mitigation only Fix from $1,9502025-01-27 HIGH 8.8 CVE-2024-48418 In Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06, the request /goform/fromSetDDNS does not properly handle special characters in any of user … Br 6476ac Firmware No fix yet Fix from $1,9502025-01-27 HIGH 8.8 CVE-2025-24742 Cross-Site Request Forgery (CSRF) vulnerability in WPGMaps WP Go Maps wp-google-maps.This issue affects WP Go Maps: from n/a through <= 9.0.40. Wp Go Maps 9.0.41+ Fix from $1,9502025-01-27 MEDIUM 5.4 CVE-2025-24537 Cross-Site Request Forgery (CSRF) vulnerability in StellarWP The Events Calendar the-events-calendar allows Cross Site Request Forgery.This issue aff… Mitigation only Fix from $1,6002025-01-27 MEDIUM 5.4 CVE-2025-24538 Cross-Site Request Forgery (CSRF) vulnerability in Slava Abakumov BuddyPress Groups Extras buddypress-groups-extras allows Cross Site Request Forgery… Mitigation only Fix from $1,6002025-01-27 MEDIUM 5.4 CVE-2025-24533 Cross-Site Request Forgery (CSRF) vulnerability in MetaSlider Responsive Slider by MetaSlider ml-slider allows Cross Site Request Forgery.This issue … Mitigation only Fix from $1,6002025-01-27 HIGH 7.1 CVE-2024-13057 The Dyn Business Panel WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which… Dyn Business Panel No fix yet Fix from $1,9502025-01-27 MEDIUM 6.5 CVE-2024-12774 The Altra Side Menu WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins delet… Altra Side Menu after 2.0 Fix from $1,6002025-01-27 HIGH 8.8 CVE-2024-11641 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.… Vikbooking Hotel Booking Engine \& Pms 1.7.3+ Fix from $1,9502025-01-26 HIGH 7.1 CVE-2025-24756 Cross-Site Request Forgery (CSRF) vulnerability in mgplugin Roi Calculator roi-calculator allows Stored XSS.This issue affects Roi Calculator: from n… Mitigation only Fix from $1,9502025-01-24 MEDIUM 5.4 CVE-2025-24724 Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Side Menu Lite side-menu-lite allows Cross Site Request Forgery.This issue affects Sid… Mitigation only Fix from $1,6002025-01-24 MEDIUM 5.4 CVE-2025-24716 Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Herd Effects mwp-herd-effect allows Cross Site Request Forgery.This issue affects Herd… Mitigation only Fix from $1,6002025-01-24 HIGH 8.8 CVE-2025-24717 Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Modal Window modal-window allows Cross Site Request Forgery.This issue affects Modal W… Modal Window 6.1.5+ Fix from $1,9502025-01-24 MEDIUM 5.4 CVE-2025-24720 Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Sticky Buttons sticky-buttons allows Cross Site Request Forgery.This issue affects Sti… Mitigation only Fix from $1,6002025-01-24 MEDIUM 5.4 CVE-2025-24711 Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Popup Box popup-box allows Cross Site Request Forgery.This issue affects Popup Box: fr… Mitigation only Fix from $1,6002025-01-24 MEDIUM 5.4 CVE-2025-24712 Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme Radius Blocks radius-blocks allows Cross Site Request Forgery.This issue affects Radiu… Mitigation only Fix from $1,6002025-01-24