Vulnerability index

Browse CVEs

7,362 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
CRITICAL 9.1 CVE-2026-26718 A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an attacker to perform unauthorized… Mitigation only Fix from $2,3002026-07-15 HIGH 8.3 CVE-2026-20296 In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.7, 10.3.2512.… Splunk 9.4.13 / 10.0.8+ Fix from $1,9502026-07-15 HIGH 8.3 CVE-2026-47158 Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO authorization flow did not bind the OAuth state para… Mitigation only Fix from $1,9502026-07-15 HIGH 7.5 CVE-2026-52100 Cross Site Request Forgery vulnerability in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to execute arbitrary code via the… Mitigation only Fix from $1,9502026-07-14 CRITICAL 9.1 CVE-2026-15747 Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle. _csrf_t… Mitigation only Fix from $2,3002026-07-14 HIGH 8.1 CVE-2026-58476 Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a cross-site request forgery vulnerability that allows remote attackers to perf… Sustainable Irrigation Platform after 5.2.16 Fix from $1,9502026-07-14 MEDIUM 6.8 CVE-2026-58489 HedgeDoc is an open source, real-time collaborative markdown notes application. Prior to 1.11.0, the GitHub Gist export flow created an OAuth2  state… Patch available Fix from $1,6002026-07-13 HIGH 7.1 CVE-2026-61956 Cross-Site Request Forgery (CSRF) vulnerability in hamsalam ووسلام &#8211; همگام سازی ووکامرس و باسلام sync-basalam allows Cross Site Request Forgery… Mitigation only Fix from $1,9502026-07-13 HIGH 8.8 CVE-2026-57786 Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core workscout-core allows Authentication Bypass.This issue affects WorkScout… Mitigation only Fix from $1,9502026-07-13 HIGH 8.1 CVE-2026-38057 The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests … Mitigation only Fix from $1,9502026-07-10 HIGH 8.8 CVE-2026-15070 The Salon Booking System – Free Version plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 10.30.… Mitigation only Fix from $1,9502026-07-10 MEDIUM 5.3 CVE-2026-44342 New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the email and WeCha… New Api 0.12.0+ Fix from $1,6002026-07-09 HIGH 8.8 CVE-2026-58143 Cotonti Siena 0.9.26 and earlier contains a cross-site request forgery vulnerability that allows unauthenticated attackers to modify administrator co… Mitigation only Fix from $1,9502026-07-09 HIGH 8.8 CVE-2026-59148 Mockoon provides way to design and run mock APIs. Prior to 9.7.0, Mockoon's admin API in commons-server/src/libs/server/admin-api.ts is mounted on th… Patch available Fix from $1,9502026-07-09 HIGH 8.8 CVE-2026-4275 The Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… Mitigation only Fix from $1,9502026-07-09 MEDIUM 6.0 CVE-2026-5923 Malicious use of a stolen cookie might allow modifications to the contents of the IP phone’s webpage. No fix yet Fix from $1,6002026-07-08 HIGH 8.3 CVE-2026-49471 Serena is a powerful MCP toolkit for coding that provides semantic retrieval and editing capabilities. Prior to v1.5.2, Serena's built-in web dashboa… Serena 1.5.2+ Fix from $1,9502026-07-07 HIGH 8.0 CVE-2026-34171 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the GET /invitations/{uu… Patch available Fix from $1,9502026-07-07 HIGH 8.1 CVE-2026-59713 Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without validating state parameters.… Patch available Fix from $1,9502026-07-06 HIGH 8.1 CVE-2026-12740 Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter. RequestTokenV2 builds the provider authorizati… Patch available Fix from $1,9502026-07-04 HIGH 8.1 CVE-2026-12746 Dancer2::Plugin::Auth::OAuth::Provider versions before 0.23 for Perl do not support the OAuth 2.0 state parameter. The authentication_url method bui… Patch available Fix from $1,9502026-07-04 HIGH 7.1 CVE-2026-57761 Unauthenticated Cross Site Request Forgery (CSRF) in SEOWP <= 3.12.2 versions. Mitigation only Fix from $1,9502026-07-02 HIGH 8.8 CVE-2026-57766 Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor <= 3.5.6 versions. Mitigation only Fix from $1,9502026-07-02 HIGH 7.1 CVE-2026-57757 Unauthenticated Cross Site Request Forgery (CSRF) in pCloud WP Backup <= 2.0.2 versions. Mitigation only Fix from $1,9502026-07-02 HIGH 7.1 CVE-2026-57758 Unauthenticated Cross Site Request Forgery (CSRF) in Permalink Manager for WooCommerce <= 1.0.8.2 versions. Mitigation only Fix from $1,9502026-07-02 HIGH 8.8 CVE-2026-57759 Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid <= 5.9.9.7 versions. Mitigation only Fix from $1,9502026-07-02 MEDIUM 6.5 CVE-2026-57747 Unauthenticated Cross Site Request Forgery (CSRF) in Booked <= 3.0.0 versions. Mitigation only Fix from $1,6002026-07-02 HIGH 8.1 CVE-2026-57751 Unauthenticated Cross Site Request Forgery (CSRF) in Heateor Social Login <= 1.1.39 versions. Mitigation only Fix from $1,9502026-07-02 HIGH 7.4 CVE-2026-57723 Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Path Traversal. This issue affects VikBooki… Mitigation only Fix from $1,9502026-07-01 HIGH 8.8 CVE-2026-12158 The RegistrationMagic – User Registration Forms Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… Mitigation only Fix from $1,9502026-07-01