Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.1 CVE-2024-12557 The Transporters.io plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.1. This is due to miss… Mitigation only Fix from $1,6002025-01-07 HIGH 8.1 CVE-2024-55076 Grocy through 4.3.0 has no CSRF protection, as demonstrated by changing the Administrator's password. Grocy after 4.3.0 Fix from $1,9502025-01-06 MEDIUM 6.1 CVE-2024-12279 The WP Social AutoConnect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6.2. This is due t… Wp Social Autoconnect 4.6.3+ Fix from $1,6002025-01-04 MEDIUM 5.4 CVE-2024-12545 The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin for WordPress is vulnerable … Scratch \& Win 2.8.0+ Fix from $1,6002025-01-04 MEDIUM 5.4 CVE-2024-37925 Cross-Site Request Forgery (CSRF) vulnerability in BUDDYBOSS LLC BuddyBoss Theme allows Cross Site Request Forgery.This issue affects BuddyBoss Theme… Mitigation only Fix from $1,6002025-01-02 MEDIUM 5.4 CVE-2024-37438 Cross-Site Request Forgery (CSRF) vulnerability in Uncanny Owl Uncanny Toolkit Pro for LearnDash allows Cross Site Request Forgery.This issue affects… Mitigation only Fix from $1,6002025-01-02 HIGH 8.8 CVE-2024-39623 Cross-Site Request Forgery (CSRF) vulnerability in CridioStudio ListingPro listingpro allows Authentication Bypass.This issue affects ListingPro: fro… Listingpro 2.9.5+ Fix from $1,9502025-01-02 MEDIUM 5.4 CVE-2024-38789 Cross-Site Request Forgery (CSRF) vulnerability in Marco Milesi Telegram Bot & Channel telegram-bot allows Cross Site Request Forgery.This issue affe… Mitigation only Fix from $1,6002025-01-02 MEDIUM 6.5 CVE-2024-38790 Cross-Site Request Forgery (CSRF) vulnerability in Smartsupp Smartsupp – live chat, chatbots, AI and lead generation smartsupp-live-chat allows Cross… Mitigation only Fix from $1,6002025-01-02 HIGH 8.8 CVE-2024-37937 Cross-Site Request Forgery (CSRF) vulnerability in raratheme Rara Business rara-business allows Cross Site Request Forgery.This issue affects Rara Bu… Rara Business 1.2.6+ Fix from $1,9502025-01-02 MEDIUM 5.4 CVE-2024-38729 Cross-Site Request Forgery (CSRF) vulnerability in mbeelink MBE eShip mail-boxes-etc allows Cross Site Request Forgery.This issue affects MBE eShip: … Mitigation only Fix from $1,6002025-01-02 HIGH 8.8 CVE-2024-37503 Cross-Site Request Forgery (CSRF) vulnerability in raratheme Lawyer Landing Page lawyer-landing-page allows Cross Site Request Forgery.This issue aff… Lawyer Landing Page 1.2.5+ Fix from $1,9502025-01-02 HIGH 8.8 CVE-2024-37508 Cross-Site Request Forgery (CSRF) vulnerability in raratheme Construction Landing Page construction-landing-page allows Cross Site Request Forgery.Th… Construction Landing Page 1.3.6+ Fix from $1,9502025-01-02 HIGH 8.8 CVE-2024-37450 Cross-Site Request Forgery (CSRF) vulnerability in raratheme Benevolent benevolent allows Cross Site Request Forgery.This issue affects Benevolent: f… Benevolent 1.3.5+ Fix from $1,9502025-01-02 HIGH 8.8 CVE-2024-37451 Cross-Site Request Forgery (CSRF) vulnerability in raratheme Travel Agency travel-agency allows Cross Site Request Forgery.This issue affects Travel … Travel Agency 1.5.0+ Fix from $1,9502025-01-02 HIGH 8.8 CVE-2024-37469 Cross-Site Request Forgery (CSRF) vulnerability in creativethemeshq Blocksy blocksy allows Cross Site Request Forgery.This issue affects Blocksy: fro… Blocksy 2.0.23+ Fix from $1,9502025-01-02 HIGH 8.8 CVE-2024-37435 Cross-Site Request Forgery (CSRF) vulnerability in raratheme Perfect Portfolio perfect-portfolio allows Cross Site Request Forgery.This issue affects… Perfect Portfolio 1.2.1+ Fix from $1,9502025-01-02 HIGH 8.8 CVE-2024-37412 Cross-Site Request Forgery (CSRF) vulnerability in blossomthemes Blossom Shop blossom-shop allows Cross Site Request Forgery.This issue affects Bloss… Blossom Shop 1.1.8+ Fix from $1,9502025-01-02 HIGH 8.8 CVE-2024-37093 Cross-Site Request Forgery (CSRF) vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Cross Site Request Forg… Masterstudy Lms 3.2.2+ Fix from $1,9502025-01-02 HIGH 8.8 CVE-2024-37102 Cross-Site Request Forgery (CSRF) vulnerability in blossomthemes Vilva vilva allows Cross Site Request Forgery.This issue affects Vilva: from n/a thr… Vilva 1.2.3+ Fix from $1,9502025-01-02 HIGH 8.8 CVE-2024-56203 Cross-Site Request Forgery (CSRF) vulnerability in gholme4 Wayne Audio Player wayne-audio-player allows Privilege Escalation.This issue affects Wayne… Mitigation only Fix from $1,9502024-12-31 HIGH 8.8 CVE-2024-56204 Cross-Site Request Forgery (CSRF) vulnerability in yonisink Sinking Dropdowns sinking-dropdowns allows Privilege Escalation.This issue affects Sinkin… Mitigation only Fix from $1,9502024-12-31 HIGH 8.8 CVE-2024-56206 Cross-Site Request Forgery (CSRF) vulnerability in krishankakkar gap-hub-user-role gap-hub-user-role allows Authentication Bypass.This issue affects … Mitigation only Fix from $1,9502024-12-31 HIGH 8.8 CVE-2024-56207 Cross-Site Request Forgery (CSRF) vulnerability in EditionGuard EditionGuard for WooCommerce – eBook Sales with DRM editionguard-for-woocommerce-eboo… Mitigation only Fix from $1,9502024-12-31 HIGH 7.1 CVE-2024-56232 Cross-Site Request Forgery (CSRF) vulnerability in Alex Volkov WP Nice Loader wp-nice-loader allows Stored XSS.This issue affects WP Nice Loader: fro… Mitigation only Fix from $1,9502024-12-31 MEDIUM 5.4 CVE-2024-56222 Cross-Site Request Forgery (CSRF) vulnerability in CodeBard CodeBard Help Desk codebard-help-desk allows Cross Site Request Forgery.This issue affect… Codebard Help Desk 1.1.2+ Fix from $1,6002024-12-31 HIGH 8.8 CVE-2024-56310 REDCap through 14.9.6 has a security flaw in the Project Dashboards name, exposing users to a Cross-Site Request Forgery (CSRF) attack. An attacker c… Redcap after 14.9.6 Fix from $1,9502024-12-22 HIGH 8.8 CVE-2024-56311 REDCap through 14.9.6 has a security flaw in the Notes section of calendar events, exposing users to a Cross-Site Request Forgery (CSRF) attack. An a… Redcap after 14.9.6 Fix from $1,9502024-12-22 HIGH 8.8 CVE-2024-12771 The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… Mitigation only Fix from $1,9502024-12-21 MEDIUM 6.1 CVE-2024-11607 The GTPayment Donations WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, whic… Gtpayment Donations after 1.0.0 Fix from $1,6002024-12-21