Vulnerability index

Browse CVEs

7,362 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.3 CVE-2026-58518 Cross-Site request forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - RedirectManager Extension allows Cross Site Request Forgery. … Mediawiki 1.3.3+ Fix from $1,6002026-07-01 MEDIUM 6.5 CVE-2026-14016 Inappropriate implementation in SVG in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML pa… Chrome 150.0.7871.47+ Fix from $1,6002026-06-30 MEDIUM 6.5 CVE-2026-13887 Inappropriate implementation in NFC in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer pro… Chrome 150.0.7871.47+ Fix from $1,6002026-06-30 MEDIUM 6.5 CVE-2026-13826 Inappropriate implementation in Autofill in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the rendere… Chrome 150.0.7871.47+ Fix from $1,6002026-06-30 MEDIUM 5.1 CVE-2026-35096 KTM System e-BOK is vulnerable to Cross‑Site Request Forgery (CSRF) in both the email-change and password-change functionalities. An attacker can cra… Mitigation only Fix from $1,6002026-06-30 HIGH 8.1 CVE-2026-43735 The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, mac… Safari 26.5.2+ Fix from $1,9502026-06-29 MEDIUM 6.5 CVE-2026-31016 Cross Site Request Forgery vulnerability in Squidex.io Squidex CMS v.7.21.0 and before allows a remote attacker to escalate privileges via the Identi… Mitigation only Fix from $1,6002026-06-29 HIGH 7.3 CVE-2026-50132 Budibase is an open-source low-code platform. Prior to 3.39.0, `GET /api/chat-links/:instance/:token/handoff` is a public endpoint (no auth required)… Budibase 3.39.0+ Fix from $1,9502026-06-26 HIGH 8.8 CVE-2026-52784 OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a CSRF on TARGET through /users/:id via POST … Mitigation only Fix from $1,9502026-06-26 HIGH 8.8 CVE-2026-57659 Unauthenticated Cross Site Request Forgery (CSRF) in Paid Memberships Pro - Add Member From Admin <= 0.7.2 versions. Mitigation only Fix from $1,9502026-06-26 HIGH 8.2 CVE-2026-57655 Unauthenticated Cross Site Request Forgery (CSRF) in Child Theme Wizard <= 1.4 versions. Mitigation only Fix from $1,9502026-06-26 MEDIUM 6.5 CVE-2026-57635 Unauthenticated Cross Site Request Forgery (CSRF) in FunnelKit Payment Gateway for Stripe WooCommerce <= 1.14.0.3 versions. Mitigation only Fix from $1,6002026-06-26 MEDIUM 6.5 CVE-2026-57641 Unauthenticated Cross Site Request Forgery (CSRF) in Real Estate 7 <= 3.5.9 versions. Mitigation only Fix from $1,6002026-06-26 HIGH 8.8 CVE-2025-68052 Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking <= 1.3.4.3 versions. Mitigation only Fix from $1,9502026-06-26 HIGH 8.8 CVE-2026-52800 Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization team member management can be performed via GET requests without CSRF p… Patch available Fix from $1,9502026-06-24 HIGH 7.3 CVE-2026-12986 A critical vulnerability in Admin GUI in Payara Server Full 4.x, 5.x, 6.x, 7.x, 7.2026.x, 6.2025.x, 6.2024.x on All platforms that allows the attacke… Mitigation only Fix from $1,9502026-06-24 MEDIUM 5.4 CVE-2026-57305 A cross-site request forgery (CSRF) vulnerability in Jenkins Assembla Plugin 1.4 and earlier allows attackers to connect to an attacker-specified URL… Assembla after 1.4 Fix from $1,6002026-06-24 MEDIUM 5.4 CVE-2026-57292 A cross-site request forgery (CSRF) vulnerability in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attackers to connect to an attacke… Mitigation only Fix from $1,6002026-06-24 MEDIUM 5.4 CVE-2026-57295 A cross-site request forgery (CSRF) vulnerability in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier allows attackers to connect to an … Ec2 Fleet after 4.2.3.539.v8fedff2a_81c3 Fix from $1,6002026-06-24 MEDIUM 5.4 CVE-2026-57298 A cross-site request forgery (CSRF) vulnerability in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allows attackers to hav… Mitigation only Fix from $1,6002026-06-24 MEDIUM 6.1 CVE-2026-8905 The Osiris Signature Banner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5. This is due t… Mitigation only Fix from $1,6002026-06-24 CRITICAL 9.3 CVE-2026-49871 Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. This defect allows a remote attacker that manag… Apisix 3.17.0+ Fix from $2,3002026-06-19 MEDIUM 6.5 CVE-2026-56024 Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal WP EasyPay allows Cross Site Request Forgery. This issue affects WP EasyPay: from n/a … Mitigation only Fix from $1,6002026-06-18 HIGH 8.6 CVE-2026-54220 uBB.threads is vulnerable to a Cross-Site Request Forgery (CSRF) due to a lack of protective mechanisms. This allows an attacker to trick an authenti… Mitigation only Fix from $1,9502026-06-18 CRITICAL 9.6 CVE-2026-55742 Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration rights handler. In system/admin/admi… Mitigation only Fix from $2,3002026-06-18 HIGH 8.1 CVE-2026-55744 Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage (PFS) module. In modules/pfs/… Mitigation only Fix from $1,9502026-06-18 MEDIUM 5.4 CVE-2026-55745 Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage (PFS) module. In modules/pfs/… Mitigation only Fix from $1,6002026-06-18 HIGH 8.8 CVE-2026-55741 Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration configuration handler. In system/adm… Mitigation only Fix from $1,9502026-06-18 MEDIUM 6.9 CVE-2026-9591 Cross-site request forgery (CSRF) in NewsItemApiController in SimplCommerce prior to commit 6233d73e allows an unauthenticated remote attacker to cre… Patch available Fix from $1,6002026-06-17 HIGH 8.8 CVE-2026-22342 Unauthenticated Cross Site Request Forgery (CSRF) in WordPress Dating Theme <= 11.2.0 versions. Mitigation only Fix from $1,9502026-06-17