Vulnerability index

Browse CVEs

7,373 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2024-45264 A cross-site request forgery (CSRF) vulnerability in the admin panel in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to add a new admin… Arfa Cms 5.1.3124+ Fix from $1,9502024-08-27 HIGH 8.8 CVE-2024-43325 Cross-Site Request Forgery (CSRF) vulnerability in Naiche Dark Mode for WP Dashboard.This issue affects Dark Mode for WP Dashboard: from n/a through … Dark Mode For Wp Dashboard 1.2.4+ Fix from $1,9502024-08-26 MEDIUM 6.1 CVE-2024-43339 Cross-Site Request Forgery (CSRF) vulnerability in WebinarPress allows Cross-Site Scripting (XSS).This issue affects WebinarPress: from n/a through 1… Webinarpress 1.33.21+ Fix from $1,6002024-08-26 HIGH 8.8 CVE-2024-43287 Cross-Site Request Forgery (CSRF) vulnerability in Brevo Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue.This issue affects Newsl… Newsletter\, Smtp\, Email Marketing And Subscribe 3.1.83+ Fix from $1,9502024-08-26 MEDIUM 5.4 CVE-2024-43299 Cross-Site Request Forgery (CSRF) vulnerability in Softaculous SpeedyCache speedycache.This issue affects SpeedyCache: from n/a through <= 1.1.8. Speedycache 1.1.9+ Fix from $1,6002024-08-26 MEDIUM 5.4 CVE-2024-43301 Cross-Site Request Forgery (CSRF) vulnerability in Fonts Plugin Fonts allows Stored XSS.This issue affects Fonts: from n/a through 3.7.7. Fonts 3.7.8+ Fix from $1,6002024-08-26 MEDIUM 6.1 CVE-2024-43255 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zookatron MyBookTable Bookstore mybooktable.Thi… Mybook Table Bookstore after 3.3.9 Fix from $1,6002024-08-26 HIGH 8.8 CVE-2024-39657 Cross-Site Request Forgery (CSRF) vulnerability in Sender Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce.This issue affects … Sender 2.6.19+ Fix from $1,9502024-08-26 HIGH 8.8 CVE-2024-43116 Cross-Site Request Forgery (CSRF) vulnerability in 10up Simple Local Avatars.This issue affects Simple Local Avatars: from n/a through 2.7.10. Simple Local Avatars 2.7.11+ Fix from $1,9502024-08-26 HIGH 8.8 CVE-2024-43117 Cross-Site Request Forgery (CSRF) vulnerability in WPMU DEV - Your All-in-One WordPress Platform Hummingbird hummingbird-performance.This issue affec… Hummingbird 3.9.2+ Fix from $1,9502024-08-26 HIGH 8.8 CVE-2024-39628 Cross-Site Request Forgery (CSRF) vulnerability in Saturday Drive Ninja Forms allows Cross Site Request Forgery.This issue affects Ninja Forms: from … Ninja Forms 3.8.7+ Fix from $1,9502024-08-26 HIGH 8.8 CVE-2024-39641 Cross-Site Request Forgery (CSRF) vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.6.8.2. Learnpress 4.2.6.9+ Fix from $1,9502024-08-26 HIGH 8.8 CVE-2024-39645 Cross-Site Request Forgery (CSRF) vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.7.2. Tutor Lms 2.7.3+ Fix from $1,9502024-08-26 HIGH 8.1 CVE-2024-7568 The Favicon Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5. This is due to missing … Favicon Generator 2.1+ Fix from $1,9502024-08-24 CRITICAL 9.4 CVE-2024-42764 Kashipara Bus Ticket Reservation System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via /deleteTicket.php. Bus Ticket Reservation System No fix yet Fix from $2,3002024-08-23 MEDIUM 6.8 CVE-2024-42768 A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Hotel Management System v1.0 via /admin/delete_room.php. Hotel Management System No fix yet Fix from $1,6002024-08-22 MEDIUM 5.0 CVE-2024-43787 Hono is a Web application framework that provides support for any JavaScript runtime. Hono CSRF middleware can be bypassed using crafted Content-Type… Hono 4.5.8+ Fix from $1,6002024-08-22 HIGH 8.8 CVE-2024-40886 Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to sanitize user inputs in the frontend that are used for r… Mattermost 9.5.8 / 9.8.3+ Fix from $1,9502024-08-22 MEDIUM 6.5 CVE-2024-42056 Retool (self-hosted enterprise) through 3.40.0 inserts resource authentication credentials into sent data. Credentials for users with "Use" permissio… Retool after 3.40.0 Fix from $1,6002024-08-22 HIGH 8.8 CVE-2024-20486 A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cond… Identity Services Engine 3.1+ Fix from $1,9502024-08-21 MEDIUM 6.1 CVE-2024-7647 The OTA Sync Booking Engine Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.7. This… Ota Sync Booking Engine Widget after 1.2.7 Fix from $1,6002024-08-21 HIGH 8.8 CVE-2024-42619 Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/domain_management.php?id=0&list=whitelist&rem… Pligg Cms No fix yet Fix from $1,9502024-08-20 HIGH 8.8 CVE-2024-42612 Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/domain_management.php?whitelist_add Pligg Cms No fix yet Fix from $1,9502024-08-20 HIGH 8.8 CVE-2024-42605 Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/edit_page.php?link_id=1 Pligg Cms No fix yet Fix from $1,9502024-08-20 HIGH 8.8 CVE-2024-42606 Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_log.php?clear=1 Pligg Cms No fix yet Fix from $1,9502024-08-20 HIGH 8.8 CVE-2024-42607 Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=database Pligg Cms No fix yet Fix from $1,9502024-08-20 HIGH 8.8 CVE-2024-42609 Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=avatars Pligg Cms No fix yet Fix from $1,9502024-08-20 HIGH 8.8 CVE-2024-42610 Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=files Pligg Cms No fix yet Fix from $1,9502024-08-20 HIGH 8.8 CVE-2024-42611 Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/admin_page.php?link_id=1&mode=delete Pligg Cms No fix yet Fix from $1,9502024-08-20 HIGH 8.8 CVE-2024-42613 Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_widgets.php?action=install&widget=akism… Pligg Cms No fix yet Fix from $1,9502024-08-20