Vulnerability index

Browse CVEs

7,362 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
MEDIUM 6.5 CVE-2026-42073 OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the OpenClaude MCP auth… Openclaude 0.5.1+ Fix from $1,6002026-06-02 MEDIUM 5.4 CVE-2026-34460 NamelessMC is website software for Minecraft servers. In versions 2.2.4 and prior, the OAuth callback handling does not validate the state parameter … Mitigation only Fix from $1,6002026-06-02 MEDIUM 5.3 CVE-2018-25435 ZeusCart 4.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of victims by crafti… No fix yet Fix from $1,6002026-06-01 MEDIUM 5.0 CVE-2026-49433 The DeepAI endpoint 'https://api.deepai.org/change_user_email' accepts POST requests without any CSRF protection. If an attacker can trick a logged-i… Mitigation only Fix from $1,6002026-06-01 MEDIUM 5.1 CVE-2026-40549 SOPlanning is vulnerable to Cross‑Site Request Forgery (CSRF) in groupe_save create, modify and delete endpoints. An attacker can craft a malicious w… Mitigation only Fix from $1,6002026-06-01 MEDIUM 5.3 CVE-2018-25397 PHP-SHOP 1.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to add administrative users by crafting malici… No fix yet Fix from $1,6002026-05-29 MEDIUM 5.3 CVE-2018-25387 HaPe PKH 1.1 contains a cross-site request forgery vulnerability that allows attackers to change administrator passwords by submitting forged request… No fix yet Fix from $1,6002026-05-29 MEDIUM 6.5 CVE-2026-45610 WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cross-site request forgery vulnerability on the 2FA toggle. plugin/Logi… Avideo after 29.0 Fix from $1,6002026-05-29 HIGH 8.1 CVE-2026-6075 The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.35 This is due to mi… Mitigation only Fix from $1,9502026-05-29 HIGH 7.9 CVE-2026-35266 Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Difficult to exploit vulnerabi… Rest Data Services after 26.1.0 Fix from $1,9502026-05-28 HIGH 8.1 CVE-2026-6455 The WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Deletion via SQL Injectio… Mitigation only Fix from $1,9502026-05-28 MEDIUM 6.5 CVE-2026-48147 Budibase is an open-source low-code platform. Prior to 3.35.4, the buildMatcherRegex() / matches() functions in packages/backend-core/src/middleware/… Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.3 CVE-2026-30498 A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the delete.php endpoint of Jason2605 AdminPanel 4.0. Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.1 CVE-2026-8906 The WP Promoter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing or… Mitigation only Fix from $1,6002026-05-27 MEDIUM 5.3 CVE-2026-49001 Cross-site request forgery (CSRF) vulnerabilities allow attackers to exploit a user's authenticated session to forge cross-site requests, inducing th… Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.1 CVE-2026-8911 The WP AutoBuzz plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.1. This is due to missing … Mitigation only Fix from $1,6002026-05-27 MEDIUM 6.5 CVE-2026-46620 e107 is a content management system (CMS). Prior to 2.3.5, e107 CMS does not properly enforce CSRF token validation on comment moderation actions. Th… Mitigation only Fix from $1,6002026-05-26 MEDIUM 5.7 CVE-2026-8174 Zohocorp Zoho Mail wordpress plugin is vulnerable to Cross-Site request forgery (CSRF). This issue affects Zoho Mail wordpress plugin versions befor… Mitigation only Fix from $1,6002026-05-26 HIGH 7.1 CVE-2026-39436 Cross-Site Request Forgery (CSRF) vulnerability in bgermann CformsII allows Cross Site Request Forgery. This issue affects CformsII: from n/a throug… Mitigation only Fix from $1,9502026-05-25 MEDIUM 6.5 CVE-2026-24574 Cross-Site Request Forgery (CSRF) vulnerability in Recorp Export WP Page to Static HTML/CSS allows Cross Site Request Forgery. This issue affects Ex… Mitigation only Fix from $1,6002026-05-25 MEDIUM 5.3 CVE-2018-25370 Admidio 3.3.5 contains a cross-site request forgery vulnerability that allows low-privilege users to increase their permissions by exploiting imprope… No fix yet Fix from $1,6002026-05-25 HIGH 7.1 CVE-2026-41074 RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 through 6.0.2 contain a Cross-Site Request Forgery (CSRF) vul… Mitigation only Fix from $1,9502026-05-22 MEDIUM 6.5 CVE-2026-8435 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file approveVersion(). The Concrete CM… Concrete Cms 9.5.1+ Fix from $1,6002026-05-21 HIGH 8.8 CVE-2026-8413 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design. The Concrete CMS secu… Concrete Cms 9.5.1+ Fix from $1,9502026-05-21 HIGH 8.8 CVE-2026-8414 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/duplicate. The Concrete CMS secur… Concrete Cms 9.5.1+ Fix from $1,9502026-05-21 HIGH 8.8 CVE-2026-8415 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/association/reorder. The Concre… Concrete Cms 9.5.1+ Fix from $1,9502026-05-21 HIGH 8.8 CVE-2026-8416 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addFavoriteFolder($id). The Concr… Concrete Cms 9.5.1+ Fix from $1,9502026-05-21 HIGH 8.8 CVE-2026-8427 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file removeFavoriteFolder($id). The Co… Concrete Cms 9.5.1+ Fix from $1,9502026-05-21 HIGH 8.8 CVE-2026-8432 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star(). The Concrete CMS security… Concrete Cms 9.5.1+ Fix from $1,9502026-05-21 HIGH 8.8 CVE-2026-8433 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescan(). The Concrete CMS securi… Concrete Cms 9.5.1+ Fix from $1,9502026-05-21