Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2024-27948 Cross-Site Request Forgery (CSRF) vulnerability in bytesforall Atahualpa.This issue affects Atahualpa: from n/a through 3.7.24. Atahualpa after 3.7.24 Fix from $1,9502024-02-28 MEDIUM 6.1 CVE-2023-51533 Cross-Site Request Forgery (CSRF) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart.This issue affects Ecwid Ecommerce Shopping Cart: fr… Ecwid Ecommerce Shopping Cart 6.12.5+ Fix from $1,6002024-02-28 HIGH 8.8 CVE-2023-52226 Cross-Site Request Forgery (CSRF) vulnerability in Advanced Flamingo.This issue affects Advanced Flamingo: from n/a through 1.0. Advanced Flamingo after 1.0 Fix from $1,9502024-02-28 HIGH 8.8 CVE-2024-21749 Cross-Site Request Forgery (CSRF) vulnerability in Atakan Au 1 click disable all.This issue affects 1 click disable all: from n/a through 1.0.1. Click Disable All after 1.0.1 Fix from $1,9502024-02-28 MEDIUM 6.5 CVE-2023-51681 Cross-Site Request Forgery (CSRF) vulnerability in Duplicator Duplicator – WordPress Migration & Backup Plugin.This issue affects Duplicator – WordPr… Mitigation only Fix from $1,6002024-02-28 HIGH 8.8 CVE-2023-51683 Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Easy PayPal & Stripe Buy Now Button.This issue affects Easy PayPal & Stripe Buy Now… Easy Paypal \& Stripe Buy Now Button 1.8.2+ Fix from $1,9502024-02-28 HIGH 8.8 CVE-2023-52223 Cross-Site Request Forgery (CSRF) vulnerability in MailerLite MailerLite – WooCommerce integration.This issue affects MailerLite – WooCommerce integr… Mailerlite 2.0.9+ Fix from $1,9502024-02-28 HIGH 8.8 CVE-2024-24702 Cross-Site Request Forgery (CSRF) vulnerability in Matt Martz & Andy Stratton Page Restrict.This issue affects Page Restrict: from n/a through 2.5.5. Pagerestrict after 2.5.5 Fix from $1,9502024-02-28 MEDIUM 5.4 CVE-2024-24705 Cross-Site Request Forgery (CSRF) vulnerability in Octa Code Accessibility.This issue affects Accessibility: from n/a through 1.0.6. Mitigation only Fix from $1,6002024-02-28 MEDIUM 6.3 CVE-2024-1954 The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ… Oliver Pos 2.4.1.9+ Fix from $1,6002024-02-28 MEDIUM 6.1 CVE-2023-7202 The Fatal Error Notify WordPress plugin before 1.5.3 does not have authorisation and CSRF checks in its test_error AJAX action, allowing any authenti… Fatal Error Notify 1.5.3+ Fix from $1,6002024-02-27 MEDIUM 6.1 CVE-2023-7203 The Smart Forms WordPress plugin before 2.6.87 does not have authorisation in various AJAX actions, which could allow users with a role as low as sub… Smart Forms 2.6.87+ Fix from $1,6002024-02-27 HIGH 8.8 CVE-2023-36237 Cross Site Request Forgery vulnerability in Bagisto before v.1.5.1 allows an attacker to execute arbitrary code via a crafted HTML script. Bagisto 1.5.1+ Fix from $1,9502024-02-26 HIGH 8.8 CVE-2024-1889 Cross-Site Request Forgery vulnerability in SMA Cluster Controller, affecting version 01.05.01.R. This vulnerability could allow an attacker to send … Clcon 10 Firmware Mitigation only Fix from $1,9502024-02-26 HIGH 8.8 CVE-2024-26350 flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_contact_form_settings.php Flusity No fix yet Fix from $1,9502024-02-22 MEDIUM 6.1 CVE-2024-26351 flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_place.php Flusity Mitigation only Fix from $1,6002024-02-22 HIGH 8.8 CVE-2024-26352 flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/add_places.php Flusity No fix yet Fix from $1,9502024-02-22 MEDIUM 6.1 CVE-2024-26445 flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_place.php Flusity No fix yet Fix from $1,6002024-02-22 HIGH 8.8 CVE-2024-23094 Flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /cover/addons/info_media_gallery/action/edit_addon_… Flusity Mitigation only Fix from $1,9502024-02-22 HIGH 8.8 CVE-2024-24802 Cross-Site Request Forgery (CSRF) vulnerability in John Tendik JTRT Responsive Tables.This issue affects JTRT Responsive Tables: from n/a through 4.1… Jtrt Responsive Tables after 4.1.9 Fix from $1,9502024-02-21 HIGH 8.8 CVE-2024-24798 Cross-Site Request Forgery (CSRF) vulnerability in SoniNow Team Debug.This issue affects Debug: from n/a through 1.10. Debug 1.11+ Fix from $1,9502024-02-21 MEDIUM 5.4 CVE-2024-25905 Cross-Site Request Forgery (CSRF) vulnerability in Mondula GmbH Multi Step Form.This issue affects Multi Step Form: from n/a through 1.7.18. Multi Step Form 1.7.19+ Fix from $1,6002024-02-21 HIGH 8.8 CVE-2024-24876 Cross-Site Request Forgery (CSRF) vulnerability in Janis Elsts Admin Menu Editor.This issue affects Admin Menu Editor: from n/a through 1.12. Admin Menu Editor 1.12.1+ Fix from $1,9502024-02-21 HIGH 8.8 CVE-2024-25904 Cross-Site Request Forgery (CSRF) vulnerability in David Stockl TinyMCE and TinyMCE Advanced Professsional Formats and Styles.This issue affects Tiny… Tinymce And Tinymce Advanced Professsional Formats And Styles after 1.1.2 Fix from $1,9502024-02-21 HIGH 8.8 CVE-2024-24849 Cross-Site Request Forgery (CSRF) vulnerability in Mark Stockton Quicksand Post Filter jQuery Plugin.This issue affects Quicksand Post Filter jQuery … Quicksand Post Filter Jquery after 3.1.1 Fix from $1,9502024-02-21 HIGH 8.8 CVE-2024-24872 Cross-Site Request Forgery (CSRF) vulnerability in Themify Themify Builder.This issue affects Themify Builder: from n/a through 7.0.5. Builder 7.0.6+ Fix from $1,9502024-02-21 HIGH 8.8 CVE-2024-24843 Cross-Site Request Forgery (CSRF) vulnerability in PowerPack Addons for Elementor PowerPack Pro for Elementor.This issue affects PowerPack Pro for El… Powerpack Addons For Elementor after 2.10.8 Fix from $1,9502024-02-21 HIGH 8.8 CVE-2021-29050 Cross-Site Request Forgery (CSRF) vulnerability in the terms of use page in Liferay Portal before 7.3.6, and Liferay DXP 7.3 before service pack 1, 7… Mitigation only Fix from $1,9502024-02-20 MEDIUM 5.7 CVE-2023-47635 Decidim is a participatory democracy framework. Starting in version 0.23.0 and prior to versions 0.27.5 and 0.28.0, the CSRF authenticity token check… Decidim 0.27.5+ Fix from $1,6002024-02-20 HIGH 8.8 CVE-2024-25982 The link to update all installed language packs did not include the necessary token to prevent a CSRF risk. Moodle 4.1.9 / 4.2.6+ Fix from $1,9502024-02-19