Vulnerability index

Browse CVEs

7,362 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2026-8434 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescanMultiple(). The Concrete CM… Concrete Cms 9.5.1+ Fix from $1,9502026-05-21 HIGH 8.8 CVE-2026-8409 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delete.  The The Concrete CMS secu… Concrete Cms 9.5.1+ Fix from $1,9502026-05-21 HIGH 8.8 CVE-2026-8410 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/delete.  The The Concrete CMS… Concrete Cms 9.5.1+ Fix from $1,9502026-05-21 HIGH 8.8 CVE-2026-8411 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/delete. The Concrete CMS secu… Concrete Cms 9.5.1+ Fix from $1,9502026-05-21 HIGH 8.8 CVE-2026-8412 Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/cache. The Concrete CMS secu… Concrete Cms 9.5.1+ Fix from $1,9502026-05-21 HIGH 8.8 CVE-2026-8421 Concrete CMS 9.5.0 and below contains a CSRF vulnerability in the install_package() method of concrete/controllers/single_page/dashboard/extend/insta… Concrete Cms 9.5.1+ Fix from $1,9502026-05-21 HIGH 8.8 CVE-2026-8426 Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/prepare_remote_upgrade/<remoteMPID… Concrete Cms 9.5.1+ Fix from $1,9502026-05-21 HIGH 8.8 CVE-2026-8428 Concrete CMS 9.5.0 and below emits a CSRF token in the local_available_update.php view ($token->output('do_update')) but the corresponding do_update(… Concrete Cms 9.5.1+ Fix from $1,9502026-05-21 MEDIUM 6.5 CVE-2026-8140 Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/install/download/<remoteId>. The download… Concrete Cms after 9.5.0 Fix from $1,6002026-05-21 HIGH 8.8 CVE-2026-8417 Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/do_update/<pkgHandle>. The do_upda… Concrete Cms 9.5.1+ Fix from $1,9502026-05-21 MEDIUM 6.1 CVE-2026-22880 Mattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to properly validate the SSO authentication callback origin w… Mattermost Mobile 2.37.1+ Fix from $1,6002026-05-21 HIGH 8.8 CVE-2026-44925 Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to force the user with an active se… Infoscale Operations Manager 9.1.3+ Fix from $1,9502026-05-20 HIGH 8.0 CVE-2025-11954 Cross-Site request forgery (CSRF) vulnerability in Sitemio Information Technologies Trade Ltd. Co. WISECP allows Cross Site Request Forgery. This is… Mitigation only Fix from $1,9502026-05-20 MEDIUM 6.1 CVE-2026-8420 The BLOGCHAT Chat System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.6.3. This is due … Mitigation only Fix from $1,6002026-05-20 MEDIUM 6.1 CVE-2026-6391 The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl… Mitigation only Fix from $1,6002026-05-20 MEDIUM 6.1 CVE-2026-6395 The Word 2 Cash plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting in versions up to and includi… Mitigation only Fix from $1,6002026-05-20 HIGH 8.8 CVE-2026-8604 In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a victim's session by luring any l… Scadabr Mitigation only Fix from $1,9502026-05-19 MEDIUM 5.4 CVE-2018-25334 Zechat 1.5 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows an attacker to change a user's information by bypassing anti-CSRF p… No fix yet Fix from $1,6002026-05-17 MEDIUM 5.3 CVE-2018-25336 jCart for OpenCart 2.3.0.2 contains a cross-site request forgery vulnerability that allows attackers to modify user account information without authe… No fix yet Fix from $1,6002026-05-17 MEDIUM 5.3 CVE-2018-25327 Joomla! Component Js Jobs 1.2.0 contains a cross-site request forgery vulnerability that allows attackers to perform state-changing actions without t… No fix yet Fix from $1,6002026-05-17 HIGH 8.8 CVE-2021-47976 TextPattern CMS 4.9.0-dev contains a remote code execution vulnerability that allows authenticated attackers to upload arbitrary PHP files by exploit… No fix yet Fix from $1,9502026-05-16 MEDIUM 5.3 CVE-2020-37241 bloofoxCMS 0.5.2.1 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in … No fix yet Fix from $1,6002026-05-16 MEDIUM 6.5 CVE-2026-45773 Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14, Turborepo's self-hosted login and SSO browser … Turborepo 2.9.14+ Fix from $1,6002026-05-15 HIGH 8.1 CVE-2026-28761 Cross-site request forgery vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. If a user views a… Mitigation only Fix from $1,9502026-05-15 MEDIUM 6.5 CVE-2026-4527 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that c… GitLab 18.9.7 / 18.10.6+ Fix from $1,6002026-05-14 CRITICAL 9.3 CVE-2025-27851 The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking attack. Among other uses, the WDU … Empirbus Wireless Display Unit Firmware Mitigation only Fix from $2,3002026-05-13 CRITICAL 9.3 CVE-2026-44364 MISP modules are autonomous modules that can be used to extend MISP for new services. In 3.0.7 and earlier, a Cross-Site Request Forgery vulnerabilit… Mitigation only Fix from $2,3002026-05-13 MEDIUM 6.1 CVE-2026-41255 CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, Access to the views via tok… Ckan 2.10.10 / 2.11.5+ Fix from $1,6002026-05-13 MEDIUM 5.4 CVE-2026-40703 A cross-site request forgery (CSRF) vulnerability exists in the dashboard of the BIG-IP Configuration utility.  Note: Software versions which have re… Big Ip Access Policy Manager after 17.5.1 Fix from $1,6002026-05-13 MEDIUM 6.5 CVE-2026-44347 Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.23.3, the SSO flow does not validate the state parameter, which ma… Warpgate No fix yet Fix from $1,6002026-05-12