Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2023-48330 Cross-Site Request Forgery (CSRF) vulnerability in Mike Strand Bulk Comment Remove allows Cross Site Request Forgery.This issue affects Bulk Comment … Bulk Comment Remove after 2.0 Fix from $1,9502023-11-30 HIGH 8.8 CVE-2023-48331 Cross-Site Request Forgery (CSRF) vulnerability in Stormhill Media MyBookTable Bookstore by Stormhill Media allows Cross Site Request Forgery.This is… Mybook Table Bookstore after 3.3.4 Fix from $1,9502023-11-30 HIGH 8.8 CVE-2023-48334 Cross-Site Request Forgery (CSRF) vulnerability in DAEXT League Table allows Cross Site Request Forgery.This issue affects League Table: from n/a thr… League Table after 1.13 Fix from $1,9502023-11-30 HIGH 8.8 CVE-2023-48744 Cross-Site Request Forgery (CSRF) vulnerability in Offshore Web Master Availability Calendar allows Cross Site Request Forgery.This issue affects Ava… Availability Calendar after 1.2.6 Fix from $1,9502023-11-30 HIGH 8.8 CVE-2023-48282 Cross-Site Request Forgery (CSRF) vulnerability in Andrea Landonio Taxonomy filter allows Cross Site Request Forgery.This issue affects Taxonomy filt… Taxonomy Filter after 2.2.9 Fix from $1,9502023-11-30 HIGH 8.8 CVE-2023-48283 Cross-Site Request Forgery (CSRF) vulnerability in PressTigers Simple Testimonials Showcase allows Cross Site Request Forgery.This issue affects Simp… Simple Testimonials Showcase after 1.1.5 Fix from $1,9502023-11-30 HIGH 8.8 CVE-2023-48284 Cross-Site Request Forgery (CSRF) vulnerability in WebToffee Decorator – WooCommerce Email Customizer allows Cross Site Request Forgery.This issue af… Decorator after 1.2.7 Fix from $1,9502023-11-30 MEDIUM 6.5 CVE-2023-49076 Customer-data-framework allows management of customer data within Pimcore. There are no tokens or headers to prevent CSRF attacks from occurring, the… Pimcore 4.0.5+ Fix from $1,6002023-11-30 HIGH 8.8 CVE-2023-49655 A cross-site request forgery (CSRF) vulnerability in Jenkins MATLAB Plugin 2.11.0 and earlier allows attackers to have Jenkins parse an XML file from… Matlab 2.11.1+ Fix from $1,9502023-11-29 HIGH 8.8 CVE-2023-49673 A cross-site request forgery (CSRF) vulnerability in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier allows attackers to connect to a… Neuvector Vulnerability Scanner 2.2 / 2.11.1+ Fix from $1,9502023-11-29 MEDIUM 6.1 CVE-2023-41792 Cross-Site Request Forgery (CSRF) vulnerability in Pandora FMS on all allows Cross-Site Scripting (XSS). This vulnerability allowed Javascript code t… Pandora Fms after 773 Fix from $1,6002023-11-23 MEDIUM 6.1 CVE-2023-47790 Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) vulnerability in Poporon Pz-LinkCard plugin <= 2.4.8 versions. Pz Linkcard after 2.4.8 Fix from $1,6002023-11-23 HIGH 8.8 CVE-2023-47824 Cross-Site Request Forgery (CSRF) vulnerability in wpWax Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator pl… Legal Pages 1.3.9+ Fix from $1,9502023-11-22 HIGH 8.8 CVE-2023-47825 Cross-Site Request Forgery (CSRF) vulnerability in TienCOP WP EXtra plugin <= 6.4 versions. Wp Extra 6.5+ Fix from $1,9502023-11-22 HIGH 8.8 CVE-2023-47791 Cross-Site Request Forgery (CSRF) vulnerability in Leadster plugin <= 1.1.2 versions. Leadster after 1.1.2 Fix from $1,9502023-11-22 HIGH 8.8 CVE-2023-47792 Cross-Site Request Forgery (CSRF) vulnerability in Infinite Uploads Big File Uploads – Increase Maximum File Upload Size plugin <= 2.1.1 versions. Big File Uploads 2.1.2+ Fix from $1,9502023-11-22 HIGH 8.8 CVE-2023-47819 Cross-Site Request Forgery (CSRF) vulnerability in Dang Ngoc Binh Easy Call Now by ThikShare plugin <= 1.1.0 versions. Easy Call Now By Thikshare after 1.1.0 Fix from $1,9502023-11-22 HIGH 8.8 CVE-2023-39925 Cross-Site Request Forgery (CSRF) vulnerability in PeepSo Download Community by PeepSo plugin <= 6.1.6.0 versions. Peepso 6.2.0.0+ Fix from $1,9502023-11-22 HIGH 8.8 CVE-2023-47775 Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team Comments — wpDiscuz plugin <= 7.6.11 versions. Wpdiscuz 7.6.12+ Fix from $1,9502023-11-22 HIGH 8.8 CVE-2023-47781 Cross-Site Request Forgery (CSRF) vulnerability in Thrive Themes Thrive Theme Builder < 3.24.2 versions. Thrive Themes Builder after 3.24.2 Fix from $1,9502023-11-22 HIGH 8.8 CVE-2023-47785 Cross-Site Request Forgery (CSRF) vulnerability in LayerSlider plugin <= 7.7.9 versions. Layerslider 7.7.10+ Fix from $1,9502023-11-22 HIGH 8.8 CVE-2023-47758 Cross-Site Request Forgery (CSRF) vulnerability in Mondula GmbH Multi Step Form plugin <= 1.7.11 versions. Multi Step Form 1.7.11+ Fix from $1,9502023-11-22 HIGH 8.8 CVE-2023-47765 Cross-Site Request Forgery (CSRF) vulnerability in CodeBard CodeBard's Patron Button and Widgets for Patreon plugin <= 2.1.9 versions. Codebard\'s Patron Button And Widgets For Patreon 2.2.0+ Fix from $1,9502023-11-22 HIGH 8.8 CVE-2023-25986 Cross-Site Request Forgery (CSRF) vulnerability in WattIsIt PayGreen – Ancienne version plugin <= 4.10.2 versions. Paygreen Ancienne after 4.10.2 Fix from $1,9502023-11-22 HIGH 8.8 CVE-2023-25987 Cross-Site Request Forgery (CSRF) vulnerability in Aleksandar Urošević My YouTube Channel plugin <= 3.23.3 versions. My Youtube Channel 3.23.4+ Fix from $1,9502023-11-22 MEDIUM 6.5 CVE-2023-47014 A Cross-Site Request Forgery (CSRF) vulnerability in Sourcecodester Sticky Notes App Using PHP with Source Code v.1.0 allows a local attacker to obta… Sticky Notes App No fix yet Fix from $1,6002023-11-22 HIGH 8.8 CVE-2023-47350 Cross-Site Request Forgery (CSRF) vulnerability in SwiftyEdit Content Management System prior to v1.2.0, allows remote attackers to escalate privileg… Swiftyedit 1.2.0+ Fix from $1,9502023-11-22 MEDIUM 6.1 CVE-2023-2438 The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.0. This is due to missing or incor… Userpro after 5.1.0 Fix from $1,6002023-11-22 HIGH 8.8 CVE-2023-2440 The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. This is due to missing nonce va… Userpro after 5.1.1 Fix from $1,9502023-11-22 HIGH 8.8 CVE-2023-2497 The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.0. This is due to missing or incor… Userpro after 5.1.0 Fix from $1,9502023-11-22