Vulnerability index

Browse CVEs

7,375 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
HIGH 8.8 CVE-2023-48020 Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/task/changeStatus. Dreamer Cms No fix yet Fix from $1,9502023-11-14 HIGH 8.8 CVE-2023-48021 Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/task/update. Dreamer Cms No fix yet Fix from $1,9502023-11-14 MEDIUM 6.1 CVE-2023-31230 Cross-Site Request Forgery (CSRF) vulnerability in Haoqisir Baidu Tongji generator allows Stored XSS.This issue affects Baidu Tongji generator: from … Baidu Tongji Generator after 1.0.2 Fix from $1,6002023-11-13 MEDIUM 6.1 CVE-2023-32123 Cross-Site Request Forgery (CSRF) vulnerability in Dream-Theme The7 allows Stored XSS.This issue affects The7: from n/a through 11.7.3. The7 after 11.7.3 Fix from $1,6002023-11-13 MEDIUM 6.1 CVE-2023-35877 Cross-Site Request Forgery (CSRF) vulnerability in Vadym K. Extra User Details allows Stored XSS.This issue affects Extra User Details: from n/a thro… Extra User Details 0.5.1+ Fix from $1,6002023-11-13 MEDIUM 6.1 CVE-2023-39166 Cross-Site Request Forgery (CSRF) vulnerability in tagDiv tagDiv Composer allows Cross-Site Scripting (XSS).This issue affects tagDiv Composer: from … Tagdiv Composer 4.4+ Fix from $1,6002023-11-13 HIGH 8.8 CVE-2023-48058 Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/task/run Dreamer Cms No fix yet Fix from $1,9502023-11-13 HIGH 8.8 CVE-2023-48060 Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/task/add Dreamer Cms No fix yet Fix from $1,9502023-11-13 MEDIUM 6.1 CVE-2023-40335 Cross-Site Request Forgery (CSRF) vulnerability in Jeremy O'Connell Cleverwise Daily Quotes allows Stored XSS.This issue affects Cleverwise Daily Quo… Cleverwise Daily Quotes after 3.2 Fix from $1,6002023-11-13 MEDIUM 6.1 CVE-2023-46092 Cross-Site Request Forgery (CSRF) vulnerability in LionScripts.Com Webmaster Tools allows Stored XSS.This issue affects Webmaster Tools: from n/a thr… Webmaster Tools after 2.0 Fix from $1,6002023-11-13 MEDIUM 6.1 CVE-2023-46201 Cross-Site Request Forgery (CSRF) vulnerability in Jeff Sherk Auto Login New User After Registration allows Stored XSS.This issue affects Auto Login … Auto Login New User After Registration after 1.9.6 Fix from $1,6002023-11-13 MEDIUM 6.1 CVE-2023-46634 Cross-Site Request Forgery (CSRF) vulnerability in phoeniixx Custom My Account for Woocommerce allows Cross-Site Scripting (XSS).This issue affects C… Custom My Account For Woocommerce after 2.1 Fix from $1,6002023-11-13 MEDIUM 6.1 CVE-2023-47516 Cross-Site Request Forgery (CSRF) vulnerability in Stark Digital Category Post List Widget allows Stored XSS.This issue affects Category Post List Wi… Category Post List Widget after 2.0 Fix from $1,6002023-11-13 MEDIUM 6.1 CVE-2023-47652 Cross-Site Request Forgery (CSRF) vulnerability in Lucian Apostol Auto Affiliate Links allows Stored XSS.This issue affects Auto Affiliate Links: fro… Auto Affiliate Links 6.4.2.5+ Fix from $1,6002023-11-13 HIGH 8.8 CVE-2023-35041 Cross-Site Request Forgery (CSRF) vulnerability leading to Local File Inclusion (LF) in Webpushr Web Push Notifications Web Push Notifications – Webp… Web Push Notifications after 4.34.0 Fix from $1,9502023-11-13 HIGH 8.8 CVE-2023-47669 Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Edi… Profile Builder 3.10.4+ Fix from $1,9502023-11-13 HIGH 8.8 CVE-2023-33207 Cross-Site Request Forgery (CSRF) vulnerability in Krzysztof Wielogórski Stop Referrer Spam plugin <= 1.3.0 versions. Stop Referrer Spam after 1.3.0 Fix from $1,9502023-11-13 HIGH 8.8 CVE-2023-34378 Cross-Site Request Forgery (CSRF) vulnerability in scriptburn.Com WP Hide Post plugin <= 2.0.10 versions. Wp Hide Post after 2.0.10 Fix from $1,9502023-11-13 HIGH 8.8 CVE-2023-34384 Cross-Site Request Forgery (CSRF) vulnerability in Kebo Kebo Twitter Feed plugin <= 1.5.12 versions. Kebo Twitter Feed after 1.5.12 Fix from $1,9502023-11-13 HIGH 8.8 CVE-2023-32583 Cross-Site Request Forgery (CSRF) vulnerability in Prashant Walke WP All Backup plugin <= 2.4.3 versions. Wp All Backup after 2.4.3 Fix from $1,9502023-11-13 HIGH 8.8 CVE-2023-32588 Cross-Site Request Forgery (CSRF) vulnerability in BRANDbrilliance Post State Tags plugin <= 2.0.6 versions. Post State Tags after 2.0.6 Fix from $1,9502023-11-13 HIGH 8.8 CVE-2023-46638 Cross-Site Request Forgery (CSRF) vulnerability in Webcodin WCP OpenWeather plugin <= 2.5.0 versions. Wcp Openweather after 2.5.0 Fix from $1,9502023-11-13 HIGH 8.8 CVE-2023-47230 Cross-Site Request Forgery (CSRF) vulnerability in Cimatti Consulting WordPress Contact Forms by Cimatti plugin <= 1.6.0 versions. Wordpress Contact Forms after 1.6.0 Fix from $1,9502023-11-13 HIGH 8.8 CVE-2023-46619 Cross-Site Request Forgery (CSRF) vulnerability in WebDorado WDSocialWidgets plugin <= 1.0.15 versions. Wdsocialwidgets after 1.0.15 Fix from $1,9502023-11-13 HIGH 8.8 CVE-2023-46620 Cross-Site Request Forgery (CSRF) vulnerability in Fluenx DeepL API translation plugin <= 2.3.9.1 versions. Deepl Api Translation after 2.3.9.1 Fix from $1,9502023-11-13 HIGH 8.8 CVE-2023-46625 Cross-Site Request Forgery (CSRF) vulnerability in DAEXT Autolinks Manager plugin <= 1.10.04 versions. Autolinks Manager after 1.10.04 Fix from $1,9502023-11-13 HIGH 8.8 CVE-2023-46629 Cross-Site Request Forgery (CSRF) vulnerability in themelocation Remove Add to Cart WooCommerce plugin <= 1.4.4. Remove Add To Cart Woocommerce after 1.4.4 Fix from $1,9502023-11-13 HIGH 8.8 CVE-2023-46636 Cross-Site Request Forgery (CSRF) vulnerability in David Stöckl Custom Header Images plugin <= 1.2.1 versions. Custom Header Images after 1.2.1 Fix from $1,9502023-11-13 HIGH 8.8 CVE-2023-26531 Cross-Site Request Forgery (CSRF) vulnerability in 闪电博 多合一搜索自动推送管理插件-支持Baidu/Google/Bing/IndexNow/Yandex/头条 allows Cross Site Req… All In One Search Automatic Push Management after 4.2.7 Fix from $1,9502023-11-13 HIGH 8.8 CVE-2023-26543 Cross-Site Request Forgery (CSRF) vulnerability in Aleksandr Guidrevitch WP Meteor Website Speed Optimization Addon plugin <= 3.1.4 versions. Wp Meteor after 3.1.4 Fix from $1,9502023-11-13