Total
8048 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2024-35556 | 1 Idccms | 1 Idccms | 2025-04-09 | 8.8 High |
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/vpsSys_deal.php?mudi=infoSet. | ||||
CVE-2024-35557 | 2 Idccms, Idccms Project | 2 Idccms, Idccms | 2025-04-09 | 5.5 Medium |
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/vpsApi_deal.php?mudi=rev&nohrefStr=close. | ||||
CVE-2024-35558 | 2 Idccms, Idccms Project | 2 Idccms, Idccms | 2025-04-09 | 8.8 High |
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=rev&nohrefStr=close. | ||||
CVE-2024-35559 | 2 Idccms, Idccms Project | 2 Idccms, Idccms | 2025-04-09 | 8.8 High |
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=rev&nohrefStr=close. | ||||
CVE-2024-35560 | 2 Idccms, Idccms Project | 2 Idccms, Idccms | 2025-04-09 | 4.3 Medium |
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=del&dataType=&dataTypeCN. | ||||
CVE-2024-35561 | 2 Idccms, Idccms Project | 2 Idccms, Idccms | 2025-04-09 | 5.4 Medium |
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=add&nohrefStr=close. | ||||
CVE-2025-32280 | 1 Wedevs | 1 Wp Project Manager | 2025-04-09 | 4.3 Medium |
Cross-Site Request Forgery (CSRF) vulnerability in weDevs WP Project Manager allows Cross Site Request Forgery. This issue affects WP Project Manager: from n/a through 2.6.22. | ||||
CVE-2022-4849 | 1 Usememos | 1 Memos | 2025-04-09 | 6.5 Medium |
Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1. | ||||
CVE-2024-30458 | 1 Pluginus | 1 Fox - Currency Switcher Professional For Woocommerce | 2025-04-09 | 4.3 Medium |
Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOOCS – WooCommerce Currency Switcher.This issue affects WOOCS – WooCommerce Currency Switcher: from n/a through 1.4.1.7. | ||||
CVE-2024-30456 | 1 Pluginus | 1 Wordpress Currency Switcher | 2025-04-09 | 4.3 Medium |
Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WPCS.This issue affects WPCS: from n/a through 1.2.0.1. | ||||
CVE-2024-1325 | 1 Delabon | 1 Woomotiv | 2025-04-09 | 4.3 Medium |
The Live Sales Notification for Woocommerce – Woomotiv plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.4.3. This is due to missing or incorrect nonce validation on the 'ajax_cancel_review' function. This makes it possible for unauthenticated attackers to reset the site's review count via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | ||||
CVE-2022-4867 | 1 Froxlor | 1 Froxlor | 2025-04-09 | 4.3 Medium |
Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 2.0.0-beta1. | ||||
CVE-2022-4844 | 1 Usememos | 1 Memos | 2025-04-09 | 8.8 High |
Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1. | ||||
CVE-2022-4103 | 1 Royal-elementor-addons | 1 Royal Elementor Addons | 2025-04-09 | 4.3 Medium |
The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorisation and CSRF checks when creating a template, and does not ensure that the post created is a template. This could allow any authenticated users, such as subscriber to create a post (as well as any post type) with an arbitrary title | ||||
CVE-2025-28856 | 1 W3counter | 1 W3counter | 2025-04-09 | 4.3 Medium |
Cross-Site Request Forgery (CSRF) vulnerability in dangrossman W3Counter Free Real-Time Web Stats allows Cross Site Request Forgery. This issue affects W3Counter Free Real-Time Web Stats: from n/a through 4.1. | ||||
CVE-2025-28876 | 1 Skrill | 1 Skrill | 2025-04-09 | 4.3 Medium |
Cross-Site Request Forgery (CSRF) vulnerability in Skrill_Team Skrill Official allows Cross Site Request Forgery. This issue affects Skrill Official: from n/a through 1.0.65. | ||||
CVE-2008-0524 | 1 Yamaha | 18 Rt107e, Rt52pro, Rt56v and 15 more | 2025-04-09 | N/A |
Cross-site request forgery (CSRF) vulnerability in the management interface in multiple Yamaha RT series routers allows remote attackers to change password settings and probably other configuration settings as administrators via unspecified vectors. | ||||
CVE-2008-0164 | 1 Plone | 1 Plone Cms | 2025-04-09 | N/A |
Multiple cross-site request forgery (CSRF) vulnerabilities in Plone CMS 3.0.5 and 3.0.6 allow remote attackers to (1) add arbitrary accounts via the join_form page and (2) change the privileges of arbitrary groups via the prefs_groups_overview page. | ||||
CVE-2008-0472 | 1 Woltlab | 1 Burning Board | 2025-04-09 | N/A |
Cross-site request forgery (CSRF) vulnerability in modcp.php in Woltlab Burning Board (wBB) 2.3.6 PL2 allows remote attackers to delete threads as moderators or administrators via a thread_del action. | ||||
CVE-2008-5189 | 1 Rubyonrails | 2 Rails, Ruby On Rails | 2025-04-09 | N/A |
CRLF injection vulnerability in Ruby on Rails before 2.0.5 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL to the redirect_to function. |