Total
7920 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2022-32555 | 1 Unisys | 1 Data Exchange Management Studio | 2025-06-05 | 8.8 High |
Unisys Data Exchange Management Studio before 6.0.IC2 and 7.x before 7.0.IC1 doesn't have an Anti-CSRF token to authenticate the POST request. Thus, a cross-site request forgery attack could occur. | ||||
CVE-2024-22817 | 1 Flycms Project | 1 Flycms | 2025-06-05 | 8.8 High |
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/email/email_conf_updagte | ||||
CVE-2024-9943 | 1 Multivendorx | 1 Multivendorx | 2025-06-05 | 6.3 Medium |
The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.4. This is due to missing or incorrect nonce validation on several functions in api/class-mvx-rest-controller.php. This makes it possible for unauthenticated attackers to update vendor account details, create vendor accounts, and delete arbitrary users via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | ||||
CVE-2024-22699 | 1 Flycms Project | 1 Flycms | 2025-06-05 | 8.8 High |
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/admin/update_group_save. | ||||
CVE-2024-12545 | 1 Appsmav | 1 Scratch \& Win | 2025-06-05 | 5.4 Medium |
The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.1. This is due to missing nonce validation on the reset_installation() function. This makes it possible for unauthenticated attackers to reset the plugin’s installation via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | ||||
CVE-2023-25987 | 1 Urosevic | 1 My Youtube Channel | 2025-06-05 | 4.3 Medium |
Cross-Site Request Forgery (CSRF) vulnerability in Aleksandar Urošević My YouTube Channel plugin <= 3.23.3 versions. | ||||
CVE-2023-47785 | 1 Kreaturamedia | 1 Layerslider | 2025-06-05 | 7.1 High |
Cross-Site Request Forgery (CSRF) vulnerability in LayerSlider plugin <= 7.7.9 versions. | ||||
CVE-2023-47819 | 1 Dangngocbinh | 1 Easy Call Now By Thikshare | 2025-06-05 | 4.3 Medium |
Cross-Site Request Forgery (CSRF) vulnerability in Dang Ngoc Binh Easy Call Now by ThikShare plugin <= 1.1.0 versions. | ||||
CVE-2023-49673 | 2 Jenkins, Jenkins Project | 5 Google Compute Engine, Jira, Matlab and 2 more | 2025-06-05 | 8.8 High |
A cross-site request forgery (CSRF) vulnerability in Jenkins NeuVector Vulnerability Scanner Plugin 1.22 and earlier allows attackers to connect to an attacker-specified hostname and port using attacker-specified username and password. | ||||
CVE-2023-49076 | 1 Pimcore | 1 Pimcore | 2025-06-05 | 4.3 Medium |
Customer-data-framework allows management of customer data within Pimcore. There are no tokens or headers to prevent CSRF attacks from occurring, therefore an attacker could abuse this vulnerability to create new customers. This issue has been patched in version 4.0.5. | ||||
CVE-2018-18760 | 1 Saltos | 1 Rhinos | 2025-06-05 | N/A |
RhinOS 3.0 build 1190 allows CSRF. | ||||
CVE-2020-14506 | 1 Philips | 1 Clinical Collaboration Platform | 2025-06-04 | 3.4 Low |
Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly. | ||||
CVE-2024-9233 | 1 Gsplugins | 1 Logo Slider | 2025-06-04 | 4.3 Medium |
The Logo Slider WordPress plugin before 3.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | ||||
CVE-2024-9450 | 1 Syntactics | 1 Free Booking Plugin For Hotels\, Restaurant And Car Rental | 2025-06-04 | 6.5 Medium |
The Free Booking Plugin for Hotels, Restaurants and Car Rentals WordPress plugin before 1.3.15 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in subscriber change them via a CSRF attack | ||||
CVE-2025-4580 | 1 Dimdavid | 1 File Provider | 2025-06-04 | 4.3 Medium |
The File Provider WordPress plugin through 1.2.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | ||||
CVE-2025-2247 | 1 Mantus667 | 1 Wp-pmanager | 2025-06-04 | 5.4 Medium |
The WP-PManager WordPress plugin through 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | ||||
CVE-2025-1557 | 1 Ofcms Project | 1 Ofcms | 2025-06-04 | 4.3 Medium |
A vulnerability, which was classified as problematic, was found in OFCMS 1.1.3. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | ||||
CVE-2025-5142 | 1 Pluginsandsnippets | 1 Simple Page Access Restriction | 2025-06-04 | 6.5 Medium |
The Simple Page Access Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.31. This is due to missing nonce validation and capability checks in the settings save handler in the settings.php script. This makes it possible for unauthenticated attackers to (1) enable or disable access protection on all post types or taxonomies, (2) force every new page/post to be public or private, regardless of meta-box settings, (3) cause a silent wipe of all plugin data when it’s later removed, or (4) to conduct URL redirection attacks via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | ||||
CVE-2024-13244 | 1 Migrate Tools Project | 1 Migrate Tools | 2025-06-04 | 8.8 High |
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Migrate Tools allows Cross Site Request Forgery.This issue affects Migrate Tools: from 0.0.0 before 6.0.3. | ||||
CVE-2023-5934 | 1 Travelpayouts | 1 Travelpayouts | 2025-06-04 | 7.3 High |
The Travelpayouts: All Travel Brands in One Place WordPress plugin before 1.1.13 does not have CSRF check in place when importing settings from the v1, which could allow attackers to make a logged in admin update some settings via a CSRF attack |