Total
6529 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2024-6852 | 1 Ngothang | 1 Wp Multitasking | 2024-09-11 | N/A | 4.3 MEDIUM |
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |||||
CVE-2024-6853 | 1 Ngothang | 1 Wp Multitasking | 2024-09-11 | N/A | 4.3 MEDIUM |
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating welcome popups, which could allow attackers to make logged admins perform such action via a CSRF attack | |||||
CVE-2024-6855 | 1 Ngothang | 1 Wp Multitasking | 2024-09-11 | N/A | 4.3 MEDIUM |
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating exit popups, which could allow attackers to make logged admins perform such action via a CSRF attack | |||||
CVE-2024-6856 | 1 Ngothang | 1 Wp Multitasking | 2024-09-11 | N/A | 4.3 MEDIUM |
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |||||
CVE-2024-6925 | 1 Themetechmount | 1 Truebooker | 2024-09-11 | N/A | 4.3 MEDIUM |
The TrueBooker WordPress plugin before 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack. | |||||
CVE-2024-43275 | 1 Xyzscripts | 1 Insert Php Code Snippet | 2024-09-11 | N/A | 8.8 HIGH |
Cross-Site Request Forgery (CSRF) vulnerability in xyzscripts.Com Insert PHP Code Snippet.This issue affects Insert PHP Code Snippet: from n/a through 1.3.6. | |||||
CVE-2024-42557 | 2024-09-06 | N/A | 8.8 HIGH | ||
A Cross-Site Request Forgery (CSRF) in the component admin_modify_room.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges. | |||||
CVE-2024-8414 | 1 Munyweki | 1 Insurance Management System | 2024-09-06 | 5.0 MEDIUM | 4.3 MEDIUM |
A vulnerability has been found in SourceCodester Insurance Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | |||||
CVE-2024-42792 | 1 Lopalopa | 1 Music Management System | 2024-09-05 | N/A | 3.5 LOW |
A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via /music/ajax.php?action=delete_playlist page. | |||||
CVE-2024-43947 | 1 Dineshkarki | 1 Wp Armour Extended | 2024-09-04 | N/A | 4.3 MEDIUM |
Cross-Site Request Forgery (CSRF) vulnerability in Dinesh Karki WP Armour Extended.This issue affects WP Armour Extended: from n/a through 1.26. | |||||
CVE-2024-45270 | 1 Majeedraza | 1 Carousel Slider | 2024-09-04 | N/A | 4.3 MEDIUM |
WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Hero image selection feature. While logged in to the WordPress site with Carousel Slider plugin enabled, accessing a crafted page may cause a user to alter the contents of the WordPress site. | |||||
CVE-2024-45269 | 1 Majeedraza | 1 Carousel Slider | 2024-09-04 | N/A | 4.3 MEDIUM |
WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Carousel image selection feature. While logged in to the WordPress site with Carousel Slider plugin enabled, accessing a crafted page may cause a user to alter the contents of the WordPress site. | |||||
CVE-2024-45527 | 2024-09-03 | N/A | 6.1 MEDIUM | ||
REDCap 14.7.0 allows HTML injection via the project title of a New Project action. This can lead to resultant logout CSRF via index.php?logout=1, and can also be used to insert a link to an external phishing website. | |||||
CVE-2024-8319 | 1 Themeific | 1 Tourfic | 2024-09-03 | N/A | 4.3 MEDIUM |
The Tourfic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.11.20. This is due to missing or incorrect nonce validation on the tf_order_status_email_resend_function, tf_visitor_details_edit_function, tf_checkinout_details_edit_function, tf_order_status_edit_function, tf_order_bulk_action_edit_function, tf_remove_room_order_ids, and tf_delete_old_review_fields functions. This makes it possible for unauthenticated attackers to resend order status emails, update visitor/order details, edit check-in/out details, edit order status, perform bulk order status updates, remove room order IDs, and delete old review fields, respectively, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |||||
CVE-2024-42793 | 1 Lopalopa | 1 Music Management System | 2024-08-30 | N/A | 8.0 HIGH |
A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via a crafted request to the /music/ajax.php?action=save_user page. | |||||
CVE-2024-8200 | 1 Smashballoon | 1 Reviews Feed | 2024-08-30 | N/A | 4.3 MEDIUM |
The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing or incorrect nonce validation on the 'update_api_key' function. This makes it possible for unauthenticated attackers to update an API key via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |||||
CVE-2024-45264 | 1 Skyss | 1 Arfa-cms | 2024-08-30 | N/A | 8.8 HIGH |
A cross-site request forgery (CSRF) vulnerability in the admin panel in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to add a new administrator, leading to escalation of privileges. | |||||
CVE-2024-43336 | 1 Wpusermanager | 1 Wp User Manager | 2024-08-27 | N/A | 4.3 MEDIUM |
Cross-Site Request Forgery (CSRF) vulnerability in WP User Manager.This issue affects WP User Manager: from n/a through 2.9.10. | |||||
CVE-2024-43337 | 1 Getbrave | 1 Brave | 2024-08-27 | N/A | 4.3 MEDIUM |
Cross-Site Request Forgery (CSRF) vulnerability in Brave Brave Popup Builder.This issue affects Brave Popup Builder: from n/a through 0.7.0. | |||||
CVE-2024-43339 | 1 Webinarpress | 1 Webinarpress | 2024-08-27 | N/A | 6.1 MEDIUM |
Cross-Site Request Forgery (CSRF) vulnerability in WebinarPress allows Cross-Site Scripting (XSS).This issue affects WebinarPress: from n/a through 1.33.20. |