Total
8008 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-44937 | 1 Bosscms | 1 Bosscms | 2025-04-25 | N/A | 6.5 MEDIUM |
Bosscms v2.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Add function under the Administrator List module. | |||||
CVE-2022-3850 | 1 Find And Replace All Project | 1 Find And Replace All | 2025-04-25 | N/A | 4.3 MEDIUM |
The Find and Replace All WordPress plugin before 1.3 does not have CSRF check when replacing string, which could allow attackers to make a logged admin replace arbitrary string in database tables via a CSRF attack | |||||
CVE-2024-49672 | 1 Gief | 1 Google Docs Rsvp | 2025-04-25 | N/A | 7.1 HIGH |
Cross-Site Request Forgery (CSRF) vulnerability in Gifford Cheung, Brian Watanabe, Chongsun Ahn Google Docs RSVP allows Stored XSS.This issue affects Google Docs RSVP: from n/a through 2.0.1. | |||||
CVE-2022-40489 | 1 Thinkcmf | 1 Thinkcmf | 2025-04-24 | N/A | 8.8 HIGH |
ThinkCMF version 6.0.7 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows a Super Administrator user to be injected into administrative users. | |||||
CVE-2022-43470 | 1 Fsi | 8 Fs020w, Fs020w Firmware, Fs030w and 5 more | 2025-04-24 | N/A | 7.3 HIGH |
Cross-site request forgery (CSRF) vulnerability in +F FS040U software versions v2.3.4 and earlier, +F FS020W software versions v4.0.0 and earlier, +F FS030W software versions v3.3.5 and earlier, and +F FS040W software versions v1.4.1 and earlier allows an adjacent attacker to hijack the authentication of an administrator and user's unintended operations such as to reboot the product and/or reset the configuration to the initial set-up may be performed. | |||||
CVE-2020-11919 | 1 Svakom | 2 Svakom Siime Eye, Svakom Siime Eye Firmware | 2025-04-24 | N/A | 8.0 HIGH |
An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. There is no CSRF protection. | |||||
CVE-2024-56116 | 1 Amiro | 1 Amiro.cms | 2025-04-23 | N/A | 8.8 HIGH |
A Cross-Site Request Forgery vulnerability in Amiro.CMS before 7.8.4 allows remote attackers to create an administrator account. | |||||
CVE-2024-25905 | 1 Mondula | 1 Multi Step Form | 2025-04-23 | N/A | 5.4 MEDIUM |
Cross-Site Request Forgery (CSRF) vulnerability in Mondula GmbH Multi Step Form.This issue affects Multi Step Form: from n/a through 1.7.18. | |||||
CVE-2025-28101 | 1 Dogukanurker | 1 Flaskblog | 2025-04-23 | N/A | 6.5 MEDIUM |
An arbitrary file deletion vulnerability in the /post/{postTitle} component of flaskBlog v2.6.1 allows attackers to delete article titles created by other users via supplying a crafted POST request. | |||||
CVE-2025-29722 | 1 Yassmittal | 1 Commercify | 2025-04-23 | N/A | 6.3 MEDIUM |
A CSRF vulnerability in Commercify v1.0 allows remote attackers to perform unauthorized actions on behalf of authenticated users. The issue exists due to missing CSRF protection on sensitive endpoints. | |||||
CVE-2022-38144 | 1 Gvectors | 1 Wpforo Forum | 2025-04-23 | N/A | 8.8 HIGH |
Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 at WordPress. | |||||
CVE-2023-5519 | 1 Metagauss | 1 Eventprime | 2025-04-23 | N/A | 4.3 MEDIUM |
The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attackers to make logged in users create unwanted bookings via CSRF attacks. | |||||
CVE-2023-3508 | 1 Woocommerce | 1 Woocommerce Pre-orders | 2025-04-23 | N/A | 6.5 MEDIUM |
The WooCommerce Pre-Orders WordPress plugin before 2.0.3 has a flawed CSRF check when processing its tab actions, which could allow attackers to make logged in admins email pre-orders customer, change the released date, mark all pre-orders of a specific product as complete or cancel via CSRF attacks | |||||
CVE-2023-3507 | 1 Woocommerce | 1 Woocommerce Pre-orders | 2025-04-23 | N/A | 6.5 MEDIUM |
The WooCommerce Pre-Orders WordPress plugin before 2.0.3 has a flawed CSRF check when canceling pre-orders, which could allow attackers to make logged in admins cancel arbitrary pre-orders via a CSRF attack | |||||
CVE-2023-0603 | 1 Sloth Logo Customizer Project | 1 Sloth Logo Customizer | 2025-04-23 | N/A | 8.8 HIGH |
The Sloth Logo Customizer WordPress plugin through 2.0.2 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack | |||||
CVE-2022-46688 | 1 Jenkins | 1 Sonar Gerrit | 2025-04-23 | N/A | 6.5 MEDIUM |
A cross-site request forgery (CSRF) vulnerability in Jenkins Sonar Gerrit Plugin 377.v8f3808963dc5 and earlier allows attackers to have Jenkins connect to Gerrit servers (previously configured by Jenkins administrators) using attacker-specified credentials IDs obtained through another method, potentially capturing credentials stored in Jenkins. | |||||
CVE-2022-3926 | 1 Wp-oauth | 1 Wp Oauth Server | 2025-04-23 | N/A | 6.5 MEDIUM |
The WP OAuth Server (OAuth Authentication) WordPress plugin before 3.4.2 does not have CSRF check when regenerating secrets, which could allow attackers to make logged in admins regenerate the secret of an arbitrary client given they know the client ID | |||||
CVE-2022-45228 | 1 Dragino | 2 Lg01 Lora, Lg01 Lora Firmware | 2025-04-23 | N/A | 3.5 LOW |
Dragino Lora LG01 18ed40 IoT v4.3.4 was discovered to contain a Cross-Site Request Forgery in the logout page. | |||||
CVE-2022-44849 | 1 Metinfo | 1 Metinfo | 2025-04-23 | N/A | 8.8 HIGH |
A Cross-Site Request Forgery (CSRF) in the Administrator List of MetInfo v7.7 allows attackers to arbitrarily add Super Administrator account. | |||||
CVE-2025-3843 | 2025-04-23 | 5.0 MEDIUM | 4.3 MEDIUM | ||
A vulnerability was found in panhainan DS-Java 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. |