Vulnerabilities (CVE)

Filtered by CWE-352
Total 7932 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-49453 2025-06-06 N/A 7.1 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Jatinder Pal Singh BP Profile as Homepage allows Stored XSS. This issue affects BP Profile as Homepage: from n/a through 1.1.
CVE-2025-30629 2025-06-06 N/A 4.3 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in Codehaveli Bitly URL Shortener allows Cross Site Request Forgery. This issue affects Bitly URL Shortener: from n/a through 1.3.3.
CVE-2025-49332 2025-06-06 N/A 4.3 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in codepeople WP Time Slots Booking Form allows Cross Site Request Forgery. This issue affects WP Time Slots Booking Form: from n/a through 1.2.30.
CVE-2024-54356 1 Vcita 1 Online Booking \& Scheduling Calendar For Wordpress By Vcita 2025-06-05 N/A 5.4 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in vCita.com Online Booking & Scheduling Calendar for WordPress by vcita allows Cross Site Request Forgery.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through 4.5.
CVE-2024-37235 1 Groundhogg 1 Groundhogg 2025-06-05 N/A 4.3 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in Groundhogg Inc. Groundhogg allows Cross Site Request Forgery.This issue affects Groundhogg: from n/a through 3.4.2.3.
CVE-2024-56229 1 Searchiq 1 Searchiq 2025-06-05 N/A 4.3 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in Searchiq SearchIQ.This issue affects SearchIQ: from n/a through 4.6.
CVE-2024-42553 1 Vaibhavverma9999 1 Hotel Management System 2025-06-05 N/A 8.8 HIGH
A Cross-Site Request Forgery (CSRF) in the component admin_room_added.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.
CVE-2024-42555 1 Vaibhavverma9999 1 Hotel Management System 2025-06-05 N/A 8.8 HIGH
A Cross-Site Request Forgery (CSRF) in the component admin_room_removed.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.
CVE-2024-42557 1 Vaibhavverma9999 1 Hotel Management System 2025-06-05 N/A 8.8 HIGH
A Cross-Site Request Forgery (CSRF) in the component admin_modify_room.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges.
CVE-2025-31482 2025-06-05 N/A 4.3 MEDIUM
FreshRSS is a self-hosted RSS feed aggregator. A vulnerability in versions prior to 1.26.2 causes a user to be repeatedly logged out after fetching a malicious feed entry, effectively causing that user to suffer denial of service. Version 1.26.2 contains a patch for the issue.
CVE-2025-46257 2025-06-05 N/A 4.3 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in BdThemes Element Pack Pro allows Cross Site Request Forgery.This issue affects Element Pack Pro: from n/a before 8.0.0.
CVE-2022-32555 1 Unisys 1 Data Exchange Management Studio 2025-06-05 N/A 8.8 HIGH
Unisys Data Exchange Management Studio before 6.0.IC2 and 7.x before 7.0.IC1 doesn't have an Anti-CSRF token to authenticate the POST request. Thus, a cross-site request forgery attack could occur.
CVE-2024-22817 1 Flycms Project 1 Flycms 2025-06-05 N/A 8.8 HIGH
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/email/email_conf_updagte
CVE-2024-9943 1 Multivendorx 1 Multivendorx 2025-06-05 N/A 6.3 MEDIUM
The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.4. This is due to missing or incorrect nonce validation on several functions in api/class-mvx-rest-controller.php. This makes it possible for unauthenticated attackers to update vendor account details, create vendor accounts, and delete arbitrary users via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CVE-2024-22699 1 Flycms Project 1 Flycms 2025-06-05 N/A 8.8 HIGH
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/admin/update_group_save.
CVE-2024-12545 1 Appsmav 1 Scratch \& Win 2025-06-05 N/A 5.4 MEDIUM
The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.1. This is due to missing nonce validation on the reset_installation() function. This makes it possible for unauthenticated attackers to reset the plugin’s installation via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CVE-2018-18760 1 Saltos 1 Rhinos 2025-06-05 4.3 MEDIUM 6.5 MEDIUM
RhinOS 3.0 build 1190 allows CSRF.
CVE-2020-14506 1 Philips 1 Clinical Collaboration Platform 2025-06-04 4.3 MEDIUM 3.4 LOW
Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly.
CVE-2024-9233 1 Gsplugins 1 Logo Slider 2025-06-04 N/A 4.3 MEDIUM
The Logo Slider WordPress plugin before 3.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVE-2024-9450 1 Syntactics 1 Free Booking Plugin For Hotels\, Restaurant And Car Rental 2025-06-04 N/A 6.5 MEDIUM
The Free Booking Plugin for Hotels, Restaurants and Car Rentals WordPress plugin before 1.3.15 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in subscriber change them via a CSRF attack