Total
7932 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2025-49453 | 2025-06-06 | N/A | 7.1 HIGH | ||
Cross-Site Request Forgery (CSRF) vulnerability in Jatinder Pal Singh BP Profile as Homepage allows Stored XSS. This issue affects BP Profile as Homepage: from n/a through 1.1. | |||||
CVE-2025-30629 | 2025-06-06 | N/A | 4.3 MEDIUM | ||
Cross-Site Request Forgery (CSRF) vulnerability in Codehaveli Bitly URL Shortener allows Cross Site Request Forgery. This issue affects Bitly URL Shortener: from n/a through 1.3.3. | |||||
CVE-2025-49332 | 2025-06-06 | N/A | 4.3 MEDIUM | ||
Cross-Site Request Forgery (CSRF) vulnerability in codepeople WP Time Slots Booking Form allows Cross Site Request Forgery. This issue affects WP Time Slots Booking Form: from n/a through 1.2.30. | |||||
CVE-2024-54356 | 1 Vcita | 1 Online Booking \& Scheduling Calendar For Wordpress By Vcita | 2025-06-05 | N/A | 5.4 MEDIUM |
Cross-Site Request Forgery (CSRF) vulnerability in vCita.com Online Booking & Scheduling Calendar for WordPress by vcita allows Cross Site Request Forgery.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through 4.5. | |||||
CVE-2024-37235 | 1 Groundhogg | 1 Groundhogg | 2025-06-05 | N/A | 4.3 MEDIUM |
Cross-Site Request Forgery (CSRF) vulnerability in Groundhogg Inc. Groundhogg allows Cross Site Request Forgery.This issue affects Groundhogg: from n/a through 3.4.2.3. | |||||
CVE-2024-56229 | 1 Searchiq | 1 Searchiq | 2025-06-05 | N/A | 4.3 MEDIUM |
Cross-Site Request Forgery (CSRF) vulnerability in Searchiq SearchIQ.This issue affects SearchIQ: from n/a through 4.6. | |||||
CVE-2024-42553 | 1 Vaibhavverma9999 | 1 Hotel Management System | 2025-06-05 | N/A | 8.8 HIGH |
A Cross-Site Request Forgery (CSRF) in the component admin_room_added.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges. | |||||
CVE-2024-42555 | 1 Vaibhavverma9999 | 1 Hotel Management System | 2025-06-05 | N/A | 8.8 HIGH |
A Cross-Site Request Forgery (CSRF) in the component admin_room_removed.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges. | |||||
CVE-2024-42557 | 1 Vaibhavverma9999 | 1 Hotel Management System | 2025-06-05 | N/A | 8.8 HIGH |
A Cross-Site Request Forgery (CSRF) in the component admin_modify_room.php of Hotel Management System commit 91caab8 allows attackers to escalate privileges. | |||||
CVE-2025-31482 | 2025-06-05 | N/A | 4.3 MEDIUM | ||
FreshRSS is a self-hosted RSS feed aggregator. A vulnerability in versions prior to 1.26.2 causes a user to be repeatedly logged out after fetching a malicious feed entry, effectively causing that user to suffer denial of service. Version 1.26.2 contains a patch for the issue. | |||||
CVE-2025-46257 | 2025-06-05 | N/A | 4.3 MEDIUM | ||
Cross-Site Request Forgery (CSRF) vulnerability in BdThemes Element Pack Pro allows Cross Site Request Forgery.This issue affects Element Pack Pro: from n/a before 8.0.0. | |||||
CVE-2022-32555 | 1 Unisys | 1 Data Exchange Management Studio | 2025-06-05 | N/A | 8.8 HIGH |
Unisys Data Exchange Management Studio before 6.0.IC2 and 7.x before 7.0.IC1 doesn't have an Anti-CSRF token to authenticate the POST request. Thus, a cross-site request forgery attack could occur. | |||||
CVE-2024-22817 | 1 Flycms Project | 1 Flycms | 2025-06-05 | N/A | 8.8 HIGH |
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/email/email_conf_updagte | |||||
CVE-2024-9943 | 1 Multivendorx | 1 Multivendorx | 2025-06-05 | N/A | 6.3 MEDIUM |
The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2.4. This is due to missing or incorrect nonce validation on several functions in api/class-mvx-rest-controller.php. This makes it possible for unauthenticated attackers to update vendor account details, create vendor accounts, and delete arbitrary users via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |||||
CVE-2024-22699 | 1 Flycms Project | 1 Flycms | 2025-06-05 | N/A | 8.8 HIGH |
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/admin/update_group_save. | |||||
CVE-2024-12545 | 1 Appsmav | 1 Scratch \& Win | 2025-06-05 | N/A | 5.4 MEDIUM |
The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.1. This is due to missing nonce validation on the reset_installation() function. This makes it possible for unauthenticated attackers to reset the plugin’s installation via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |||||
CVE-2018-18760 | 1 Saltos | 1 Rhinos | 2025-06-05 | 4.3 MEDIUM | 6.5 MEDIUM |
RhinOS 3.0 build 1190 allows CSRF. | |||||
CVE-2020-14506 | 1 Philips | 1 Clinical Collaboration Platform | 2025-06-04 | 4.3 MEDIUM | 3.4 LOW |
Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly. | |||||
CVE-2024-9233 | 1 Gsplugins | 1 Logo Slider | 2025-06-04 | N/A | 4.3 MEDIUM |
The Logo Slider WordPress plugin before 3.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |||||
CVE-2024-9450 | 1 Syntactics | 1 Free Booking Plugin For Hotels\, Restaurant And Car Rental | 2025-06-04 | N/A | 6.5 MEDIUM |
The Free Booking Plugin for Hotels, Restaurants and Car Rentals WordPress plugin before 1.3.15 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in subscriber change them via a CSRF attack |