CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,274 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,563 researchers
8,801 results Clear all
CVE-2025-64262 6.5 MEDIUM EPSS 0.00
Auto Prune Posts <= 3.0.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in ramon fincken Auto Prune Posts auto-prune-posts allows Cross Site Request Forgery.This issue affects Auto Prune Posts: from n/a through <= 3.0.0.
CWE-352 Nov 13, 2025
CVE-2025-64482 4.6 MEDIUM 1 Writeup EPSS 0.00
Tuleap <16.13.99.1762267347 - CSRF
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap Community Edition prior to version 16.13.99.1762267347 and Tuleap Enterprise Edition prior to versions 17.01-, 16.13-6, and 16.12-9 don't have cross-site request forgery protections in the file release system. An attacker could use this vulnerability to trick victims into changing the commit rules or immutable tags of a SVN repo. Tuleap Community Edition 16.13.99.1762267347, Tuleap Enterprise Edition 17.0-1, Tuleap Enterprise Edition 16.13-6, and Tuleap Enterprise Edition 16.12-9 fix the issue.
CWE-352 Nov 12, 2025
CVE-2025-64117 4.6 MEDIUM 1 Writeup EPSS 0.00
Tuleap <16.13-5, <16.12-8 - CSRF
Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap Community Edition prior to version 16.13.99.1761813675 and Tuleap Enterprise Edition prior to versions 16.13-5 and 16.12-8 don't have cross-site request forgery protection in the management of SVN commit rules and immutable tags. An attacker could use this vulnerability to trick victims into changing the commit rules or immutable tags of a SVN repo. Tuleap Community Edition 16.13.99.1761813675, Tuleap Enterprise Edition 16.13-5, and Tuleap Enterprise Edition 16.12-8 contain a fix for the issue.
CWE-352 Nov 12, 2025
CVE-2025-57310 8.8 HIGH 2 PoCs Analysis EPSS 0.00
Salmen Simple Faucet Script - CSRF
A Cross-Site Request Forgery (CSRF) vulnerability in Salmen2/Simple-Faucet-Script v1.07 via crafted POST request to admin.php?p=ads&c=1 allowing attackers to execute arbitrary code.
CWE-352 Nov 12, 2025
CVE-2025-60645 6.5 MEDIUM EPSS 0.00
xxl-api v1.3.0 - CSRF
A Cross-Site Request Forgery (CSRF) in xxl-api v1.3.0 allows attackers to arbitrarily add users to the management module via a crafted GET request.
CWE-352 Nov 12, 2025
CVE-2025-12901 4.3 MEDIUM 1 Writeup EPSS 0.00
Asgaros Forum <3.2.1 - CSRF
The Asgaros Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.1. This is due to missing nonce validation on the set_subscription_level() function. This makes it possible for unauthenticated attackers to modify the subscription settings of authenticated users via a forged request granted they can trick a logged-in user into performing an action such as clicking on a link.
CWE-352 Nov 12, 2025
CVE-2025-12590 6.1 MEDIUM EPSS 0.00
YSlider plugin - XSS
The YSlider plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in all versions up to, and including, 1.1. This is due to missing nonce verification on the content configuration page and insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages via a forged request granted they can trick an administrator into performing an action such as clicking on a link. The injected scripts will execute whenever a user accesses an injected page.
CWE-352 Nov 11, 2025
CVE-2025-12589 6.1 MEDIUM EPSS 0.00
WP-Walla <0.5.3.5 - CSRF/XSS
The WP-Walla plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in all versions up to, and including, 0.5.3.5. This is due to missing nonce verification on the settings page and insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages via a forged request granted they can trick an administrator into performing an action such as clicking on a link.
CWE-352 Nov 11, 2025
CVE-2025-12588 4.3 MEDIUM EPSS 0.00
USB Qr Code Scanner For Woocommerce <1.0.0 - CSRF
The USB Qr Code Scanner For Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing nonce validation on the settings page. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request granted they can trick an administrator into performing an action such as clicking on a link.
CWE-352 Nov 11, 2025
CVE-2025-12132 4.3 MEDIUM EPSS 0.00
WP Custom Admin Login Page Logo <1.4.8.4 - CSRF
The WP Custom Admin Login Page Logo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.8.4. This is due to missing or incorrect nonce validation on the wpclpl_save functionality. This makes it possible for unauthenticated attackers to modify the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Nov 11, 2025
CVE-2025-11886 4.3 MEDIUM EPSS 0.00
CTL Arcade Lite <1.0 - CSRF
The CTL Arcade Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the 'ctl_arcade_lite_page_manage_games' page. This makes it possible for unauthenticated attackers to deactivate and activate arbitrary plugins via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Nov 11, 2025
CVE-2025-63712 8.8 HIGH 1 Writeup EPSS 0.00
SourceCodester Product Expiry Management - CSRF
Cross-Site Request Forgery (CSRF) in SourceCodester Product Expiry Management System. The User Management module (delete-user.php) allows remote attackers to delete arbitrary user accounts via forged cross-origin GET requests because the endpoint relies solely on session cookies and lacks CSRF protection.
CWE-352 Nov 10, 2025
CVE-2025-63711 7.1 HIGH 1 Writeup EPSS 0.00
SourceCodester Client DBMS 1.0 - CSRF
A Cross-Site Request Forgery (CSRF) vulnerability in the SourceCodester Client Database Management System 1.0 allows an attacker to cause an authenticated administrative user to perform user deletion actions without their consent. The application's user deletion endpoint (e.g., superadmin_user_delete.php) accepts POST requests containing a user_id parameter and does not enforce request origin or anti-CSRF tokens. Because the endpoint lacks proper authentication/authorization checks and CSRF protections, a remote attacker can craft a malicious page that triggers deletion when visited by an authenticated admin, resulting in arbitrary removal of user accounts.
CWE-352 Nov 10, 2025
CVE-2025-63710 6.5 MEDIUM 1 Writeup EPSS 0.00
SourceCodester Simple Public Chat Room 1.0 - CSRF
The send_message.php endpoint in SourceCodester Simple Public Chat Room 1.0 is vulnerable to Cross-Site Request Forgery (CSRF). The application does not implement any CSRF-protection mechanisms such as tokens, nonces, or same-site cookie restrictions. An attacker can create a malicious HTML page that, when visited by an authenticated user, will automatically submit a forged POST request to the vulnerable endpoint. This request will be executed with the victim's privileges, allowing the attacker to perform unauthorized actions on their behalf, such as sending arbitrary messages in any chat room.
CWE-352 Nov 10, 2025
CVE-2025-63717 6.5 MEDIUM 1 Writeup EPSS 0.00
SourceCodester Pet Grooming Management Software 1.0 - CSRF
The change password functionality at /pet_grooming/admin/change_pass.php in SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks. The application does not implement adequate anti-CSRF tokens or same-site cookie restrictions, allowing attackers to trick authenticated users into unknowingly changing their passwords.
CWE-352 Nov 07, 2025
CVE-2025-63716 6.5 MEDIUM 1 Writeup EPSS 0.00
SourceCodester Leads Manager Tool v1.0 - CSRF
The SourceCodester Leads Manager Tool v1.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow unauthorized state-changing operations. The application lacks CSRF protection mechanisms such as anti-CSRF tokens or same-origin verification for critical endpoints.
CWE-352 Nov 07, 2025
CVE-2025-58469 8.8 HIGH EPSS 0.00
QuLog Center <1.8.2.927 - CSRF
A cross-site request forgery (CSRF) vulnerability has been reported to affect QuLog Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities. We have already fixed the vulnerability in the following version: QuLog Center 1.8.2.927 ( 2025/09/17 ) and later
CWE-352 Nov 07, 2025
CVE-2025-62950 4.3 MEDIUM 1 PoC Analysis EPSS 0.00
Contest Gallery <28.0.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Cross Site Request Forgery.This issue affects Contest Gallery: from n/a through <= 28.0.0.
CWE-352 Nov 06, 2025
CVE-2025-53316 8.8 HIGH EPSS 0.00
Shahjahan Jewel WP GDPR Cookie Consent - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel WP GDPR Cookie Consent wp-gdpr-cookie-consent allows Stored XSS.This issue affects WP GDPR Cookie Consent: from n/a through <= 1.0.0.
CWE-352 Nov 06, 2025
CVE-2025-48085 8.8 HIGH EPSS 0.00
ZIPANG Simple Stripe <=0.9.17 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in ZIPANG Simple Stripe simple-stripe allows Stored XSS.This issue affects Simple Stripe: from n/a through <= 0.9.17.
CWE-352 Nov 06, 2025