CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,278 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,568 researchers
8,801 results Clear all
CVE-2025-9944 4.3 MEDIUM EPSS 0.00
Professional Contact Form <1.0.0 - CSRF
The Professional Contact Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on the watch_for_contact_form_submit function. This makes it possible for unauthenticated attackers to trigger test email sending via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Sep 27, 2025
CVE-2025-9899 6.1 MEDIUM EPSS 0.00
Trust Reviews plugin - CSRF
The Trust Reviews plugin for Google, Tripadvisor, Yelp, Airbnb and other platforms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the feed_save function. This makes it possible for unauthenticated attackers to create or modify feed entries via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Sep 27, 2025
CVE-2025-9898 4.3 MEDIUM EPSS 0.00
cForms - Light speed fast Form Builder <3.0.0 - CSRF
The cForms – Light speed fast Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.0. This is due to missing or incorrect nonce validation on the cforms_api function. This makes it possible for unauthenticated attackers to modify forms and their settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Sep 27, 2025
CVE-2025-9896 4.3 MEDIUM EPSS 0.00
HidePost WordPress <2.3.8 - CSRF
The HidePost plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.8. This is due to missing or incorrect nonce validation on the options.php settings page. This makes it possible for unauthenticated attackers to modify plugin settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Sep 27, 2025
CVE-2025-9894 4.3 MEDIUM EPSS 0.00
Sync Feedly plugin - CSRF
The Sync Feedly plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the crsf_cron_job_func function. This makes it possible for unauthenticated attackers to trigger content synchronization from Feedly, potentially creating multiple posts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Sep 27, 2025
CVE-2025-9893 4.3 MEDIUM EPSS 0.00
VM Menu Reorder plugin <1.0.0 - CSRF
The VM Menu Reorder plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on the vm_set_to_default function. This makes it possible for unauthenticated attackers to reset all menu reordering settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Sep 27, 2025
CVE-2025-11051 4.3 MEDIUM EPSS 0.00
SourceCodester Pet Grooming Mgmt <1.0 - CSRF
A vulnerability has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack is possible to be carried out remotely.
CWE-862 Sep 27, 2025
CVE-2025-10499 4.3 MEDIUM EPSS 0.00
Ninjaforms Ninja Forms < 3.12.1 - CSRF
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.12.0. This is due to missing or incorrect nonce validation on the maybe_opt_in() function. This makes it possible for unauthenticated attackers to opt an affected site into usage statistics collection via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
CWE-352 Sep 27, 2025
CVE-2025-10498 4.3 MEDIUM EPSS 0.00
Ninjaforms Ninja Forms < 3.12.1 - CSRF
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.12.0. This is due to missing or incorrect nonce validation when exporting CSV files. This makes it possible for unauthenticated attackers to delete those files granted they can trick an administrator into performing an action such as clicking on a link.
CWE-352 Sep 27, 2025
CVE-2024-43192 6.5 MEDIUM EPSS 0.00
IBM Storage TS4500 Library - CSRF
IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
CWE-352 Sep 27, 2025
CVE-2025-59845 8.2 HIGH EPSS 0.00
Apollo Sandbox < 2.7.2 - CSRF
Apollo Studio Embeddable Explorer & Embeddable Sandbox are website embeddable software solutions from Apollo GraphQL. Prior to Apollo Sandbox version 2.7.2 and Apollo Explorer version 3.7.3, a cross-site request forgery (CSRF) vulnerability was identified. The vulnerability arises from missing origin validation in the client-side code that handles window.postMessage events. A malicious website can send forged messages to the embedding page, causing the victim’s browser to execute arbitrary GraphQL queries or mutations against their GraphQL server while authenticated with the victim’s cookies. This issue has been patched in Apollo Sandbox version 2.7.2 and Apollo Explorer version 3.7.3.
CWE-346 Sep 26, 2025
CVE-2025-11029 4.3 MEDIUM EPSS 0.00
givanz Vvveb <1.0.7.2 - CSRF
A weakness has been identified in givanz Vvveb up to 1.0.7.2. This vulnerability affects unknown code. Executing manipulation can lead to cross-site request forgery. The attack can be executed remotely. The exploit has been made available to the public and could be exploited. Once again the project maintainer reacted very professional: "I accept the existence of these vulnerabilities. (...) I fixed the code to remove these vulnerabilities and will push the code to github and make a new release."
CWE-862 Sep 26, 2025
CVE-2025-60173 7.1 HIGH EPSS 0.00
Ashwani kumar GST for WooCommerce <2.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Ashwani kumar GST for WooCommerce allows Stored XSS. This issue affects GST for WooCommerce: from n/a through 2.0.
CWE-352 Sep 26, 2025
CVE-2025-60172 7.1 HIGH EPSS 0.00
Flytedesk Digital <20181101 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in flytedesk Flytedesk Digital allows Stored XSS. This issue affects Flytedesk Digital: from n/a through 20181101.
CWE-352 Sep 26, 2025
CVE-2025-60171 7.1 HIGH EPSS 0.00
YourPlugins.com - WooCommerce <1.2.10 - CSRF/XSS
Cross-Site Request Forgery (CSRF) vulnerability in yourplugins Conditional Cart Messages for WooCommerce &#8211; YourPlugins.com allows Stored XSS. This issue affects Conditional Cart Messages for WooCommerce &#8211; YourPlugins.com: from n/a through 1.2.10.
CWE-352 Sep 26, 2025
CVE-2025-60170 7.1 HIGH EPSS 0.00
Taraprasad Swain HTACCESS IP Blocker <1.0 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in Taraprasad Swain HTACCESS IP Blocker allows Stored XSS. This issue affects HTACCESS IP Blocker: from n/a through 1.0.
CWE-352 Sep 26, 2025
CVE-2025-60169 7.1 HIGH EPSS 0.00
W3SCloud Contact Form 7 to Zoho CRM - XSS
Cross-Site Request Forgery (CSRF) vulnerability in W3S Cloud Technology W3SCloud Contact Form 7 to Zoho CRM allows Stored XSS. This issue affects W3SCloud Contact Form 7 to Zoho CRM: from n/a through 3.0.
CWE-352 Sep 26, 2025
CVE-2025-60164 7.1 HIGH EPSS 0.00
NewsmanApp <2.7.7 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in NewsMAN NewsmanApp allows Stored XSS. This issue affects NewsmanApp: from n/a through 2.7.7.
CWE-352 Sep 26, 2025
CVE-2025-60156 9.6 CRITICAL EPSS 0.00
Webandprint AR For WordPress - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in webandprint AR For WordPress allows Upload a Web Shell to a Web Server. This issue affects AR For WordPress: from n/a through 7.98.
CWE-352 Sep 26, 2025
CVE-2025-60145 4.3 MEDIUM EPSS 0.00
Lenix scss compiler <1.3 - CSRF
Cross-Site Request Forgery (CSRF) vulnerability in yonifre Lenix scss compiler allows Cross Site Request Forgery. This issue affects Lenix scss compiler: from n/a through 1.2.
CWE-352 Sep 26, 2025