CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,283 with exploits 4,731 exploited in wild 1,542 CISA KEV 3,930 Nuclei templates 37,826 vendors 42,577 researchers
8,801 results Clear all
CVE-2024-8032 6.1 MEDIUM EPSS 0.00
Smooth Gallery Replacement <1.0 - XSS
The Smooth Gallery Replacement WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
CWE-352 May 15, 2025
CVE-2024-7984 4.3 MEDIUM EPSS 0.00
Joy Of Text Lite <2.3.1 - CSRF
The Joy Of Text Lite WordPress plugin through 2.3.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CWE-352 May 15, 2025
CVE-2024-6719 8.1 HIGH EPSS 0.00
Offload Videos <1.0.1 - CSRF
The Offload Videos WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow low privilege users to update them via a CSRF attack
CWE-352 May 15, 2025
CVE-2024-12750 4.3 MEDIUM EPSS 0.00
Raiserweb Competition Form < 2.0 - CSRF
The Competition Form WordPress plugin through 2.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CWE-352 May 15, 2025
CVE-2024-12301 6.5 MEDIUM EPSS 0.00
Joomlaserviceprovider Jsp Store Locator < 1.0 - CSRF
The JSP Store Locator WordPress plugin through 1.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.
CWE-352 May 15, 2025
CVE-2024-12282 6.1 MEDIUM EPSS 0.00
Smyx Wp-connect < 2.5.6 - CSRF
The WordPress连接微博 WordPress plugin through 2.5.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
CWE-352 May 15, 2025
CVE-2024-11719 6.1 MEDIUM EPSS 0.00
Tarteaucitron-wp <0.3.0 - XSS
The tarteaucitron-wp WordPress plugin before 0.3.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
CWE-352 May 15, 2025
CVE-2024-11373 4.3 MEDIUM EPSS 0.00
Connexion Logs WP <3.0.2 - CSRF
The Connexion Logs WordPress plugin through 3.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CWE-352 May 15, 2025
CVE-2024-10677 4.3 MEDIUM EPSS 0.00
Bluetrait Blue Trait Event Viewer < 2.0.2 - CSRF
The BTEV WordPress plugin through 2.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CWE-352 May 15, 2025
CVE-2024-10634 4.3 MEDIUM EPSS 0.00
Nokautpl Nokaut Offers Box < 1.4.0 - CSRF
The Nokaut Offers Box WordPress plugin through 1.4.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin reset the Nokaut Offers Box WordPress plugin through 1.4.0 via a CSRF attack
CWE-352 May 15, 2025
CVE-2023-7297 3.5 LOW EPSS 0.00
Reneade Twitterposts < 1.0.2 - CSRF
The TwitterPosts WordPress plugin through 1.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CWE-352 May 15, 2025
CVE-2023-7229 5.5 MEDIUM EPSS 0.00
Evanliewer Illi Link Party! < 1.0 - CSRF
The illi Link Party! WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.
CWE-352 May 15, 2025
CVE-2023-7197 7.1 HIGH EPSS 0.00
Corbyboy Marketing Twitter Bot < 1.11 - CSRF
The Marketing Twitter Bot WordPress plugin through 1.11 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
CWE-352 May 15, 2025
CVE-2023-7196 4.3 MEDIUM EPSS 0.00
Jonkemp Ultimate Noindex Nofollow Tool < 1.1.2 - CSRF
The Ultimate Noindex Nofollow Tool WordPress plugin through 1.1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CWE-352 May 15, 2025
CVE-2023-7195 4.3 MEDIUM EPSS 0.00
Ani2life Wp-reply Notify < 1.1 - CSRF
The WP-Reply Notify WordPress plugin through 1.1 does not have a CSRF check in place when updating its settings, which could allow attackers to make a logged-in admin change them via a CSRF attack.
CWE-352 May 15, 2025
CVE-2023-7174 7.1 HIGH EPSS 0.00
Abitgone Commentsafe < 1.0.0 - CSRF
The aBitGone CommentSafe WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
CWE-352 May 15, 2025
CVE-2023-5934 7.3 HIGH EPSS 0.00
Travelpayouts < 1.1.13 - CSRF
The Travelpayouts: All Travel Brands in One Place WordPress plugin before 1.1.13 does not have CSRF check in place when importing settings from the v1, which could allow attackers to make a logged in admin update some settings via a CSRF attack
CWE-352 May 15, 2025
CVE-2023-2334 5.4 MEDIUM EPSS 0.00
edd-google-sheet-connector-pro <1.4/Easy Digital Downloads Google S...
The edd-google-sheet-connector-pro WordPress plugin before 1.4, Easy Digital Downloads Google Sheet Connector WordPress plugin before 1.6.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack
CWE-352 May 15, 2025
CVE-2025-32922 7.1 HIGH EPSS 0.00
Tobias WP2LEADS -<3.5.0 - XSS
Cross-Site Request Forgery (CSRF) vulnerability in Tobias WP2LEADS allows Stored XSS.This issue affects WP2LEADS: from n/a through 3.5.0.
CWE-352 May 15, 2025
CVE-2025-44185 5.4 MEDIUM 1 Writeup EPSS 0.00
Mayurik Best Employee Management System - CSRF
SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/change_pass.php via the password parameter.
CWE-352 May 15, 2025