CWE-352
Medium likelihoodCross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
9,348 vulnerabilities with CWE-352
CVE-2024-24593
CRITICAL
Allegro AI's ClearML <1.14.1 - CSRF
CVSS 9.6
CVE-2024-0859
MEDIUM
WordPress Affiliates Manager <2.9.34 - CSRF
CVSS 4.3
CVE-2024-0796
MEDIUM
WooCommerce <1.0.6.1 - CSRF
CVSS 4.3
CVE-2024-0790
MEDIUM
Pluginus Wolf - Wordpress Posts Bulk Editor And Products Manager Professional < 1.0.8.1 - CSRF
CVSS 5.4
CVE-2024-0660
MEDIUM
Formidable Forms < 6.7.2 - Cross-Site Request Forgery via Missing Nonce Validation
CVSS 6.1
CVE-2024-0428
HIGH
kobzarev/index_now <= 2.6.3 - Cross-Site Request Forgery via 'reset_form' Function
CVSS 7.1
CVE-2024-0374
MEDIUM
Views for WPForms <= 3.2.2 - Unauthenticated CSRF via 'create_view'
CVSS 4.3
CVE-2024-0373
MEDIUM
Views for WPForms < 3.2.2 - Cross-Site Request Forgery via 'save_view' Function
CVSS 4.3
CVE-2024-24469
HIGH
flusity-CMS 2.33 - Cross-Site Request Forgery to Code Execution via delete_post.php
CVSS 8.8
CVE-2024-24468
HIGH
flusity-CMS 2.33 - Cross-Site Request Forgery via add_customblock.php
CVSS 8.8
CVE-2024-24470
HIGH
flusity-CMS 2.33 - Cross-Site Request Forgery via update_post.php
CVSS 8.8
CVE-2024-23831
HIGH
LedgerSMB 1.3.0-1.10.29 - Cross-Site Request Forgery in setup.pl
CVSS 7.5
CVE-2024-24524
HIGH
flusity-CMS 2.33 - Cross-Site Request Forgery via add_menu.php
CVSS 8.8
CVE-2024-1162
MEDIUM
Orbit Fox by ThemeIsle <2.10.29 - CSRF
CVSS 4.3
CVE-2024-22859
HIGH
laravel/livewire < 3.0.4 - Cross-Site Request Forgery via getCsrfToken Function
CVSS 8.8
CVE-2024-22140
HIGH
Cozmoslabs Profile Builder Pro - CSRF
CVSS 8.8
CVE-2024-22136
MEDIUM
DroitThemes Droit Elementor Addons - CSRF
CVSS 4.3
CVE-2024-22304
MEDIUM
Borbis Media FreshMail For WordPress <2.3.2 - CSRF
CVSS 5.4
CVE-2024-22291
MEDIUM
Marco Milesi Browser Theme Color - CSRF
CVSS 4.3
CVE-2024-22285
MEDIUM
Elise Bosse Frontpage Manager - CSRF
CVSS 5.4
CVE-2024-22143
MEDIUM
WP Spell Check <9.17 - CSRF
CVSS 5.4
CVE-2024-22290
HIGH
AboZain,O7abeeb,UnitOne Custom Dashboard Widgets <1.3.1 - CSRF/XSS
CVSS 7.1
CVE-2024-22287
HIGH
Better Anchor Links <1.7.5 - CSRF/XSS
CVSS 7.1
CVE-2024-22643
MEDIUM
SEO Panel 4.10.0 - Cross-Site Request Forgery via Password Reset
CVSS 6.5
CVE-2024-0667
MEDIUM
10web Form Maker < 1.15.21 - Cross-Site Request Forgery via Missing Nonce Validation
CVSS 5.4
Details
Vulnerabilities
9,348
Exploit Likelihood
Medium