CWE-352
Medium likelihoodCross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
9,352 vulnerabilities with CWE-352
CVE-2023-4937
MEDIUM
BEAR WooCommerce Bulk Editor <1.1.3.3 - Cross-Site Request Forgery
CVSS 4.3
CVE-2023-4935
MEDIUM
BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.1.3.3 - Cross-Site Request Forgery
CVSS 4.3
CVE-2023-4920
MEDIUM
BEAR for WordPress <= 1.1.3.3 - Cross-Site Request Forgery via woobe_save_options Function
CVSS 4.3
CVE-2023-44385
HIGH
Home Assistant Companion < 2023.7 - Client-Side Request Forgery via Malicious Links
CVSS 8.6
CVE-2023-45992
CRITICAL
RUCKUS Cloudpath <5.12.5538 - XSS/CSRF
CVSS 9.6
CVE-2023-42435
MEDIUM
dexgate - Cross-Site Request Forgery
CVSS 5.5
CVE-2023-3254
MEDIUM
Widgets for Google Reviews <= 10.9 - Cross-Site Request Forgery via setup_no_reg_header.php
CVSS 4.3
CVE-2023-5626
HIGH
Open Journal System < 3.3.0-16 - Cross-Site Request Forgery
CVSS 8.8
CVE-2023-45907
HIGH
Dreamer CMS 4.1.3 - Cross-Site Request Forgery via Variable Management Deletion
CVSS 8.8
CVE-2023-45906
HIGH
Dreamer CMS 4.1.3 - Cross-Site Request Forgery via User Add Endpoint
CVSS 8.8
CVE-2023-45905
HIGH
Dreamer CMS 4.1.3 - Cross-Site Request Forgery via Variable Management Add Functionality
CVSS 8.8
CVE-2023-45904
HIGH
Dreamer CMS 4.1.3 - Cross-Site Request Forgery via Variable Update Component
CVSS 8.8
CVE-2023-45903
HIGH
Dreamer CMS 4.1.3 - Cross-Site Request Forgery via Label Management Deletion
CVSS 8.8
CVE-2023-45902
HIGH
Dreamer CMS 4.1.3 - Cross-Site Request Forgery via Attachment Management Deletion
CVSS 8.8
CVE-2023-45901
HIGH
Dreamer CMS 4.1.3 - Cross-Site Request Forgery via /admin/category/add
CVSS 8.8
CVE-2023-45141
HIGH
Fiber < 2.50.0 - Cross-Site Request Forgery via Improper Token Validation
CVSS 8.6
CVE-2023-45128
CRITICAL
Fiber < 2.50.0 - Cross-Site Request Forgery via Improper CSRF Token Validation
CVSS 10.0
CVE-2023-43118
HIGH
Extreme Networks EXOS 31.7.0-31.7.1 - Cross-Site Request Forgery via /jsonrpc API
CVSS 8.8
CVE-2023-46087
MEDIUM
Mahlamusa Who Hit The Page - Hit Counter <1.4.14.3 - CSRF
CVSS 4.3
CVE-2023-45836
MEDIUM
XYDAC Ultimate Taxonomy Manager <= 2.0 - Cross-Site Request Forgery
CVSS 4.3
CVE-2023-45831
MEDIUM
AMP WP - Google AMP For WordPress <= 1.5.15 - Cross-Site Request Forgery
CVSS 5.4
CVE-2023-45763
MEDIUM
Taggbox < 2.9 - Cross-Site Request Forgery
CVSS 5.4
CVE-2023-45753
MEDIUM
Gilles Dumas which template file <= 4.6.0 - Cross-Site Request Forgery
CVSS 4.3
CVE-2023-45752
MEDIUM
10 Quality Post Gallery <= 2.3.12 - Cross-Site Request Forgery
CVSS 4.3
CVE-2023-45749
MEDIUM
AGP Font Awesome Collection <= 3.2.4 - Cross-Site Request Forgery
CVSS 4.3
Details
Vulnerabilities
9,352
Exploit Likelihood
Medium