Total
7225 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2024-7423 | 1 Xwp | 1 Stream | 2024-09-26 | N/A | 8.8 HIGH |
The Stream plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.1. This is due to missing or incorrect nonce validation on the network_options_action() function. This makes it possible for unauthenticated attackers to update arbitrary options that can lead to DoS or privilege escalation via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |||||
CVE-2024-8795 | 1 Ba-booking | 1 Ba Book Everything | 2024-09-26 | N/A | 8.8 HIGH |
The BA Book Everything plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.20. This is due to missing or incorrect nonce validation on the my_account_update() function. This makes it possible for unauthenticated attackers to update a user's account details via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. This can be leveraged to reset a user's password and gain access to their account. | |||||
CVE-2024-3163 | 1 Realestateconnected | 1 Easy Property Listings | 2024-09-26 | N/A | 4.3 MEDIUM |
The Easy Property Listings WordPress plugin before 3.5.4 does not have CSRF check when deleting contacts in bulk, which could allow attackers to make a logged in admin delete them via a CSRF attack | |||||
CVE-2024-46086 | 1 Frogcms Project | 1 Frogcms | 2024-09-25 | N/A | 8.8 HIGH |
FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/delete/123 | |||||
CVE-2024-46394 | 1 Frogcms Project | 1 Frogcms | 2024-09-25 | N/A | 8.8 HIGH |
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/?/user/add | |||||
CVE-2023-41801 | 1 Strategy11 | 1 Awp Classifieds | 2024-09-25 | N/A | 8.8 HIGH |
Cross-Site Request Forgery (CSRF) vulnerability in AWP Classifieds Team Ad Directory & Listings by AWP Classifieds plugin <= 4.3 versions. | |||||
CVE-2024-44064 | 1 Likebtn | 1 Like Button Rating | 2024-09-24 | N/A | 6.1 MEDIUM |
Cross-Site Request Forgery (CSRF) vulnerability in LikeBtn Like Button Rating allows Cross-Site Scripting (XSS).This issue affects Like Button Rating: from n/a through 2.6.54. | |||||
CVE-2024-6862 | 1 Lunary | 1 Lunary | 2024-09-19 | N/A | 8.1 HIGH |
A Cross-Site Request Forgery (CSRF) vulnerability exists in lunary-ai/lunary version 1.2.34 due to overly permissive CORS settings. This vulnerability allows an attacker to sign up for and create projects or use the instance as if they were a user with local access. The main attack vector is for instances hosted locally on personal machines, which are not publicly accessible. The CORS settings in the backend permit all origins, exposing unauthenticated endpoints to CSRF attacks. | |||||
CVE-2024-7161 | 1 Seacms | 1 Seacms | 2024-09-19 | N/A | 6.5 MEDIUM |
A vulnerability classified as problematic was found in SeaCMS 13.0. Affected by this vulnerability is an unknown functionality of the file /member.php?action=chgpwdsubmit of the component Password Change Handler. The manipulation of the argument newpwd/newpwd2 leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-272575. | |||||
CVE-2024-39641 | 1 Thimpress | 1 Learnpress | 2024-09-18 | N/A | 8.8 HIGH |
Cross-Site Request Forgery (CSRF) vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.6.8.2. | |||||
CVE-2024-39645 | 1 Themeum | 1 Tutor Lms | 2024-09-18 | N/A | 8.8 HIGH |
Cross-Site Request Forgery (CSRF) vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.7.2. | |||||
CVE-2024-39657 | 1 Sender | 1 Sender | 2024-09-18 | N/A | 8.8 HIGH |
Cross-Site Request Forgery (CSRF) vulnerability in Sender Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce.This issue affects Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce: from n/a through 2.6.18. | |||||
CVE-2024-43116 | 1 10up | 1 Simple Local Avatars | 2024-09-18 | N/A | 8.8 HIGH |
Cross-Site Request Forgery (CSRF) vulnerability in 10up Simple Local Avatars.This issue affects Simple Local Avatars: from n/a through 2.7.10. | |||||
CVE-2024-43117 | 1 Wpmudev | 1 Hummingbird | 2024-09-18 | N/A | 8.8 HIGH |
Cross-Site Request Forgery (CSRF) vulnerability in WPMU DEV Hummingbird.This issue affects Hummingbird: from n/a through 3.9.1. | |||||
CVE-2024-8120 | 1 Imagerecycle | 1 Imagerecycle Pdf \& Image Compression | 2024-09-17 | N/A | 4.3 MEDIUM |
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.14. This is due to missing or incorrect nonce validation on several functions in the class/class-image-otimizer.php file. This makes it possible for unauthenticated attackers to update plugin settings along with performing other actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |||||
CVE-2024-43255 | 1 Stormhillmedia | 1 Mybook Table Bookstore | 2024-09-17 | N/A | 6.1 MEDIUM |
Cross-Site Request Forgery (CSRF) vulnerability in Stormhill Media MyBookTable Bookstore allows Cross-Site Scripting (XSS).This issue affects MyBookTable Bookstore: from n/a through 3.3.9. | |||||
CVE-2024-5815 | 1 Github | 1 Enterprise Server | 2024-09-17 | N/A | 6.5 MEDIUM |
A Cross-Site Request Forgery vulnerability in GitHub Enterprise Server allowed write operations on a victim-owned repository by exploiting incorrect request types. A mitigating factor is that the attacker would have to be a trusted GitHub Enterprise Server user, and the victim would have to visit a tag in the attacker's fork of their own repository. vulnerability affected all versions of GitHub Enterprise Server prior 3.14 and was fixed in version 3.13.1, 3.12.6, 3.11.12, 3.10.14, and 3.9.17. This vulnerability was reported via the GitHub Bug Bounty program. | |||||
CVE-2022-29450 | 1 Admin Management Xtended Project | 1 Admin Management Xtended | 2024-09-17 | 6.8 MEDIUM | 8.8 HIGH |
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Admin Management Xtended plugin <= 2.4.4 at WordPress. | |||||
CVE-2022-38139 | 1 Rdstation | 1 Rd Station | 2024-09-16 | N/A | 8.8 HIGH |
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in RD Station plugin <= 5.2.0 at WordPress. | |||||
CVE-2022-38093 | 1 Aioseo | 1 All In One Seo | 2024-09-16 | N/A | 8.8 HIGH |
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in All in One SEO plugin <= 4.2.3.1 at WordPress. |