Total
7225 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-47163 | 1 Wp Csv To Database Project | 1 Wp Csv To Database | 2023-11-07 | N/A | 7.5 HIGH |
Cross-Site Request Forgery (CSRF) vulnerability in Tips and Tricks HQ, josh401 WP CSV to Database – Insert CSV file content into WordPress plugin <= 2.6 versions. | |||||
CVE-2022-4021 | 1 Permalink Manager Lite Project | 1 Permalink Manager Lite | 2023-11-07 | N/A | 4.3 MEDIUM |
The Permalink Manager Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2.20.1. This is due to missing or incorrect nonce validation on the extra_actions function. This makes it possible for unauthenticated attackers to change plugin settings including permalinks and site maps, via forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |||||
CVE-2022-47612 | 1 Xnau | 1 Participants Database | 2023-11-07 | N/A | 4.3 MEDIUM |
Cross-Site Request Forgery (CSRF) vulnerability in Roland Barker, xnau webdesign Participants Database plugin <= 2.4.5 leads to list column update. | |||||
CVE-2022-47443 | 1 Multi Rating Project | 1 Multi Rating | 2023-11-07 | N/A | 8.8 HIGH |
Cross-Site Request Forgery (CSRF) vulnerability in Daniel Powney Multi Rating plugin <= 5.0.5 versions. | |||||
CVE-2022-4090 | 1 Stock Management System Project | 1 Stock Management System | 2023-11-07 | N/A | 8.8 HIGH |
A vulnerability was found in rickxy Stock Management System and classified as problematic. This issue affects some unknown processing of the file us_transac.php?action=add. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-214331. | |||||
CVE-2022-46793 | 1 Adtribes | 1 Product Feed Pro For Woocommerce | 2023-11-07 | N/A | 8.8 HIGH |
Cross-Site Request Forgery (CSRF) vulnerability in AdTribes.Io Product Feed PRO for WooCommerce plugin <= 12.4.4 versions. | |||||
CVE-2022-45068 | 1 Mercadopago | 1 Mercado Pago Payments For Woocommerce | 2023-11-07 | N/A | 8.8 HIGH |
Cross-Site Request Forgery (CSRF) vulnerability in Mercado Pago Mercado Pago payments for WooCommerce plugin <= 6.3.1. | |||||
CVE-2022-45127 | 1 Sewio | 1 Real-time Location System Studio | 2023-11-07 | N/A | 8.1 HIGH |
Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 is vulnerable to cross-site request forgery in its backup services. An attacker could take advantage of this vulnerability to execute arbitrary backup operations and cause a denial-of-service condition. | |||||
CVE-2022-45804 | 1 Robogallery | 1 Robo Gallery | 2023-11-07 | N/A | 5.4 MEDIUM |
Cross-Site Request Forgery (CSRF) vulnerability in RoboSoft Photo Gallery, Images, Slider in Rbs Image Gallery plugin <= 3.2.9 leading to galleries hierarchy change, included plugin deactivate & activate. | |||||
CVE-2022-44585 | 1 Magneticlab | 1 Homepage Pop-up | 2023-11-07 | N/A | 8.8 HIGH |
Cross-Site Request Forgery (CSRF) vulnerability in Magneticlab Sàrl Homepage Pop-up plugin <= 1.2.5 versions. | |||||
CVE-2022-45807 | 1 Wpvibes | 1 Wp Mail Log | 2023-11-07 | N/A | 8.8 HIGH |
Cross-Site Request Forgery (CSRF) in WPVibes WP Mail Log plugin <= 1.0.1 versions. | |||||
CVE-2022-45067 | 1 Devscred | 1 Exclusive Addons For Elementor | 2023-11-07 | N/A | 8.8 HIGH |
Cross-Site Request Forgery (CSRF) vulnerability in DevsCred Exclusive Addons Elementor plugin <= 2.6.1 versions. | |||||
CVE-2022-44737 | 1 Tipsandtricks-hq | 1 All In One Wp Security \& Firewall | 2023-11-07 | N/A | 8.8 HIGH |
Multiple Cross-Site Request Forgery vulnerabilities in All-In-One Security (AIOS) – Security and Firewall (WordPress plugin) <= 5.1.0 on WordPress. | |||||
CVE-2022-45824 | 1 Elbtide | 1 Advanced Booking Calendar | 2023-11-07 | N/A | 6.5 MEDIUM |
Cross-Site Request Forgery (CSRF) vulnerability in Advanced Booking Calendar plugin <= 1.7.1 on WordPress. | |||||
CVE-2022-42435 | 1 Ibm | 1 Business Automation Workflow | 2023-11-07 | N/A | 8.8 HIGH |
IBM Business Automation Workflow 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, and 22.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 238054. | |||||
CVE-2022-43459 | 1 Captainform | 1 Captainform | 2023-11-07 | N/A | 8.8 HIGH |
Cross-Site Request Forgery (CSRF) vulnerability in Forms by CaptainForm – Form Builder for WordPress plugin <= 2.5.3 versions. | |||||
CVE-2022-41919 | 1 Fastify | 1 Fastify | 2023-11-07 | N/A | 8.8 HIGH |
Fastify is a web framework with minimal overhead and plugin architecture. The attacker can use the incorrect `Content-Type` to bypass the `Pre-Flight` checking of `fetch`. `fetch()` requests with Content-Type’s essence as "application/x-www-form-urlencoded", "multipart/form-data", or "text/plain", could potentially be used to invoke routes that only accepts `application/json` content type, thus bypassing any CORS protection, and therefore they could lead to a Cross-Site Request Forgery attack. This issue has been patched in version 4.10.2 and 3.29.4. As a workaround, implement Cross-Site Request Forgery protection using `@fastify/csrf'. | |||||
CVE-2022-43469 | 1 Orchestrated | 1 Corona Virus \(covid-19\) Banner \& Live Data | 2023-11-07 | N/A | 8.8 HIGH |
Cross-Site Request Forgery (CSRF) vulnerability in Orchestrated Corona Virus (COVID-19) Banner & Live Data plugin <= 1.7.0.6 versions. | |||||
CVE-2022-41297 | 1 Ibm | 3 Db2 On Cloud Pak For Data, Db2 Warehouse On Cloud Pak For Data, Db2u | 2023-11-07 | N/A | 6.5 MEDIUM |
IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 237212. | |||||
CVE-2022-41134 | 1 Optinly | 1 Optinly | 2023-11-07 | N/A | 8.8 HIGH |
Cross-Site Request Forgery (CSRF) in OptinlyHQ Optinly – Exit Intent, Newsletter Popups, Gamification & Opt-in Forms plugin <= 1.0.15 versions. |