Total
7225 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2025-39351 | 2025-05-19 | N/A | N/A | ||
Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Restaurant WordPress allows Cross Site Request Forgery.This issue affects Grand Restaurant WordPress: from n/a through 7.0. | |||||
CVE-2025-39375 | 2025-05-19 | N/A | N/A | ||
Cross-Site Request Forgery (CSRF) vulnerability in Ashok G Easy Child Theme Creator allows Cross Site Request Forgery.This issue affects Easy Child Theme Creator: from n/a through 1.3.1. | |||||
CVE-2025-47583 | 2025-05-19 | N/A | N/A | ||
Unauthenticated Cross Site Request Forgery (CSRF) in Salon booking system <= 10.16 versions. | |||||
CVE-2024-5935 | 1 Pribai | 1 Privategpt | 2025-05-19 | N/A | 5.4 MEDIUM |
A Cross-Site Request Forgery (CSRF) vulnerability in version 0.5.0 of imartinez/privategpt allows an attacker to delete all uploaded files on the server. This can lead to data loss and service disruption for the application's users. | |||||
CVE-2025-48344 | 2025-05-19 | N/A | N/A | ||
Cross-Site Request Forgery (CSRF) vulnerability in ed4becky Rootspersona allows Cross Site Request Forgery. This issue affects Rootspersona: from n/a through 3.7.5. | |||||
CVE-2025-48259 | 2025-05-19 | N/A | N/A | ||
Cross-Site Request Forgery (CSRF) vulnerability in Juan Carlos WP Mapa Politico España allows Cross Site Request Forgery. This issue affects WP Mapa Politico España: from n/a through 3.8.0. | |||||
CVE-2025-48342 | 2025-05-19 | N/A | N/A | ||
Cross-Site Request Forgery (CSRF) vulnerability in RedefiningTheWeb Dynamic Pricing & Discounts Lite for WooCommerce allows Cross Site Request Forgery. This issue affects Dynamic Pricing & Discounts Lite for WooCommerce: from n/a through 2.0.3. | |||||
CVE-2025-48264 | 2025-05-19 | N/A | N/A | ||
Cross-Site Request Forgery (CSRF) vulnerability in artiosmedia Product Code for WooCommerce allows Cross Site Request Forgery. This issue affects Product Code for WooCommerce: from n/a through 1.5.0. | |||||
CVE-2025-48285 | 2025-05-19 | N/A | N/A | ||
Cross-Site Request Forgery (CSRF) vulnerability in sbouey Falang multilanguage allows Cross Site Request Forgery. This issue affects Falang multilanguage: from n/a through 1.3.61. | |||||
CVE-2025-48238 | 2025-05-19 | N/A | N/A | ||
Cross-Site Request Forgery (CSRF) vulnerability in awcode AWcode Toolkit allows Stored XSS. This issue affects AWcode Toolkit: from n/a through 1.0.18. | |||||
CVE-2025-48265 | 2025-05-19 | N/A | N/A | ||
Cross-Site Request Forgery (CSRF) vulnerability in Pektsekye Year Make Model Search for WooCommerce allows Cross Site Request Forgery. This issue affects Year Make Model Search for WooCommerce: from n/a through 1.0.11. | |||||
CVE-2025-48243 | 2025-05-19 | N/A | N/A | ||
Cross-Site Request Forgery (CSRF) vulnerability in Bill Minozzi reCAPTCHA for all allows Cross Site Request Forgery. This issue affects reCAPTCHA for all: from n/a through 2.26. | |||||
CVE-2025-48233 | 2025-05-19 | N/A | N/A | ||
Cross-Site Request Forgery (CSRF) vulnerability in affmngr Affiliates Manager Google reCAPTCHA Integration allows Stored XSS. This issue affects Affiliates Manager Google reCAPTCHA Integration: from n/a through 1.0.6. | |||||
CVE-2025-48284 | 2025-05-19 | N/A | N/A | ||
Cross-Site Request Forgery (CSRF) vulnerability in shohei.tanaka Japanized For WooCommerce allows Cross Site Request Forgery. This issue affects Japanized For WooCommerce: from n/a through 2.6.40. | |||||
CVE-2024-4758 | 1 Realwebcare | 1 Muslim Prayer Time Bd | 2025-05-19 | N/A | N/A |
The Muslim Prayer Time BD WordPress plugin through 2.4 does not have CSRF check in place when reseting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack | |||||
CVE-2024-5287 | 1 Tipsandtricks-hq | 1 Wp Affiliate Platform | 2025-05-19 | N/A | N/A |
The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in user change them via a CSRF attack | |||||
CVE-2024-5284 | 1 Tipsandtricks-hq | 1 Wp Affiliate Platform | 2025-05-19 | N/A | N/A |
The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack | |||||
CVE-2024-5280 | 1 Tipsandtricks-hq | 1 Wp Affiliate Platform | 2025-05-19 | N/A | N/A |
The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make non-logged in users execute an XSS payload via a CSRF attack | |||||
CVE-2024-3642 | 1 Mndpsingh287 | 1 Newsletter Popup | 2025-05-19 | N/A | N/A |
The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting subscriber, which could allow attackers to make logged in admins perform such action via a CSRF attack | |||||
CVE-2024-3643 | 1 Mndpsingh287 | 1 Newsletter Popup | 2025-05-19 | N/A | N/A |
The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting list, which could allow attackers to make logged in admins perform such action via a CSRF attack |