Total
7225 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2015-9409 | 1 Alo-easymail Project | 1 Alo-easymail | 2019-09-26 | 4.3 MEDIUM | 6.5 MEDIUM |
The alo-easymail plugin before 2.6.01 for WordPress has CSRF with resultant XSS in pages/alo-easymail-admin-options.php. | |||||
CVE-2015-9434 | 1 Kiwi-logo-carousel Project | 1 Kiwi-logo-carousel | 2019-09-26 | 4.3 MEDIUM | 6.5 MEDIUM |
The kiwi-logo-carousel plugin before 1.7.2 for WordPress has CSRF with resultant XSS via the wp-admin/edit.php?post_type=kwlogos&page=kwlogos_settings tab or tab_flags_order parameter. | |||||
CVE-2019-16706 | 1 Kkcms Project | 1 Kkcms | 2019-09-23 | 6.8 MEDIUM | 8.8 HIGH |
kkcms v1.3 has a CSRF vulnerablity that can add an user account via admin/cms_user_add.php. | |||||
CVE-2019-16677 | 1 Idreamsoft | 1 Icms | 2019-09-23 | 5.8 MEDIUM | 6.5 MEDIUM |
An issue was discovered in idreamsoft iCMS V7.0. admincp.php?app=members&do=del allows CSRF. | |||||
CVE-2019-16721 | 1 5none | 1 Nonecms | 2019-09-23 | 5.8 MEDIUM | 6.5 MEDIUM |
NoneCMS v1.3 has CSRF in public/index.php/admin/admin/dele.html, as demonstrated by deleting the admin user. | |||||
CVE-2010-0289 | 1 Dokuwiki | 1 Dokuwiki | 2019-09-23 | 6.8 MEDIUM | N/A |
Multiple cross-site request forgery (CSRF) vulnerabilities in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25c allow remote attackers to hijack the authentication of administrators for requests that modify access control rules, and other unspecified requests, via unknown vectors. | |||||
CVE-2015-9388 | 1 Mtouch Quiz Project | 1 Mtouch Quiz | 2019-09-23 | 4.3 MEDIUM | 6.5 MEDIUM |
The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/edit.php CSRF with resultant XSS. | |||||
CVE-2015-9387 | 1 Mtouch Quiz Project | 1 Mtouch Quiz | 2019-09-23 | 4.3 MEDIUM | 6.5 MEDIUM |
The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/options-general.php CSRF. | |||||
CVE-2019-16678 | 1 Yzmcms | 1 Yzmcms | 2019-09-23 | 4.3 MEDIUM | 6.5 MEDIUM |
admin/urlrule/add.html in YzmCMS 5.3 allows CSRF with a resultant denial of service by adding a superseding route. | |||||
CVE-2019-16658 | 1 Tuzicms | 1 Tuzicms | 2019-09-23 | 6.8 MEDIUM | 8.8 HIGH |
TuziCMS 2.0.6 has index.php/manage/notice/do_add CSRF. | |||||
CVE-2018-16380 | 1 Digimute | 1 Ogma Cms | 2019-09-23 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in Ogma CMS 0.4 Beta. There is a CSRF vulnerability in users.php?action=createnew that can add an admin account. | |||||
CVE-2019-16659 | 1 Tuzicms | 1 Tuzicms | 2019-09-23 | 6.8 MEDIUM | 8.8 HIGH |
TuziCMS 2.0.6 has index.php/manage/link/do_add CSRF. | |||||
CVE-2019-16660 | 1 Joyplus Project | 1 Joyplus | 2019-09-23 | 6.8 MEDIUM | 8.8 HIGH |
joyplus-cms 1.6.0 has admin_ajax.php?action=savexml&tab=vodplay CSRF. | |||||
CVE-2015-9394 | 1 Usersultra | 1 Users Ultra Membership | 2019-09-20 | 6.8 MEDIUM | 8.8 HIGH |
The users-ultra plugin before 1.5.63 for WordPress has CSRF via action=package_add_new to wp-admin/admin-ajax.php. | |||||
CVE-2019-15089 | 1 Prise | 1 Adas | 2019-09-20 | 6.8 MEDIUM | 8.8 HIGH |
An issue was discovered in PRiSE adAS 1.7.0. Forms have no CSRF protection, letting an attacker execute actions as the administrator. | |||||
CVE-2015-9408 | 1 Cyberseo | 1 Xpinner Lite | 2019-09-20 | 4.3 MEDIUM | 6.5 MEDIUM |
The xpinner-lite plugin through 2.2 for WordPress has wp-admin/options-general.php CSRF with resultant XSS. | |||||
CVE-2016-10997 | 1 Yourinspirationweb | 1 Beauty-premium | 2019-09-20 | 4.3 MEDIUM | 6.5 MEDIUM |
The beauty-premium theme 1.0.8 for WordPress has CSRF with resultant arbitrary file upload in includes/sendmail.php. | |||||
CVE-2019-16531 | 1 Layerbb | 1 Layerbb | 2019-09-20 | 6.8 MEDIUM | 8.8 HIGH |
LayerBB before 1.1.4 has multiple CSRF issues, as demonstrated by changing the System Settings via admin/general.php. | |||||
CVE-2016-10989 | 1 Leenk | 1 Leenk.me | 2019-09-17 | 6.8 MEDIUM | 8.8 HIGH |
The leenkme plugin before 2.6.0 for WordPress has wp-admin/admin.php?page=leenkme_facebook CSRF. | |||||
CVE-2016-10974 | 1 Tonjoostudio | 1 Fluid-responsive-slideshow | 2019-09-17 | 6.8 MEDIUM | 8.8 HIGH |
The fluid-responsive-slideshow plugin before 2.2.7 for WordPress has frs_save CSRF with resultant stored XSS. |