Total
4240 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-5959 | 1 Metalgenix | 1 Genixcms | 2019-10-02 | 7.5 HIGH | 9.8 CRITICAL |
CSRF token bypass in GeniXCMS before 1.0.2 could result in escalation of privileges. The forgotpassword.php page can be used to acquire a token. | |||||
CVE-2017-16780 | 1 Mybb | 1 Mybb | 2019-10-02 | 7.5 HIGH | 9.8 CRITICAL |
The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file. | |||||
CVE-2017-8928 | 1 Mailcow | 1 Mailcow\ | 2019-10-02 | 6.8 MEDIUM | 8.8 HIGH |
mailcow 0.14, as used in "mailcow: dockerized" and other products, has CSRF. | |||||
CVE-2018-17789 | 1 Prospecta | 1 Master Data Online | 2019-09-30 | 4.3 MEDIUM | 6.5 MEDIUM |
Prospecta Master Data Online (MDO) allows CSRF. | |||||
CVE-2016-2863 | 1 Ibm | 1 Websphere Commerce | 2019-09-30 | 6.0 MEDIUM | 8.0 HIGH |
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Commerce 7.0 Feature Pack 8, 8.0.0.x before 8.0.0.10, and 8.0.1.x before 8.0.1.2 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences. | |||||
CVE-2015-5007 | 1 Ibm | 1 Websphere Commerce | 2019-09-30 | 6.8 MEDIUM | 8.8 HIGH |
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Commerce 6.0 through 6.0.0.11, 7.0 through 7.0.0.9, and 7.0 Feature Pack 8 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences. | |||||
CVE-2015-0970 | 1 Searchblox | 1 Searchblox | 2019-09-27 | 6.8 MEDIUM | 8.8 HIGH |
Cross-site request forgery (CSRF) vulnerability in SearchBlox before 8.2 allows remote attackers to hijack the authentication of arbitrary users. | |||||
CVE-2015-9418 | 1 Kibokolabs | 1 Watupro | 2019-09-27 | 5.8 MEDIUM | 4.3 MEDIUM |
The Watu Pro plugin before 4.9.0.8 for WordPress has CSRF that allows an attacker to delete quizzes. | |||||
CVE-2015-9440 | 1 Monetize Project | 1 Monetize | 2019-09-27 | 4.3 MEDIUM | 6.5 MEDIUM |
The monetize plugin through 1.03 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=monetize-zones-new. | |||||
CVE-2015-9441 | 1 Bookmarkify Project | 1 Bookmarkify | 2019-09-27 | 4.3 MEDIUM | 6.5 MEDIUM |
The bookmarkify plugin 2.9.2 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=bookmarkify.php. | |||||
CVE-2015-9442 | 1 Avenirsoft | 1 Directdownload | 2019-09-27 | 4.3 MEDIUM | 6.5 MEDIUM |
The avenirsoft-directdownload plugin 1.0 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=avenir_plugin. | |||||
CVE-2015-9443 | 1 Wp Accurate Form Data Project | 1 Wp Accurate Form Data | 2019-09-27 | 4.3 MEDIUM | 6.5 MEDIUM |
The accurate-form-data-real-time-form-validation plugin 1.2 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=Accu_Data_WP. | |||||
CVE-2015-9447 | 1 Unitegallery | 1 Unite Gallery Lite | 2019-09-27 | 4.3 MEDIUM | 6.5 MEDIUM |
The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin.php galleryid or id parameters. | |||||
CVE-2015-9413 | 1 Eshop Project | 1 Eshop | 2019-09-27 | 4.3 MEDIUM | 6.5 MEDIUM |
The eshop plugin through 6.3.13 for WordPress has CSRF with resultant XSS via the wp-admin/admin.php?page=eshop-downloads.php title parameter. | |||||
CVE-2015-9445 | 1 Unitegallery | 1 Unite Gallery Lite | 2019-09-26 | 6.8 MEDIUM | 8.8 HIGH |
The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin-ajax.php in a unitegallery_ajax_action operation. | |||||
CVE-2018-17792 | 1 Altn | 1 Mdaemon Webmail | 2019-09-26 | 6.8 MEDIUM | 8.8 HIGH |
MDaemon Webmail (formerly WorldClient) has CSRF. | |||||
CVE-2015-9417 | 1 Slidervilla | 1 Testimonial Slider | 2019-09-26 | 4.3 MEDIUM | 6.5 MEDIUM |
The testimonial-slider plugin through 1.2.1 for WordPress has CSRF with resultant XSS. | |||||
CVE-2015-9422 | 1 Simplysymphony | 1 Plugnedit | 2019-09-26 | 4.3 MEDIUM | 6.5 MEDIUM |
The PlugNedit Adaptive Editor plugin before 6.2.0 for WordPress has CSRF with resultant XSS via wp-admin/admin-ajax.php?action=simple_fields_field_type_post_dialog_load plugnedit_width, pnemedcount, PlugneditBGColor, PlugneditEditorMargin, or plugneditcontent parameters. | |||||
CVE-2015-9421 | 1 Olevmedia | 1 Olevmedia Shortcodes | 2019-09-26 | 4.3 MEDIUM | 6.5 MEDIUM |
The olevmedia-shortcodes plugin before 1.1.9 for WordPress has CSRF with resultant XSS via the wp-admin/admin-ajax.php?action=omsc_popup id parameter. | |||||
CVE-2015-9433 | 1 Wp Social Bookmarking Light Project | 1 Wp Social Bookmarking Light | 2019-09-26 | 4.3 MEDIUM | 6.5 MEDIUM |
The wp-social-bookmarking-light plugin before 1.7.10 for WordPress has CSRF with resultant XSS via configuration parameters for Tumblr, Twitter, Facebook, etc. in wp-admin/options-general.php?page=wp-social-bookmarking-light%2Fmodules%2Fadmin.php. |