Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-352
Total 4240 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-5959 1 Metalgenix 1 Genixcms 2019-10-02 7.5 HIGH 9.8 CRITICAL
CSRF token bypass in GeniXCMS before 1.0.2 could result in escalation of privileges. The forgotpassword.php page can be used to acquire a token.
CVE-2017-16780 1 Mybb 1 Mybb 2019-10-02 7.5 HIGH 9.8 CRITICAL
The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file.
CVE-2017-8928 1 Mailcow 1 Mailcow\ 2019-10-02 6.8 MEDIUM 8.8 HIGH
mailcow 0.14, as used in "mailcow: dockerized" and other products, has CSRF.
CVE-2018-17789 1 Prospecta 1 Master Data Online 2019-09-30 4.3 MEDIUM 6.5 MEDIUM
Prospecta Master Data Online (MDO) allows CSRF.
CVE-2016-2863 1 Ibm 1 Websphere Commerce 2019-09-30 6.0 MEDIUM 8.0 HIGH
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Commerce 7.0 Feature Pack 8, 8.0.0.x before 8.0.0.10, and 8.0.1.x before 8.0.1.2 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVE-2015-5007 1 Ibm 1 Websphere Commerce 2019-09-30 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Commerce 6.0 through 6.0.0.11, 7.0 through 7.0.0.9, and 7.0 Feature Pack 8 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
CVE-2015-0970 1 Searchblox 1 Searchblox 2019-09-27 6.8 MEDIUM 8.8 HIGH
Cross-site request forgery (CSRF) vulnerability in SearchBlox before 8.2 allows remote attackers to hijack the authentication of arbitrary users.
CVE-2015-9418 1 Kibokolabs 1 Watupro 2019-09-27 5.8 MEDIUM 4.3 MEDIUM
The Watu Pro plugin before 4.9.0.8 for WordPress has CSRF that allows an attacker to delete quizzes.
CVE-2015-9440 1 Monetize Project 1 Monetize 2019-09-27 4.3 MEDIUM 6.5 MEDIUM
The monetize plugin through 1.03 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=monetize-zones-new.
CVE-2015-9441 1 Bookmarkify Project 1 Bookmarkify 2019-09-27 4.3 MEDIUM 6.5 MEDIUM
The bookmarkify plugin 2.9.2 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=bookmarkify.php.
CVE-2015-9442 1 Avenirsoft 1 Directdownload 2019-09-27 4.3 MEDIUM 6.5 MEDIUM
The avenirsoft-directdownload plugin 1.0 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=avenir_plugin.
CVE-2015-9443 1 Wp Accurate Form Data Project 1 Wp Accurate Form Data 2019-09-27 4.3 MEDIUM 6.5 MEDIUM
The accurate-form-data-real-time-form-validation plugin 1.2 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=Accu_Data_WP.
CVE-2015-9447 1 Unitegallery 1 Unite Gallery Lite 2019-09-27 4.3 MEDIUM 6.5 MEDIUM
The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin.php galleryid or id parameters.
CVE-2015-9413 1 Eshop Project 1 Eshop 2019-09-27 4.3 MEDIUM 6.5 MEDIUM
The eshop plugin through 6.3.13 for WordPress has CSRF with resultant XSS via the wp-admin/admin.php?page=eshop-downloads.php title parameter.
CVE-2015-9445 1 Unitegallery 1 Unite Gallery Lite 2019-09-26 6.8 MEDIUM 8.8 HIGH
The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin-ajax.php in a unitegallery_ajax_action operation.
CVE-2018-17792 1 Altn 1 Mdaemon Webmail 2019-09-26 6.8 MEDIUM 8.8 HIGH
MDaemon Webmail (formerly WorldClient) has CSRF.
CVE-2015-9417 1 Slidervilla 1 Testimonial Slider 2019-09-26 4.3 MEDIUM 6.5 MEDIUM
The testimonial-slider plugin through 1.2.1 for WordPress has CSRF with resultant XSS.
CVE-2015-9422 1 Simplysymphony 1 Plugnedit 2019-09-26 4.3 MEDIUM 6.5 MEDIUM
The PlugNedit Adaptive Editor plugin before 6.2.0 for WordPress has CSRF with resultant XSS via wp-admin/admin-ajax.php?action=simple_fields_field_type_post_dialog_load plugnedit_width, pnemedcount, PlugneditBGColor, PlugneditEditorMargin, or plugneditcontent parameters.
CVE-2015-9421 1 Olevmedia 1 Olevmedia Shortcodes 2019-09-26 4.3 MEDIUM 6.5 MEDIUM
The olevmedia-shortcodes plugin before 1.1.9 for WordPress has CSRF with resultant XSS via the wp-admin/admin-ajax.php?action=omsc_popup id parameter.
CVE-2015-9433 1 Wp Social Bookmarking Light Project 1 Wp Social Bookmarking Light 2019-09-26 4.3 MEDIUM 6.5 MEDIUM
The wp-social-bookmarking-light plugin before 1.7.10 for WordPress has CSRF with resultant XSS via configuration parameters for Tumblr, Twitter, Facebook, etc. in wp-admin/options-general.php?page=wp-social-bookmarking-light%2Fmodules%2Fadmin.php.