Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-352
Total 4240 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-16966 1 File Manager Project 1 File Manager 2019-09-02 6.8 MEDIUM 8.8 HIGH
There is a CSRF vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter.
CVE-2015-4089 1 Wpfastestcache 1 Wp Fastest Cache 2019-08-31 6.8 MEDIUM 8.8 HIGH
Multiple cross-site request forgery (CSRF) vulnerabilities in the optionsPageRequest function in admin.php in WP Fastest Cache plugin before 0.8.3.5 for WordPress allow remote attackers to hijack the authentication of unspecified victims for requests that call the (1) saveOption, (2) deleteCache, (3) deleteCssAndJsCache, or (4) addCacheTimeout method via the wpFastestCachePage parameter in the WpFastestCacheOptions/ page.
CVE-2019-15781 1 Weblizar 1 Social Likebox \& Feed 2019-08-30 6.8 MEDIUM 8.8 HIGH
The facebook-by-weblizar plugin before 2.8.5 for WordPress has CSRF.
CVE-2019-15496 1 Manageyourteam 1 Myt Project Management 2019-08-30 6.8 MEDIUM 8.8 HIGH
MyT Project Management 1.5.1 lacks CSRF protection and, for example, allows a user/create CSRF attack. This could lead to an attacker tricking the administrator into executing arbitrary code via a specially crafted HTML page.
CVE-2019-14999 1 Atlassian 1 Universal Plugin Manager 2019-08-30 4.3 MEDIUM 4.3 MEDIUM
The Uninstall REST endpoint in Atlassian Universal Plugin Manager before version 2.22.19, from version 3.0.0 before version 3.0.3 and from version 4.0.0 before version 4.0.3 allows remote attackers to uninstall plugins using a Cross-Site Request Forgery (CSRF) vulnerability on an authenticated administrator.
CVE-2019-15515 1 Discourse 1 Discourse 2019-08-29 4.3 MEDIUM 6.5 MEDIUM
Discourse 2.3.2 sends the CSRF token in the query string.
CVE-2019-10057 1 Lexmark 50 Cs31x, Cs31x Firmware, Cs41x and 47 more 2019-08-29 4.3 MEDIUM 6.5 MEDIUM
Various Lexmark products have CSRF.
CVE-2018-14668 1 Yandex 1 Clickhouse 2019-08-29 6.8 MEDIUM 8.8 HIGH
In ClickHouse before 1.1.54388, "remote" table function allowed arbitrary symbols in "user", "password" and "default_database" fields which led to Cross Protocol Request Forgery Attacks.
CVE-2015-9343 1 Impress 1 Wp Rollback 2019-08-29 6.8 MEDIUM 8.8 HIGH
The wp-rollback plugin before 1.2.3 for WordPress has CSRF.
CVE-2014-10382 1 Pippinsplugins 1 Featured Comments 2019-08-29 4.3 MEDIUM 4.3 MEDIUM
The feature-comments plugin before 1.2.5 for WordPress has CSRF for featuring or burying a comment.
CVE-2018-21002 1 Joomsky 1 Js Help Desk 2019-08-28 6.8 MEDIUM 8.8 HIGH
The js-support-ticket plugin before 2.0.6 for WordPress has CSRF.
CVE-2019-15660 1 Wp-members Project 1 Wp-members 2019-08-28 6.8 MEDIUM 8.8 HIGH
The wp-members plugin before 3.2.8 for WordPress has CSRF.
CVE-2018-21006 1 Bbpress Move Topics Project 1 Bbpress Move Topics 2019-08-28 6.8 MEDIUM 8.8 HIGH
The bbp-move-topics plugin before 1.1.6 for WordPress has CSRF.
CVE-2019-15645 1 Zoho 1 Salesiq 2019-08-28 6.8 MEDIUM 8.8 HIGH
The zoho-salesiq plugin before 1.0.9 for WordPress has CSRF.
CVE-2019-14526 1 Netgear 2 Mr1100, Mr1100 Firmware 2019-08-27 5.8 MEDIUM 8.1 HIGH
An issue was discovered on NETGEAR Nighthawk M1 (MR1100) devices before 12.06.03. The web-interface Cross-Site Request Forgery token is stored in a dynamically generated JavaScript file, and therefore can be embedded in third party pages, and re-used against the Nighthawk web interface. This entirely bypasses the intended security benefits of the use of a CSRF-protection token.
CVE-2019-15491 1 It-novum 1 Openitcockpit 2019-08-26 6.8 MEDIUM 8.8 HIGH
openITCOCKPIT before 3.7.1 has CSRF, aka RVID 2-445b21.
CVE-2016-10918 1 Supsystic 1 Photo Gallery 2019-08-26 6.8 MEDIUM 8.8 HIGH
The gallery-by-supsystic plugin before 1.8.6 for WordPress has CSRF.
CVE-2019-15229 1 Thedaylightstudio 1 Fuel Cms 2019-08-26 6.8 MEDIUM 8.8 HIGH
FUEL CMS 1.4.4 has CSRF in the blocks/create/ Create Blocks section of the Admin console. This could lead to an attacker tricking the administrator into executing arbitrary code via a specially crafted HTML page.
CVE-2019-15329 1 Codection 1 Import Users From Csv With Meta 2019-08-23 6.8 MEDIUM 8.8 HIGH
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF.
CVE-2017-18521 1 Wp-kama 1 Democracy Poll 2019-08-23 6.8 MEDIUM 8.8 HIGH
The democracy-poll plugin before 5.4 for WordPress has CSRF via wp-admin/options-general.php?page=democracy-poll&subpage=l10n.