Total
4240 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-16966 | 1 File Manager Project | 1 File Manager | 2019-09-02 | 6.8 MEDIUM | 8.8 HIGH |
There is a CSRF vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter. | |||||
CVE-2015-4089 | 1 Wpfastestcache | 1 Wp Fastest Cache | 2019-08-31 | 6.8 MEDIUM | 8.8 HIGH |
Multiple cross-site request forgery (CSRF) vulnerabilities in the optionsPageRequest function in admin.php in WP Fastest Cache plugin before 0.8.3.5 for WordPress allow remote attackers to hijack the authentication of unspecified victims for requests that call the (1) saveOption, (2) deleteCache, (3) deleteCssAndJsCache, or (4) addCacheTimeout method via the wpFastestCachePage parameter in the WpFastestCacheOptions/ page. | |||||
CVE-2019-15781 | 1 Weblizar | 1 Social Likebox \& Feed | 2019-08-30 | 6.8 MEDIUM | 8.8 HIGH |
The facebook-by-weblizar plugin before 2.8.5 for WordPress has CSRF. | |||||
CVE-2019-15496 | 1 Manageyourteam | 1 Myt Project Management | 2019-08-30 | 6.8 MEDIUM | 8.8 HIGH |
MyT Project Management 1.5.1 lacks CSRF protection and, for example, allows a user/create CSRF attack. This could lead to an attacker tricking the administrator into executing arbitrary code via a specially crafted HTML page. | |||||
CVE-2019-14999 | 1 Atlassian | 1 Universal Plugin Manager | 2019-08-30 | 4.3 MEDIUM | 4.3 MEDIUM |
The Uninstall REST endpoint in Atlassian Universal Plugin Manager before version 2.22.19, from version 3.0.0 before version 3.0.3 and from version 4.0.0 before version 4.0.3 allows remote attackers to uninstall plugins using a Cross-Site Request Forgery (CSRF) vulnerability on an authenticated administrator. | |||||
CVE-2019-15515 | 1 Discourse | 1 Discourse | 2019-08-29 | 4.3 MEDIUM | 6.5 MEDIUM |
Discourse 2.3.2 sends the CSRF token in the query string. | |||||
CVE-2019-10057 | 1 Lexmark | 50 Cs31x, Cs31x Firmware, Cs41x and 47 more | 2019-08-29 | 4.3 MEDIUM | 6.5 MEDIUM |
Various Lexmark products have CSRF. | |||||
CVE-2018-14668 | 1 Yandex | 1 Clickhouse | 2019-08-29 | 6.8 MEDIUM | 8.8 HIGH |
In ClickHouse before 1.1.54388, "remote" table function allowed arbitrary symbols in "user", "password" and "default_database" fields which led to Cross Protocol Request Forgery Attacks. | |||||
CVE-2015-9343 | 1 Impress | 1 Wp Rollback | 2019-08-29 | 6.8 MEDIUM | 8.8 HIGH |
The wp-rollback plugin before 1.2.3 for WordPress has CSRF. | |||||
CVE-2014-10382 | 1 Pippinsplugins | 1 Featured Comments | 2019-08-29 | 4.3 MEDIUM | 4.3 MEDIUM |
The feature-comments plugin before 1.2.5 for WordPress has CSRF for featuring or burying a comment. | |||||
CVE-2018-21002 | 1 Joomsky | 1 Js Help Desk | 2019-08-28 | 6.8 MEDIUM | 8.8 HIGH |
The js-support-ticket plugin before 2.0.6 for WordPress has CSRF. | |||||
CVE-2019-15660 | 1 Wp-members Project | 1 Wp-members | 2019-08-28 | 6.8 MEDIUM | 8.8 HIGH |
The wp-members plugin before 3.2.8 for WordPress has CSRF. | |||||
CVE-2018-21006 | 1 Bbpress Move Topics Project | 1 Bbpress Move Topics | 2019-08-28 | 6.8 MEDIUM | 8.8 HIGH |
The bbp-move-topics plugin before 1.1.6 for WordPress has CSRF. | |||||
CVE-2019-15645 | 1 Zoho | 1 Salesiq | 2019-08-28 | 6.8 MEDIUM | 8.8 HIGH |
The zoho-salesiq plugin before 1.0.9 for WordPress has CSRF. | |||||
CVE-2019-14526 | 1 Netgear | 2 Mr1100, Mr1100 Firmware | 2019-08-27 | 5.8 MEDIUM | 8.1 HIGH |
An issue was discovered on NETGEAR Nighthawk M1 (MR1100) devices before 12.06.03. The web-interface Cross-Site Request Forgery token is stored in a dynamically generated JavaScript file, and therefore can be embedded in third party pages, and re-used against the Nighthawk web interface. This entirely bypasses the intended security benefits of the use of a CSRF-protection token. | |||||
CVE-2019-15491 | 1 It-novum | 1 Openitcockpit | 2019-08-26 | 6.8 MEDIUM | 8.8 HIGH |
openITCOCKPIT before 3.7.1 has CSRF, aka RVID 2-445b21. | |||||
CVE-2016-10918 | 1 Supsystic | 1 Photo Gallery | 2019-08-26 | 6.8 MEDIUM | 8.8 HIGH |
The gallery-by-supsystic plugin before 1.8.6 for WordPress has CSRF. | |||||
CVE-2019-15229 | 1 Thedaylightstudio | 1 Fuel Cms | 2019-08-26 | 6.8 MEDIUM | 8.8 HIGH |
FUEL CMS 1.4.4 has CSRF in the blocks/create/ Create Blocks section of the Admin console. This could lead to an attacker tricking the administrator into executing arbitrary code via a specially crafted HTML page. | |||||
CVE-2019-15329 | 1 Codection | 1 Import Users From Csv With Meta | 2019-08-23 | 6.8 MEDIUM | 8.8 HIGH |
The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF. | |||||
CVE-2017-18521 | 1 Wp-kama | 1 Democracy Poll | 2019-08-23 | 6.8 MEDIUM | 8.8 HIGH |
The democracy-poll plugin before 5.4 for WordPress has CSRF via wp-admin/options-general.php?page=democracy-poll&subpage=l10n. |