Search Results (9129 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-35553 1 Idccms 1 Idccms 2025-04-09 8.3 High
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=add&nohrefStr=close.
CVE-2024-35554 2 Idccms, Idccms Project 2 Idccms, Idccms 2025-04-09 5.4 Medium
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mudi=del&dataType=newsWeb&dataTypeCN.
CVE-2024-35555 2 Idccms, Idccms Project 2 Idccms, Idccms 2025-04-09 6.3 Medium
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/share_switch.php?mudi=switch&dataType=newsWeb&fieldName=state&fieldName2=state&tabName=infoWeb&dataID=40.
CVE-2024-35556 1 Idccms 1 Idccms 2025-04-09 8.8 High
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/vpsSys_deal.php?mudi=infoSet.
CVE-2024-35557 2 Idccms, Idccms Project 2 Idccms, Idccms 2025-04-09 5.5 Medium
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/vpsApi_deal.php?mudi=rev&nohrefStr=close.
CVE-2024-35558 2 Idccms, Idccms Project 2 Idccms, Idccms 2025-04-09 8.8 High
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=rev&nohrefStr=close.
CVE-2024-35559 2 Idccms, Idccms Project 2 Idccms, Idccms 2025-04-09 8.8 High
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=rev&nohrefStr=close.
CVE-2024-35560 2 Idccms, Idccms Project 2 Idccms, Idccms 2025-04-09 4.3 Medium
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=del&dataType=&dataTypeCN.
CVE-2024-35561 2 Idccms, Idccms Project 2 Idccms, Idccms 2025-04-09 5.4 Medium
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=add&nohrefStr=close.
CVE-2022-4849 1 Usememos 1 Memos 2025-04-09 6.5 Medium
Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.
CVE-2024-30458 1 Pluginus 1 Fox - Currency Switcher Professional For Woocommerce 2025-04-09 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOOCS – WooCommerce Currency Switcher.This issue affects WOOCS – WooCommerce Currency Switcher: from n/a through 1.4.1.7.
CVE-2024-30456 1 Pluginus 1 Wordpress Currency Switcher 2025-04-09 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WPCS.This issue affects WPCS: from n/a through 1.2.0.1.
CVE-2022-4867 1 Froxlor 1 Froxlor 2025-04-09 4.3 Medium
Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.
CVE-2022-4844 1 Usememos 1 Memos 2025-04-09 8.8 High
Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4103 1 Royal-elementor-addons 1 Royal Elementor Addons 2025-04-09 4.3 Medium
The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorisation and CSRF checks when creating a template, and does not ensure that the post created is a template. This could allow any authenticated users, such as subscriber to create a post (as well as any post type) with an arbitrary title
CVE-2024-44677 1 Eladmin 1 Eladmin 2025-04-08 9.8 Critical
eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the DatabaseController.java component.
CVE-2023-7203 1 Rednao 1 Smart Forms 2025-04-08 6.1 Medium
The Smart Forms WordPress plugin before 2.6.87 does not have authorisation in various AJAX actions, which could allow users with a role as low as subscriber to call them and perform unauthorised actions such as deleting entries. The plugin also lacks CSRF checks in some places which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as deleting entries.
CVE-2024-1306 1 Rednao 1 Smart Forms 2025-04-08 5.4 Medium
The Smart Forms WordPress plugin before 2.6.94 does not have CSRF checks in some places, which could allow attackers to make logged-in users perform unwanted actions via CSRF attacks, such as editing entries, and we consider it a medium risk.
CVE-2022-46368 1 Maxum 1 Rumpus 2025-04-08 6.8 Medium
Rumpus - FTP server version 9.0.7.1 Cross-site request forgery (CSRF) – vulnerability may allow unauthorized action on behalf of authenticated users.
CVE-2022-46367 1 Maxum 1 Rumpus 2025-04-08 6.8 Medium
Rumpus - FTP server Cross-site request forgery (CSRF) – Privilege escalation vulnerability that may allow privilege escalation.