Search Results (9951 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-35560 2 Idccms, Idccms Project 2 Idccms, Idccms 2025-04-09 4.3 Medium
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=del&dataType=&dataTypeCN.
CVE-2024-35561 2 Idccms, Idccms Project 2 Idccms, Idccms 2025-04-09 5.4 Medium
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=add&nohrefStr=close.
CVE-2022-4849 1 Usememos 1 Memos 2025-04-09 6.5 Medium
Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.
CVE-2024-30458 1 Pluginus 1 Fox - Currency Switcher Professional For Woocommerce 2025-04-09 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOOCS – WooCommerce Currency Switcher.This issue affects WOOCS – WooCommerce Currency Switcher: from n/a through 1.4.1.7.
CVE-2024-30456 1 Pluginus 1 Wordpress Currency Switcher 2025-04-09 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WPCS.This issue affects WPCS: from n/a through 1.2.0.1.
CVE-2022-4867 1 Froxlor 1 Froxlor 2025-04-09 4.3 Medium
Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 2.0.0-beta1.
CVE-2021-26328 1 Amd 48 Epyc 7003, Epyc 7003 Firmware, Epyc 72f3 and 45 more 2025-04-09 4.4 Medium
Failure to verify the mode of CPU execution at the time of SNP_INIT may lead to a potential loss of memory integrity for SNP guests.
CVE-2022-4844 1 Usememos 1 Memos 2025-04-09 8.8 High
Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-36928 1 Zoom 1 Zoom 2025-04-09 6.1 Medium
Zoom for Android clients before version 5.13.0 contain a path traversal vulnerability. A third party app could exploit this vulnerability to read and write to the Zoom application data directory.
CVE-2022-4103 1 Royal-elementor-addons 1 Royal Elementor Addons 2025-04-09 4.3 Medium
The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorisation and CSRF checks when creating a template, and does not ensure that the post created is a template. This could allow any authenticated users, such as subscriber to create a post (as well as any post type) with an arbitrary title
CVE-2024-44677 1 Eladmin 1 Eladmin 2025-04-08 9.8 Critical
eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the DatabaseController.java component.
CVE-2023-7203 1 Rednao 1 Smart Forms 2025-04-08 6.1 Medium
The Smart Forms WordPress plugin before 2.6.87 does not have authorisation in various AJAX actions, which could allow users with a role as low as subscriber to call them and perform unauthorised actions such as deleting entries. The plugin also lacks CSRF checks in some places which could allow attackers to make logged in users perform unwanted actions via CSRF attacks such as deleting entries.
CVE-2024-1306 1 Rednao 1 Smart Forms 2025-04-08 5.4 Medium
The Smart Forms WordPress plugin before 2.6.94 does not have CSRF checks in some places, which could allow attackers to make logged-in users perform unwanted actions via CSRF attacks, such as editing entries, and we consider it a medium risk.
CVE-2022-46368 1 Maxum 1 Rumpus 2025-04-08 6.8 Medium
Rumpus - FTP server version 9.0.7.1 Cross-site request forgery (CSRF) – vulnerability may allow unauthorized action on behalf of authenticated users.
CVE-2022-46367 1 Maxum 1 Rumpus 2025-04-08 6.8 Medium
Rumpus - FTP server Cross-site request forgery (CSRF) – Privilege escalation vulnerability that may allow privilege escalation.
CVE-2024-27474 1 Leantime 1 Leantime 2025-04-08 8.8 High
Leantime 3.0.6 is vulnerable to Cross Site Request Forgery (CSRF). This vulnerability allows malicious actors to perform unauthorized actions on behalf of authenticated users, specifically administrators.
CVE-2024-22721 1 Formtools 1 Form Tools 2025-04-08 6.3 Medium
Cross Site Request Forgery (CSRF) vulnerability in Form Tools 3.1.1 allows attackers to manipulate sensitive user data via crafted link.
CVE-2024-25572 2 Ninjaforms, Saturday Drive 2 Ninja Forms, Ninja Forms 2025-04-08 8.8 High
Cross-site request forgery (CSRF) vulnerability exists in Ninja Forms prior to 3.4.31. If a website administrator views a malicious page while logging in, unintended operations may be performed.
CVE-2024-53258 1 Autolabproject 1 Autolab 2025-04-07 5.3 Medium
Autolab is a course management service that enables auto-graded programming assignments. From Autolab versions v.3.0.0 onward students can download all assignments from another student, as long as they are logged in, using the download_all_submissions feature. This can allow for leakage of submissions to unauthorized users, such as downloading submissions from other students in the class, or even instructor test submissions, given they know their user IDs. This issue has been patched in commit `1aa4c769` which is not yet in a release version, but is expected to be included in version 3.0.3. Users are advised to either manually patch or to wait for version 3.0.3. As a workaround administrators can disable the feature.
CVE-2023-22852 1 Tiki 1 Tiki 2025-04-07 6.5 Medium
Tiki through 25.0 allows CSRF attacks that are related to tiki-importer.php and tiki-import_sheet.php.