Vulnerabilities (CVE)

Filtered by CWE-352
Total 5841 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-45072 1 Wpml 1 Wpml 2022-11-22 N/A 4.3 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in WPML Multilingual CMS premium plugin <= 4.5.13 on WordPress.
CVE-2022-40192 1 Gvectors 1 Wpforo Forum 2022-11-22 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.
CVE-2022-38075 1 Webartesanal 1 Mantenimiento Web 2022-11-21 N/A 6.1 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in Mantenimiento web plugin <= 0.13 on WordPress.
CVE-2022-40686 1 Constantcontact 1 Creative Mail 2022-11-21 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Creative Mail plugin <= 1.5.4 on WordPress.
CVE-2022-40695 1 Clogica 1 Seo Redirection 2022-11-21 N/A 8.8 HIGH
Multiple Cross-Site Scripting (CSRF) vulnerabilities in SEO Redirection Plugin plugin <= 8.9 on WordPress.
CVE-2022-41805 1 Booster 1 Booster For Woocommerce 2022-11-21 N/A 4.3 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in Booster for WooCommerce plugin <= 5.6.6 on WordPress.
CVE-2022-40687 1 Constantcontact 1 Creative Mail 2022-11-21 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Creative Mail plugin <= 1.5.4 on WordPress.
CVE-2022-42246 1 Duofoxtechnologies 1 Duofox Cms 2022-11-17 N/A 8.8 HIGH
Doufox 0.0.4 contains a CSRF vulnerability that can add system administrator account.
CVE-2022-43693 1 Concretecms 1 Concrete Cms 2022-11-17 N/A 8.8 HIGH
Concrete CMS is vulnerable to CSRF due to the lack of "State" parameter for external Concrete authentication service for users of Concrete who use the "out of the box" core OAuth.
CVE-2019-1010054 1 Dolibarr 1 Dolibarr Erp\/crm 2022-11-17 6.8 MEDIUM 8.8 HIGH
Dolibarr 7.0.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: allow malitious html to change user password, disable users and disable password encryptation. The component is: Function User password change, user disable and password encryptation. The attack vector is: admin access malitious urls.
CVE-2020-11825 1 Dolibarr 1 Dolibarr Erp\/crm 2022-11-17 6.8 MEDIUM 8.8 HIGH
In Dolibarr 10.0.6, forms are protected with a CSRF token against CSRF attacks. The problem is any CSRF token in any user's session can be used in another user's session. CSRF tokens should not be valid in this situation.
CVE-2019-15062 1 Dolibarr 1 Dolibarr Erp\/crm 2022-11-17 6.0 MEDIUM 8.0 HIGH
An issue was discovered in Dolibarr 11.0.0-alpha. A user can store an IFRAME element (containing a user/card.php CSRF request) in his Linked Files settings page. When visited by the admin, this could completely take over the admin account. (The protection mechanism for CSRF is to check the Referer header; however, because the attack is from one of the application's own settings pages, this mechanism is bypassed.)
CVE-2022-35613 1 Konker 1 Konker Platform 2022-11-17 N/A 8.8 HIGH
Konker v2.3.9 was to discovered to contain a Cross-Site Request Forgery (CSRF).
CVE-2022-43323 1 Eyoucms 1 Eyoucms 2022-11-16 N/A 8.8 HIGH
EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Top Up Balance component under the Edit Member module.
CVE-2022-44387 1 Eyoucms 1 Eyoucms 2022-11-16 N/A 8.8 HIGH
EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Basic Information component under the Edit Member module.
CVE-2022-44389 1 Eyoucms 1 Eyoucms 2022-11-16 N/A 6.5 MEDIUM
EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit Admin Profile module. This vulnerability allows attackers to arbitrarily change Administrator account information.
CVE-2022-3632 1 Digitialpixies 1 Oauth Client 2022-11-16 N/A 6.5 MEDIUM
The OAuth Client by DigitialPixies WordPress plugin through 1.1.0 does not have CSRF checks in some places, which could allow attackers to make logged-in users perform unwanted actions.
CVE-2022-2449 1 Resmush.it 1 Resmush.it Image Optimizer 2022-11-16 N/A 6.5 MEDIUM
The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 does not perform CSRF checks for any of its AJAX actions, allowing an attackers to trick logged in users to perform various actions on their behalf on the site.
CVE-2020-25015 1 Genexis 2 Platinum 4410, Platinum 4410 Firmware 2022-11-16 4.3 MEDIUM 6.5 MEDIUM
A specific router allows changing the Wi-Fi password remotely. Genexis Platinum 4410 V2-1.28, a compact router generally used at homes and offices was found to be vulnerable to Broken Access Control and CSRF which could be combined to remotely change the WIFI access point’s password.
CVE-2020-24373 1 Free 10 Freebox Delta, Freebox Delta Firmware, Freebox Mini and 7 more 2022-11-16 6.8 MEDIUM 8.8 HIGH
A CSRF vulnerability in the UPnP MediaServer implementation in Freebox Server before 4.2.3.