Vulnerabilities (CVE)

Filtered by CWE-352
Total 5841 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-45753 1 Gillesdumas 1 Which Template File 2023-10-19 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Gilles Dumas which template file plugin <= 4.6.0 versions.
CVE-2023-45763 1 Taggbox 1 Taggbox 2023-10-19 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Taggbox plugin <= 2.9 versions.
CVE-2023-45749 1 Profosbox 1 Agp Font Awesome Collection 2023-10-19 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Alexey Golubnichenko AGP Font Awesome Collection plugin <= 3.2.4 versions.
CVE-2023-45752 1 10quality 1 Post Gallery 2023-10-19 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in 10 Quality Post Gallery plugin <= 2.3.12 versions.
CVE-2023-45748 1 Mailmunch 1 Mailchimp Forms 2023-10-19 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in MailMunch MailChimp Forms by MailMunch plugin <= 3.1.4 versions.
CVE-2023-45274 1 Sendpulse 1 Free Web Push 2023-10-18 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in SendPulse SendPulse Free Web Push plugin <= 1.3.1 versions.
CVE-2023-45605 1 Feed Statistics Project 1 Feed Statistics 2023-10-18 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Christopher Finke Feed Statistics plugin <= 4.1 versions.
CVE-2023-45606 1 Getlasso 1 Simple Urls 2023-10-18 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Lasso Simple URLs plugin <= 120 versions.
CVE-2023-45638 1 Eupago 1 Eupago Gateway Woocommerce 2023-10-18 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in euPago Eupago Gateway For Woocommerce plugin <= 3.1.9 versions.
CVE-2023-45273 1 Mattmckenny 1 Stout Google Calendar 2023-10-18 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Matt McKenny Stout Google Calendar plugin <= 1.2.3 versions.
CVE-2023-45650 1 Fla-shop 1 Html5 Maps 2023-10-18 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Fla-shop.Com HTML5 Maps plugin <= 1.7.1.4 versions.
CVE-2023-45647 1 Mailmunch 1 Constant Contact Forms 2023-10-18 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in MailMunch Constant Contact Forms by MailMunch plugin <= 2.0.10 versions.
CVE-2023-45268 1 Hitsteps 1 Hitsteps Web Analytics 2023-10-18 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Hitsteps Hitsteps Web Analytics plugin <= 5.86 versions.
CVE-2023-45276 1 Automatededitor 1 Automated Editor 2023-10-18 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in automatededitor.Com Automated Editor plugin <= 1.3 versions.
CVE-2023-45270 1 Pinpoint 1 Pinpoint Booking System 2023-10-18 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in PINPOINT.WORLD Pinpoint Booking System plugin <= 2.9.9.4.0 versions.
CVE-2023-43148 1 Spa-cart 1 Spa-cart 2023-10-18 N/A 8.1 HIGH
SPA-Cart 1.9.0.3 has a Cross Site Request Forgery (CSRF) vulnerability that allows a remote attacker to delete all accounts.
CVE-2020-26516 1 Intland 1 Codebeamer 2023-10-18 6.8 MEDIUM 8.8 HIGH
A CSRF issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. Requests sent to the server that trigger actions do not contain a CSRF token and can therefore be entirely predicted allowing attackers to cause the victim's browser to execute undesired actions in the web application through crafted requests.
CVE-2023-43147 1 Phpjabbers 1 Limo Booking Software 2023-10-18 N/A 8.8 HIGH
PHPJabbers Limo Booking Software 1.0 is vulnerable to Cross Site Request Forgery (CSRF) to add an admin user via the Add Users Function, aka an index.php?controller=pjAdminUsers&action=pjActionCreate URI.
CVE-2023-45907 1 Dreamer Cms Project 1 Dreamer Cms 2023-10-18 N/A 8.8 HIGH
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/variable/delete.
CVE-2023-45906 1 Dreamer Cms Project 1 Dreamer Cms 2023-10-18 N/A 8.8 HIGH
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/user/add.