Total
5841 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-36517 | 1 Wp Abstracts Project | 1 Wp Abstracts | 2023-07-18 | N/A | 8.8 HIGH |
| Cross-Site Request Forgery (CSRF) vulnerability in Kevon Adonis WP Abstracts plugin <= 2.6.2 versions. | |||||
| CVE-2023-36691 | 1 Webwinkelkeur Project | 1 Webwinkelkeur | 2023-07-18 | N/A | 8.8 HIGH |
| Cross-Site Request Forgery (CSRF) vulnerability in Albert Peschar WebwinkelKeur plugin <= 3.24 versions. | |||||
| CVE-2023-34015 | 1 Piwebsolution | 1 Advanced-free-flat-shipping-woocommerce | 2023-07-18 | N/A | 8.8 HIGH |
| Cross-Site Request Forgery (CSRF) vulnerability in PI Websolution Conditional shipping & Advanced Flat rate shipping rates / Flexible shipping for WooCommerce shipping plugin <= 1.6.4.4 versions. | |||||
| CVE-2021-34619 | 1 Storeapps | 1 Stock Manager For Woocommerce | 2023-07-18 | 6.8 MEDIUM | 8.8 HIGH |
| The WooCommerce Stock Manager WordPress plugin is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Upload in versions up to, and including, 2.5.7 due to missing nonce and file validation in the /woocommerce-stock-manager/trunk/admin/views/import-export.php file. | |||||
| CVE-2023-37392 | 1 Wp Dummy Content Generator Project | 1 Wp Dummy Content Generator | 2023-07-18 | N/A | 8.8 HIGH |
| Cross-Site Request Forgery (CSRF) vulnerability in Deepak Anand WP Dummy Content Generator plugin <= 2.3.0 versions. | |||||
| CVE-2023-31999 | 1 Fastify | 1 Oauth2 | 2023-07-17 | N/A | 8.8 HIGH |
| All versions of @fastify/oauth2 used a statically generated state parameter at startup time and were used across all requests for all users. The purpose of the Oauth2 state parameter is to prevent Cross-Site-Request-Forgery attacks. As such, it should be unique per user and should be connected to the user's session in some way that will allow the server to validate it. v7.2.0 changes the default behavior to store the state in a cookie with the http-only and same-site=lax attributes set. The state is now by default generated for every user. Note that this contains a breaking change in the checkStateFunction function, which now accepts the full Request object. | |||||
| CVE-2023-25201 | 1 Multitech | 4 Conduit Ap Mtcap2-l4e1, Conduit Ap Mtcap2-l4e1-868-042a, Conduit Ap Mtcap2-l4e1-868-042a Firmware and 1 more | 2023-07-17 | N/A | 8.8 HIGH |
| Cross Site Request Forgery (CSRF) vulnerability in MultiTech Conduit AP MTCAP2-L4E1 MTCAP2-L4E1-868-042A v.6.0.0 allows a remote attacker to execute arbitrary code via a crafted script upload. | |||||
| CVE-2023-35781 | 1 Lws | 1 Lws Cleaner | 2023-07-14 | N/A | 8.8 HIGH |
| Cross-Site Request Forgery (CSRF) vulnerability in LWS Cleaner plugin <= 2.3.0 versions. | |||||
| CVE-2023-35913 | 1 Oopspam | 1 Oopspam Anti-spam | 2023-07-14 | N/A | 8.8 HIGH |
| Cross-Site Request Forgery (CSRF) vulnerability in OOPSpam OOPSpam Anti-Spam plugin <= 1.1.44 versions. | |||||
| CVE-2023-35774 | 1 Lws | 1 Lws Tools | 2023-07-14 | N/A | 8.8 HIGH |
| Cross-Site Request Forgery (CSRF) vulnerability in LWS LWS Tools plugin <= 2.4.1 versions. | |||||
| CVE-2022-2350 | 1 Brainvire | 1 Disable User Login | 2023-07-14 | N/A | 5.3 MEDIUM |
| The Disable User Login WordPress plugin through 1.0.1 does not have authorisation and CSRF checks when updating its settings, allowing unauthenticated attackers to block (or unblock) users at will. | |||||
| CVE-2023-35912 | 1 Wpzone | 1 Potent Donations For Woocommerce | 2023-07-14 | N/A | 8.8 HIGH |
| Cross-Site Request Forgery (CSRF) vulnerability in WP Zone Potent Donations for WooCommerce plugin <= 1.1.9 versions. | |||||
| CVE-2023-25487 | 1 Pixelgrade | 1 Pixtypes | 2023-07-14 | N/A | 8.8 HIGH |
| Cross-Site Request Forgery (CSRF) vulnerability in Pixelgrade PixTypes plugin <= 1.4.14 versions. | |||||
| CVE-2023-25468 | 1 Pvmg | 1 Reservation.studio | 2023-07-14 | N/A | 8.8 HIGH |
| Cross-Site Request Forgery (CSRF) vulnerability in Reservation.Studio Reservation.Studio widget plugin <= 1.0.11 versions. | |||||
| CVE-2023-23997 | 1 Database Collation Fix Project | 1 Database Collation Fix | 2023-07-14 | N/A | 8.8 HIGH |
| Cross-Site Request Forgery (CSRF) vulnerability in Dave Jesch Database Collation Fix plugin <= 1.2.7 versions. | |||||
| CVE-2023-24421 | 1 Wpengine | 1 Php Compatibility Checker | 2023-07-14 | N/A | 8.8 HIGH |
| Cross-Site Request Forgery (CSRF) vulnerability in WP Engine PHP Compatibility Checker plugin <= 1.5.2 versions. | |||||
| CVE-2023-25051 | 1 Comment Reply Notification Project | 1 Comment Reply Notification | 2023-07-14 | N/A | 8.8 HIGH |
| Cross-Site Request Forgery (CSRF) vulnerability in Denishua Comment Reply Notification plugin <= 1.4 versions. | |||||
| CVE-2023-35120 | 1 Piigab | 2 M-bus 900s, M-bus 900s Firmware | 2023-07-13 | N/A | 8.8 HIGH |
| PiiGAB M-Bus is vulnerable to cross-site request forgery. An attacker who wants to execute a certain command could send a phishing mail to the owner of the device and hope that the owner clicks on the link. If the owner of the device has a cookie stored that allows the owner to be logged in, then the device could execute the GET or POST link request. | |||||
| CVE-2023-23731 | 1 Hasthemes | 1 Wishsuite | 2023-07-13 | N/A | 8.8 HIGH |
| Cross-Site Request Forgery (CSRF) vulnerability in HasTheme WishSuite plugin <= 1.3.3 versions. | |||||
| CVE-2023-23704 | 1 Pixelgrade | 1 Comments Rating | 2023-07-13 | N/A | 8.8 HIGH |
| Cross-Site Request Forgery (CSRF) vulnerability in Pixelgrade Comments Ratings plugin <= 1.1.6 versions. | |||||
