Vulnerabilities (CVE)

Filtered by CWE-352
Total 5841 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-45823 1 Video Contest Wordpress Project 1 Video Contest Wordpress 2023-07-13 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in GalleryPlugins Video Contest WordPress plugin <= 3.2 versions.
CVE-2023-23803 1 Hasthemes 1 Justtables 2023-07-13 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in HasThemes JustTables plugin <= 1.4.9 versions.
CVE-2023-23791 1 Hasthemes 1 Ht Menu 2023-07-13 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Menu plugin <= 1.2.1 versions.
CVE-2023-23792 1 Hasthemes 1 Swatchly 2023-07-13 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in HasThemes Swatchly plugin <= 1.2.0 versions.
CVE-2023-28986 1 Wpaffiliatemanager 1 Affiliates Manager 2023-07-13 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in wp.Insider, wpaffiliatemgr Affiliates Manager plugin <= 2.9.20 versions.
CVE-2023-28989 1 Wedevs 1 Happy Addons For Elementor 2023-07-13 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in weDevs Happy Addons for Elementor plugin <= 3.8.2 versions.
CVE-2023-28995 1 Configurable Tag Cloud Project 1 Configurable Tag Cloud 2023-07-13 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Keith Solomon Configurable Tag Cloud (CTC) plugin <= 5.2 versions.
CVE-2023-22673 1 Magenet 1 Website Monetization 2023-07-13 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in MageNet Website Monetization by MageNet plugin <= 1.0.29.1 versions.
CVE-2023-36256 1 Online Examination System Project 1 Online Examination System 2023-07-13 N/A 6.5 MEDIUM
The Online Examination System Project 1.0 version is vulnerable to Cross-Site Request Forgery (CSRF) attacks. An attacker can craft a malicious link that, when clicked by an admin user, will delete a user account from the database without the admin's consent. The email of the user to be deleted is passed as a parameter in the URL, which can be manipulated by the attacker. This could result in a loss of data.
CVE-2023-25478 1 Weather Station Project 1 Weather Station 2023-07-13 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Jason Rouet Weather Station plugin <= 3.8.12 versions.
CVE-2023-24405 1 Wpplugin 1 Paypal \& Stripe Add-on 2023-07-13 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Contact Form 7 – PayPal & Stripe Add-on plugin <= 1.9.3 versions.
CVE-2023-24395 1 Wpplugin 1 Contact Form 7 Redirect \& Thank You Page 2023-07-13 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Contact Form 7 Redirect & Thank You Page plugin <= 1.0.3 versions.
CVE-2023-23993 1 Lionscripts 1 Ip Blocker Lite 2023-07-13 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in LionScripts.Com LionScripts: IP Blocker Lite plugin <= 11.1.1 versions.
CVE-2023-23897 1 Ozette 1 Simple Mobile Url Redirect 2023-07-13 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Ozette Plugins Simple Mobile URL Redirect plugin <= 1.7.2 versions.
CVE-2023-23869 1 Digitalinspiration 1 Google Xml Sitemap For Mobile 2023-07-13 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Mobile plugin <= 1.6.1 versions.
CVE-2023-23804 1 Hasthemes 1 Ht Feed 2023-07-12 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Feed plugin <= 1.2.7 versions.
CVE-2023-23787 1 Premmerce 1 Redirect Manager 2023-07-12 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Premmerce Premmerce Redirect Manager plugin <= 1.0.9 versions.
CVE-2023-22695 1 Wpgogo 1 Custom Field Template 2023-07-12 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Hiroaki Miyashita Custom Field Template plugin <= 2.5.8 versions.
CVE-2023-22694 1 Bigcontact Contact Page Project 1 Bigcontact Contact Page 2023-07-12 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Arian Khosravi, Norik Davtian BigContact Contact Page plugin <= 1.5.8 versions.
CVE-2022-41263 1 Sap 1 Business Objects Business Intelligence Platform 2023-07-11 N/A 4.3 MEDIUM
Due to a missing authentication check, SAP Business Objects Business Intelligence Platform (Web Intelligence) - versions 420, 430, allows an authenticated non-administrator attacker to modify the data source information for a document that is otherwise restricted. On successful exploitation, the attacker can modify information causing a limited impact on the integrity of the application.