Export limit exceeded: 402579 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (9798 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-103067 2 Memberful, Wordpress-extensions 2 Memberful - Membership Plugin, Memberful 2026-10-01 8 High
Cross-Site Request Forgery (CSRF) vulnerability in Memberful Memberful - Membership Plugin memberful-wp allows Cross Site Request Forgery.This issue affects Memberful - Membership Plugin: from n/a through 1.81.0.
CVE-2026-103285 1 Ghost 1 Ghost 2026-10-01 4.3 Medium
Ghost versions from 5.19.0 before 6.57.1 contain a cross-site request forgery vulnerability in the post feedback functionality that allows attackers to submit feedback on behalf of logged-in users. Attackers can craft a malicious link to the feedback page that automatically submits feedback when visited by authenticated members without their knowledge or consent.
CVE-2023-53961 1 Sound4 18 Big Voice2, Big Voice2 Firmware, Big Voice4 and 15 more 2026-10-01 4.3 Medium
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages that submit HTTP requests to the radio processing interface, triggering unintended administrative operations when a logged-in user visits the page.
CVE-2018-25321 1 Tp-link 3 Tl-wr720n, Tl-wr720n Firmware, Tl-wr720nmbps Wireless N Router 2026-10-01 4.3 Medium
TP-Link TL-WR720N wireless router contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious web requests. Attackers can modify port forwarding rules via VirtualServerRpm.htm or change WiFi security settings via WlanSecurityRpm.htm by tricking authenticated users into visiting attacker-controlled pages.
CVE-2025-62593 2 Anyscale, Ray Project 2 Ray, Ray 2026-10-01 8.8 High
Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard against browser-based attacks, as the current defense uses the User-Agent header starting with the string "Mozilla" as a defense mechanism. This defense is insufficient as the fetch specification allows the User-Agent header to be modified. Combined with a DNS rebinding attack against the browser, and this vulnerability is exploitable against a developer running Ray who inadvertently visits a malicious website, or is served a malicious advertisement (malvertising). This issue has been patched in version 2.52.0.
CVE-2026-34190 1 Pandora Fms 1 Pandora Fms 2026-10-01 N/A
Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of alert commands via sequential, unvalidated GET requests when an authenticated administrator visits a malicious page. This issue affects Pandora FMS: from 777 onwards.
CVE-2026-34189 1 Pandora Fms 1 Pandora Fms 2026-10-01 N/A
Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of event responses via a forged GET request when an authenticated administrator visits a malicious page. This issue affects Pandora FMS: from 777 onwards.
CVE-2026-101147 1 Wordpress-extensions 2 Featured Image From Url (fifu) Free, Featured Image From Url (fifu) Premium 2026-10-01 8.8 High
The Featured Image from URL (FIFU) WordPress plugin before 6.0.8, Featured Image from URL (FIFU) Premium WordPress plugin before 8.2.8 do not correctly enforce the REST API nonce, disabling the check for the whole request when a crafted URL is used, which could allow attackers to make a logged-in administrator perform any REST API action, such as creating a new administrator account, via a CSRF attack.
CVE-2026-61502 1 Rejetto 2 Hfs, Http File Server 2026-10-01 4.3 Medium
Rejetto HFS 3.0.0 through 3.2.0 accepts state-changing API requests via the GET method and exempts GET requests from its anti-CSRF header check. A remote attacker can perform administrative actions including account creation and configuration changes leading to code execution - by causing a logged-in administrator's browser to navigate to a crafted URL, or without any credentials against default installations when the attack originates from the server's own machine.
CVE-2026-58143 1 Cotonti 2 Cotonti, Cotonti Siena 2026-10-01 8.8 High
Cotonti Siena 0.9.26 and earlier contains a cross-site request forgery vulnerability that allows unauthenticated attackers to modify administrator configuration by tricking a logged-in administrator into submitting a forged POST request to the admin.php config update handler, which never invokes the application's CSRF validation function. Attackers can disable the PFS module's file extension whitelist by setting pfsfilecheck to 0, enabling any user with PFS access to upload and execute arbitrary PHP files on the server.
CVE-2026-40509 2 Open-emr, Openemr 2 Openemr, Openemr 2026-10-01 4.3 Medium
OpenEMR before 8.3.0 contains a cross-site request forgery vulnerability in the DICOM viewer. The web_path GET parameter in the DICOM viewer page is embedded unsanitized as a URL without validation against expected path formats. An attacker can craft a URL that causes an authenticated user with Patients - Documents permissions to make authenticated requests to arbitrary OpenEMR endpoints, enabling forced logout and other state-changing actions.
CVE-2026-94220 1 Apache 1 Apisix 2026-10-01 N/A
Cross-Site request forgery (CSRF) vulnerability in feishu-auth and dingtalk-auth plugins in Apache APISIX. An attacker who can get a user to click a crafted link may cause that user's browser session on a protected route to be established under the attacker's identity instead of their own. Any work the user then performs in that session, including uploads, form submissions, and account bindings, lands in the attacker's account. This issue affects Apache APISIX: from 3.17.0 through 3.18.0. Users are recommended to upgrade to version 3.19.0, which fixes the issue.
CVE-2026-64946 1 Pandora Fms 1 Pandora Fms 2026-10-01 N/A
A chained CSRF and unrestricted SVG file upload vulnerability in the File Manager module allows stored Cross-Site Scripting, enabling session cookie exfiltration and administrator account takeover. This issue affects Pandora FMS: from 777 onwards.
CVE-2026-95362 1 Google 1 Chrome 2026-10-01 8.8 High
Cross-site request forgery in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-67993 2026-10-01 8.8 High
basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f contains a login cross-site request forgery issue in the static credentials callback.
CVE-2026-102399 2 Supsystic, Wordpress-extensions 2 Photo Gallery By Supsystic, Photo Gallery By Supsystic 2026-09-30 5.4 Medium
Unauthenticated Cross Site Request Forgery (CSRF) in Photo Gallery by Supsystic <= 1.21.0 versions.
CVE-2026-73597 1 Dell 1 Secure Connect Gateway Policy Manager 2026-09-30 6.5 Medium
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, Launch of phishing attacks, and Protection mechanism bypass.
CVE-2026-65488 2 La-studioweb, Wordpress 2 Element Kit For Elementor, Wordpress 2026-09-30 7.1 High
Cross-Site Request Forgery (CSRF) vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Stored XSS.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.6.2.
CVE-2026-97299 2026-09-30 5.4 Medium
Unauthenticated Cross Site Request Forgery (CSRF) in Razorpay Payment Links for WooCommerce <= 2.1.5 versions.
CVE-2026-96838 2026-09-30 8.8 High
Unauthenticated Cross Site Request Forgery (CSRF) in Blacklist Manager &#8211; WooCommerce Anti-Fraud, Blacklist &amp; Checkout Verification <= 2.3.1 versions.