Export limit exceeded: 402579 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (9798 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-103067 | 2 Memberful, Wordpress-extensions | 2 Memberful - Membership Plugin, Memberful | 2026-10-01 | 8 High |
| Cross-Site Request Forgery (CSRF) vulnerability in Memberful Memberful - Membership Plugin memberful-wp allows Cross Site Request Forgery.This issue affects Memberful - Membership Plugin: from n/a through 1.81.0. | ||||
| CVE-2026-103285 | 1 Ghost | 1 Ghost | 2026-10-01 | 4.3 Medium |
| Ghost versions from 5.19.0 before 6.57.1 contain a cross-site request forgery vulnerability in the post feedback functionality that allows attackers to submit feedback on behalf of logged-in users. Attackers can craft a malicious link to the feedback page that automatically submits feedback when visited by authenticated members without their knowledge or consent. | ||||
| CVE-2023-53961 | 1 Sound4 | 18 Big Voice2, Big Voice2 Firmware, Big Voice4 and 15 more | 2026-10-01 | 4.3 Medium |
| SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages that submit HTTP requests to the radio processing interface, triggering unintended administrative operations when a logged-in user visits the page. | ||||
| CVE-2018-25321 | 1 Tp-link | 3 Tl-wr720n, Tl-wr720n Firmware, Tl-wr720nmbps Wireless N Router | 2026-10-01 | 4.3 Medium |
| TP-Link TL-WR720N wireless router contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious web requests. Attackers can modify port forwarding rules via VirtualServerRpm.htm or change WiFi security settings via WlanSecurityRpm.htm by tricking authenticated users into visiting attacker-controlled pages. | ||||
| CVE-2025-62593 | 2 Anyscale, Ray Project | 2 Ray, Ray | 2026-10-01 | 8.8 High |
| Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard against browser-based attacks, as the current defense uses the User-Agent header starting with the string "Mozilla" as a defense mechanism. This defense is insufficient as the fetch specification allows the User-Agent header to be modified. Combined with a DNS rebinding attack against the browser, and this vulnerability is exploitable against a developer running Ray who inadvertently visits a malicious website, or is served a malicious advertisement (malvertising). This issue has been patched in version 2.52.0. | ||||
| CVE-2026-34190 | 1 Pandora Fms | 1 Pandora Fms | 2026-10-01 | N/A |
| Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of alert commands via sequential, unvalidated GET requests when an authenticated administrator visits a malicious page. This issue affects Pandora FMS: from 777 onwards. | ||||
| CVE-2026-34189 | 1 Pandora Fms | 1 Pandora Fms | 2026-10-01 | N/A |
| Cross-Site Request Forgery (CSRF) vulnerability allows unauthorized deletion of event responses via a forged GET request when an authenticated administrator visits a malicious page. This issue affects Pandora FMS: from 777 onwards. | ||||
| CVE-2026-101147 | 1 Wordpress-extensions | 2 Featured Image From Url (fifu) Free, Featured Image From Url (fifu) Premium | 2026-10-01 | 8.8 High |
| The Featured Image from URL (FIFU) WordPress plugin before 6.0.8, Featured Image from URL (FIFU) Premium WordPress plugin before 8.2.8 do not correctly enforce the REST API nonce, disabling the check for the whole request when a crafted URL is used, which could allow attackers to make a logged-in administrator perform any REST API action, such as creating a new administrator account, via a CSRF attack. | ||||
| CVE-2026-61502 | 1 Rejetto | 2 Hfs, Http File Server | 2026-10-01 | 4.3 Medium |
| Rejetto HFS 3.0.0 through 3.2.0 accepts state-changing API requests via the GET method and exempts GET requests from its anti-CSRF header check. A remote attacker can perform administrative actions including account creation and configuration changes leading to code execution - by causing a logged-in administrator's browser to navigate to a crafted URL, or without any credentials against default installations when the attack originates from the server's own machine. | ||||
| CVE-2026-58143 | 1 Cotonti | 2 Cotonti, Cotonti Siena | 2026-10-01 | 8.8 High |
| Cotonti Siena 0.9.26 and earlier contains a cross-site request forgery vulnerability that allows unauthenticated attackers to modify administrator configuration by tricking a logged-in administrator into submitting a forged POST request to the admin.php config update handler, which never invokes the application's CSRF validation function. Attackers can disable the PFS module's file extension whitelist by setting pfsfilecheck to 0, enabling any user with PFS access to upload and execute arbitrary PHP files on the server. | ||||
| CVE-2026-40509 | 2 Open-emr, Openemr | 2 Openemr, Openemr | 2026-10-01 | 4.3 Medium |
| OpenEMR before 8.3.0 contains a cross-site request forgery vulnerability in the DICOM viewer. The web_path GET parameter in the DICOM viewer page is embedded unsanitized as a URL without validation against expected path formats. An attacker can craft a URL that causes an authenticated user with Patients - Documents permissions to make authenticated requests to arbitrary OpenEMR endpoints, enabling forced logout and other state-changing actions. | ||||
| CVE-2026-94220 | 1 Apache | 1 Apisix | 2026-10-01 | N/A |
| Cross-Site request forgery (CSRF) vulnerability in feishu-auth and dingtalk-auth plugins in Apache APISIX. An attacker who can get a user to click a crafted link may cause that user's browser session on a protected route to be established under the attacker's identity instead of their own. Any work the user then performs in that session, including uploads, form submissions, and account bindings, lands in the attacker's account. This issue affects Apache APISIX: from 3.17.0 through 3.18.0. Users are recommended to upgrade to version 3.19.0, which fixes the issue. | ||||
| CVE-2026-64946 | 1 Pandora Fms | 1 Pandora Fms | 2026-10-01 | N/A |
| A chained CSRF and unrestricted SVG file upload vulnerability in the File Manager module allows stored Cross-Site Scripting, enabling session cookie exfiltration and administrator account takeover. This issue affects Pandora FMS: from 777 onwards. | ||||
| CVE-2026-95362 | 1 Google | 1 Chrome | 2026-10-01 | 8.8 High |
| Cross-site request forgery in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-67993 | 2026-10-01 | 8.8 High | ||
| basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f contains a login cross-site request forgery issue in the static credentials callback. | ||||
| CVE-2026-102399 | 2 Supsystic, Wordpress-extensions | 2 Photo Gallery By Supsystic, Photo Gallery By Supsystic | 2026-09-30 | 5.4 Medium |
| Unauthenticated Cross Site Request Forgery (CSRF) in Photo Gallery by Supsystic <= 1.21.0 versions. | ||||
| CVE-2026-73597 | 1 Dell | 1 Secure Connect Gateway Policy Manager | 2026-09-30 | 6.5 Medium |
| Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, Launch of phishing attacks, and Protection mechanism bypass. | ||||
| CVE-2026-65488 | 2 La-studioweb, Wordpress | 2 Element Kit For Elementor, Wordpress | 2026-09-30 | 7.1 High |
| Cross-Site Request Forgery (CSRF) vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Stored XSS.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.6.2. | ||||
| CVE-2026-97299 | 2026-09-30 | 5.4 Medium | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in Razorpay Payment Links for WooCommerce <= 2.1.5 versions. | ||||
| CVE-2026-96838 | 2026-09-30 | 8.8 High | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in Blacklist Manager – WooCommerce Anti-Fraud, Blacklist & Checkout Verification <= 2.3.1 versions. | ||||