Vulnerabilities (CVE)

Filtered by CWE-352
Total 9287 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-8091 1 Jakesnyder 1 Enhanced Search Box 2026-06-17 N/A 6.5 MEDIUM
The Enhanced Search Box WordPress plugin through 0.6.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVE-2024-8090 1 Justintadlock 1 Javascript-logic 2026-06-17 N/A 6.1 MEDIUM
The JavaScript Logic WordPress plugin through 0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
CVE-2024-8085 1 Solidcode 1 Peoplepond 2026-06-17 N/A 6.1 MEDIUM
The PeoplePond WordPress plugin through 1.1.9 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
CVE-2024-8082 1 Justintadlock 1 Widgets Reset 2026-06-17 N/A 4.3 MEDIUM
The Widgets Reset WordPress plugin through 0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVE-2024-8065 2026-06-17 N/A 8.1 HIGH
A Cross-Site Request Forgery (CSRF) vulnerability in version v1.4.1 of danswer-ai/danswer allows attackers to perform unauthorized actions in the context of the victim's browser. This includes connecting the victim's application with a malicious Slack Bot, inviting users, and deleting chats, among other actions. The application does not implement any CSRF protection, making it susceptible to these attacks.
CVE-2024-8052 1 Moc 1 Review Ratings 2026-06-17 N/A 6.1 MEDIUM
The Review Ratings WordPress plugin through 1.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
CVE-2024-8051 1 Moc 1 Special Feed Items 2026-06-17 N/A 5.4 MEDIUM
The Special Feed Items WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
CVE-2024-8050 1 Jfarthing 1 Custom Author Base 2026-06-17 N/A 4.3 MEDIUM
The Custom Author Base WordPress plugin through 1.1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVE-2024-8047 1 Freakingwildchild 1 Visual Sound 2026-06-17 N/A 6.5 MEDIUM
The Visual Sound (old) WordPress plugin through 1.06 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVE-2024-8044 1 Rubayathasan 1 Infolinks Ad Wrap 2026-06-17 N/A 6.5 MEDIUM
The infolinks Ad Wrap WordPress plugin through 1.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVE-2024-8043 1 Seanschulte 1 Vikinghammer Tweet 2026-06-17 N/A 5.4 MEDIUM
The Vikinghammer Tweet WordPress plugin through 0.2.4 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
CVE-2024-8032 1 Ulfbenjaminsson 1 Smooth Gallery Replacement 2026-06-17 N/A 6.1 MEDIUM
The Smooth Gallery Replacement WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
CVE-2024-8026 1 Qanything 1 Qanything 2026-06-17 N/A 8.1 HIGH
A Cross-Site Request Forgery (CSRF) vulnerability exists in the backend API of netease-youdao/qanything, as of commit d9ab8bc. The backend server has overly permissive CORS headers, allowing all cross-origin calls. This vulnerability affects all backend endpoints, enabling actions such as creating, uploading, listing, deleting files, and managing knowledge bases.
CVE-2024-7984 1 Ultimatewpsms 1 Joy Of Text 2026-06-17 N/A 4.3 MEDIUM
The Joy Of Text Lite WordPress plugin through 2.3.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVE-2024-7892 1 Vladyslavbondarenko 1 Adstxt 2026-06-17 N/A 4.3 MEDIUM
The adstxt Plugin WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVE-2024-7864 1 Pixeljar 1 Favicon Generator 2026-06-17 N/A 6.5 MEDIUM
The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not have CSRF and path validation in the output_sub_admin_page_0() function, allowing attackers to make logged in admins delete arbitrary files on the server
CVE-2024-7863 1 Pixeljar 1 Favicon Generator 2026-06-17 N/A 6.8 MEDIUM
The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not validate files to be uploaded and does not have CSRF checks, which could allow attackers to make logged in admin upload arbitrary files such as PHP on the server
CVE-2024-7862 1 Kimhuebel 1 Blogintroduction-wordpress-plugin 2026-06-17 N/A 6.5 MEDIUM
The blogintroduction-wordpress-plugin WordPress plugin through 0.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVE-2024-7859 1 Freakingwildchild 1 Visual Sound 2026-06-17 N/A 6.5 MEDIUM
The Visual Sound WordPress plugin through 1.03 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVE-2024-7850 2026-06-17 N/A 6.1 MEDIUM
The BP Profile Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.7.5. This is due to missing or incorrect nonce validation on the bps_ajax_field_selector(), bps_ajax_template_options(), and bps_ajax_field_row() functions. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.