Total
8478 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-37102 | 1 Blossomthemes | 1 Vilva | 2026-01-12 | N/A | 4.3 MEDIUM |
| Cross-Site Request Forgery (CSRF) vulnerability in Blossom Themes Vilva allows Cross Site Request Forgery.This issue affects Vilva: from n/a through 1.2.2. | |||||
| CVE-2025-7965 | 2026-01-09 | N/A | 4.3 MEDIUM | ||
| The CBX Restaurant Booking WordPress plugin through 1.2.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |||||
| CVE-2025-1382 | 1 Lordlinus | 1 Contact Us | 2026-01-09 | N/A | 6.1 MEDIUM |
| The Contact Us By Lord Linus WordPress plugin through 2.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. | |||||
| CVE-2025-12061 | 2026-01-09 | N/A | 8.6 HIGH | ||
| The TAX SERVICE Electronic HDM WordPress plugin before 1.2.1 does not authorization and CSRF checks in an AJAX action, allowing unauthenticated users to import and execute arbitrary SQL statements | |||||
| CVE-2024-3643 | 1 Mndpsingh287 | 1 Newsletter Popup | 2026-01-09 | N/A | 8.8 HIGH |
| The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting list, which could allow attackers to make logged in admins perform such action via a CSRF attack | |||||
| CVE-2024-3406 | 1 Goprayer | 1 Wp Prayer | 2026-01-09 | N/A | 8.8 HIGH |
| The WP Prayer WordPress plugin through 2.0.9 does not have CSRF check in place when updating its email settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |||||
| CVE-2024-12774 | 1 Pulseextensions | 1 Altra Side Menu | 2026-01-09 | N/A | 6.5 MEDIUM |
| The Altra Side Menu WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins delete arbitrary menu via a CSRF attack | |||||
| CVE-2025-10684 | 2026-01-09 | N/A | 4.3 MEDIUM | ||
| The Construction Light WordPress theme before 1.6.8 does not have authorisation and CSRF when activating via an AJAX action, allowing any authenticated users, such as subscriber to activate arbitrary . | |||||
| CVE-2024-27783 | 1 Fortinet | 1 Fortiaiops | 2026-01-09 | N/A | 7.6 HIGH |
| Multiple cross-site request forgery (CSRF) weaknesses [CWE-352] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an unauthenticated remote attacker to perform arbitrary actions on behalf of an authenticated user via tricking the victim to execute malicious GET requests. | |||||
| CVE-2024-37413 | 1 Rarathemes | 1 Preschool And Kindergarten | 2026-01-09 | N/A | 4.3 MEDIUM |
| Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Preschool and Kindergarten allows Cross Site Request Forgery.This issue affects Preschool and Kindergarten: from n/a through 1.2.1. | |||||
| CVE-2024-37421 | 1 Rarathemes | 1 Jobscout | 2026-01-09 | N/A | 4.3 MEDIUM |
| Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme JobScout allows Cross Site Request Forgery.This issue affects JobScout: from n/a through 1.1.4. | |||||
| CVE-2024-37426 | 1 Rarathemes | 1 Elegant Pink | 2026-01-09 | N/A | 4.3 MEDIUM |
| Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Elegant Pink allows Cross Site Request Forgery.This issue affects Elegant Pink: from n/a through 1.3.0. | |||||
| CVE-2023-28688 | 1 Themehunk | 1 Variation Swatches | 2026-01-09 | N/A | 5.4 MEDIUM |
| Cross-Site Request Forgery (CSRF) vulnerability in ThemeHunk TH Variation Swatches allows Cross Site Request Forgery.This issue affects TH Variation Swatches: from n/a through 1.2.7. | |||||
| CVE-2024-31428 | 1 Rarathemes | 1 The Conference | 2026-01-09 | N/A | 4.3 MEDIUM |
| Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme The Conference.This issue affects The Conference: from n/a through 1.2.0. | |||||
| CVE-2024-31384 | 1 Rarathemes | 1 Spa And Salon | 2026-01-09 | N/A | 4.3 MEDIUM |
| Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Spa and Salon.This issue affects Spa and Salon: from n/a through 1.2.7. | |||||
| CVE-2024-34379 | 1 Rarathemes | 1 Restaurant And Cafe | 2026-01-09 | N/A | 4.3 MEDIUM |
| Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Restaurant and Cafe.This issue affects Restaurant and Cafe: from n/a through 1.2.1. | |||||
| CVE-2024-23554 | 1 Hcltech | 1 Bigfix Platform | 2026-01-08 | N/A | 5.7 MEDIUM |
| Cross-Site Request Forgery (CSRF) on Session Token vulnerability that could potentially lead to Remote Code Execution (RCE). | |||||
| CVE-2024-2904 | 1 Extendthemes | 1 Calliope | 2026-01-08 | N/A | 4.3 MEDIUM |
| Cross-Site Request Forgery (CSRF) vulnerability in Extend Themes Calliope.This issue affects Calliope: from n/a through 1.0.33. | |||||
| CVE-2023-52212 | 2026-01-08 | N/A | 5.4 MEDIUM | ||
| Cross-Site Request Forgery (CSRF) vulnerability in Automattic WP Job Manager allows Cross Site Request Forgery.This issue affects WP Job Manager: from n/a through 2.0.0. | |||||
| CVE-2020-36906 | 2026-01-08 | N/A | 4.3 MEDIUM | ||
| P5 FNIP-8x16A FNIP-4xSH 1.0.20 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to add new admin users, change passwords, and modify system configurations by tricking authenticated users into loading a specially crafted form. | |||||
