Total
9305 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-37774 | 1 Sunbirddcim | 1 Dctrack | 2026-07-05 | N/A | 8.0 HIGH |
| A Cross-Site Request Forgery (CSRF) in Sunbird DCIM dcTrack v9.1.2 allows authenticated attackers to escalate their privileges by forcing an Administrator user to perform sensitive requests in some admin screens. | |||||
| CVE-2018-14519 | 1 Getkirby | 1 Kirby | 2026-07-05 | N/A | 4.3 MEDIUM |
| An issue was discovered in Kirby 2.5.12. The delete page functionality suffers from a CSRF flaw. A remote attacker can craft a malicious CSRF page and force the user to delete a page. | |||||
| CVE-2026-57766 | 2026-07-02 | N/A | 8.8 HIGH | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor <= 3.5.6 versions. | |||||
| CVE-2026-57759 | 2026-07-02 | N/A | 8.8 HIGH | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid <= 5.9.9.7 versions. | |||||
| CVE-2026-57758 | 2026-07-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in Permalink Manager for WooCommerce <= 1.0.8.2 versions. | |||||
| CVE-2026-57747 | 2026-07-02 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in Booked <= 3.0.0 versions. | |||||
| CVE-2026-13952 | 1 Google | 1 Chrome | 2026-07-02 | N/A | 4.3 MEDIUM |
| Inappropriate implementation in PerformanceAPIs in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-13946 | 2 Apple, Google | 2 Iphone Os, Chrome | 2026-07-02 | N/A | 4.3 MEDIUM |
| Inappropriate implementation in ScriptInjections in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-13944 | 2 Apple, Google | 2 Macos, Chrome | 2026-07-02 | N/A | 3.1 LOW |
| Inappropriate implementation in DataTransfer in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-57761 | 2026-07-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in SEOWP <= 3.12.2 versions. | |||||
| CVE-2026-57757 | 2026-07-02 | N/A | 7.1 HIGH | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in pCloud WP Backup <= 2.0.2 versions. | |||||
| CVE-2026-57751 | 2026-07-02 | N/A | 8.1 HIGH | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in Heateor Social Login <= 1.1.39 versions. | |||||
| CVE-2026-13963 | 1 Google | 1 Chrome | 2026-07-02 | N/A | 3.1 LOW |
| Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-57690 | 2026-07-02 | N/A | 4.3 MEDIUM | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in Werkstatt <= 4.7.2 versions. | |||||
| CVE-2026-14016 | 1 Google | 1 Chrome | 2026-07-01 | N/A | 6.5 MEDIUM |
| Inappropriate implementation in SVG in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | |||||
| CVE-2026-57723 | 2026-07-01 | N/A | 7.4 HIGH | ||
| Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Path Traversal. This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.8.12. | |||||
| CVE-2026-11981 | 2026-07-01 | N/A | 4.3 MEDIUM | ||
| The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.15.3 This is due to missing nonce validation on the give_set_notification_status_handler() function. This makes it possible for unauthenticated attackers to disable donation email notifications via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |||||
| CVE-2026-12158 | 2026-07-01 | N/A | 8.8 HIGH | ||
| The RegistrationMagic – User Registration Forms Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.0.9.1. This is due to missing or incorrect nonce validation on the process_request function. This makes it possible for unauthenticated attackers to escalate the privileges of an arbitrary form submitter to administrator by creating a malicious Chronos automation task that is executed via WordPress cron via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | |||||
| CVE-2026-56024 | 2026-07-01 | N/A | 6.5 MEDIUM | ||
| Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal WP EasyPay allows Cross Site Request Forgery. This issue affects WP EasyPay: from n/a through 4.5.0. | |||||
| CVE-2026-50132 | 1 Budibase | 1 Budibase | 2026-06-30 | N/A | 7.3 HIGH |
| Budibase is an open-source low-code platform. Prior to 3.39.0, `GET /api/chat-links/:instance/:token/handoff` is a public endpoint (no auth required) that performs a permanent, state-changing operation: it binds an external chat identity (Slack/Discord/MS Teams) to an authenticated Budibase user account, with no consent UI and no CSRF protection. The session token in the URL is created by the attacker (from their own /link slash command) and embeds the attacker's externalUserId. When an authenticated Budibase victim visits the URL, their account is silently and permanently linked to the attacker's Slack/Discord identity. The server responds with "Authentication succeeded." — no indication of what was linked. This vulnerability is fixed in 3.39.0. | |||||
