Total
9307 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-26547 | 2026-06-17 | N/A | 7.1 HIGH | ||
| Cross-Site Request Forgery (CSRF) vulnerability in nagarjunsonti My Login Logout Plugin my-loginlogout allows Stored XSS.This issue affects My Login Logout Plugin: from n/a through <= 2.4. | |||||
| CVE-2025-26545 | 2026-06-17 | N/A | 7.1 HIGH | ||
| Cross-Site Request Forgery (CSRF) vulnerability in shisuh Related Posts Line-up-Exactly by Milliard related-posts-line-up-exactry-by-milliard allows Stored XSS.This issue affects Related Posts Line-up-Exactly by Milliard: from n/a through <= 0.0.22. | |||||
| CVE-2025-26543 | 2026-06-17 | N/A | 7.1 HIGH | ||
| Cross-Site Request Forgery (CSRF) vulnerability in Pukhraj Suthar Simple Responsive Menu simple-responsive-menu allows Stored XSS.This issue affects Simple Responsive Menu: from n/a through <= 2.1. | |||||
| CVE-2025-26211 | 1 Gibbonedu | 1 Gibbon | 2026-06-17 | N/A | 3.7 LOW |
| Gibbon before 29.0.00 allows CSRF. | |||||
| CVE-2025-26206 | 1 Selldone | 1 Storefront | 2026-06-17 | N/A | 9.0 CRITICAL |
| Cross Site Request Forgery vulnerability in sell done storefront v.1.0 allows a remote attacker to escalate privileges via the index.html component | |||||
| CVE-2025-25967 | 1 Ddsn | 1 Acora Cms | 2026-06-17 | N/A | 8.8 HIGH |
| Acora CMS version 10.1.1 is vulnerable to Cross-Site Request Forgery (CSRF). This flaw enables attackers to trick authenticated users into performing unauthorized actions, such as account deletion or user creation, by embedding malicious requests in external content. The lack of CSRF protections allows exploitation via crafted requests. | |||||
| CVE-2025-25928 | 1 Openmrs | 1 Openmrs | 2026-06-17 | N/A | 8.0 HIGH |
| A Cross-Site Request Forgery (CSRF) in the component /admin/users/user.form of Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary operations via a crafted request. In this case, an attacker could elevate a low-privileged account to an administrative role by leveraging the CSRF vulnerability at the /admin/users/user.form endpoint. | |||||
| CVE-2025-25927 | 1 Openmrs | 1 Openmrs | 2026-06-17 | N/A | 6.8 MEDIUM |
| A Cross-Site Request Forgery (CSRF) in Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary operations via a crafted GET request. | |||||
| CVE-2025-25907 | 1 Tianti Project | 1 Tianti | 2026-06-17 | N/A | 8.8 HIGH |
| tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/save. This vulnerability allows attackers to execute arbitrary operations via a crafted GET or POST request. | |||||
| CVE-2025-25873 | 1 Openpanel | 1 Openadmin | 2026-06-17 | N/A | 5.5 MEDIUM |
| Cross Site Request Forgery vulnerability in Open Panel OpenAdmin v.0.3.4 allows a remote attacker to escalate privileges via the Change Root Password function | |||||
| CVE-2025-25772 | 1 Ujcms | 1 Jspxcms | 2026-06-17 | N/A | 5.1 MEDIUM |
| A Cross-Site Request Forgery (CSRF) in the component /back/UserController.java of Jspxcms v9.0 to v9.5 allows attackers to arbitrarily add Administrator accounts via a crafted request. | |||||
| CVE-2025-25770 | 1 Wang.market | 1 Wangmarket | 2026-06-17 | N/A | 6.8 MEDIUM |
| Wangmarket v4.10 to v5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /agency/AgencyUserController.java. | |||||
| CVE-2025-25769 | 1 Wang.market | 1 Wangmarket | 2026-06-17 | N/A | 8.0 HIGH |
| Wangmarket v4.10 to v5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /controller/UserController.java. | |||||
| CVE-2025-25748 | 1 Digitaldruid | 1 Hoteldruid | 2026-06-17 | N/A | 7.3 HIGH |
| A CSRF vulnerability in the gestione_utenti.php endpoint of HotelDruid 3.0.7 allows attackers to perform unauthorized actions (e.g., modifying user passwords) on behalf of authenticated users by exploiting the lack of origin or referrer validation and the absence of CSRF tokens. NOTE: this is disputed because there is an id_sessione CSRF token. | |||||
| CVE-2025-25379 | 1 07fly | 1 07flycms | 2026-06-17 | N/A | 9.6 CRITICAL |
| Cross Site Request Forgery vulnerability in 07FLYCMS v.1.3.9 allows a remote attacker to execute arbitrary code via the id parameter of the del.html component. | |||||
| CVE-2025-25168 | 1 Blackandwhitedigital | 1 Bookpress | 2026-06-17 | N/A | 7.1 HIGH |
| Cross-Site Request Forgery (CSRF) vulnerability in Black and White BookPress – For Book Authors book-press allows Cross-Site Scripting (XSS).This issue affects BookPress – For Book Authors: from n/a through <= 1.2.7. | |||||
| CVE-2025-25166 | 1 Gabrieldarezzo | 1 Inlocation | 2026-06-17 | N/A | 7.1 HIGH |
| Cross-Site Request Forgery (CSRF) vulnerability in gabrieldarezzo InLocation inlocation allows Stored XSS.This issue affects InLocation: from n/a through <= 1.8. | |||||
| CVE-2025-25160 | 1 Markbarnes | 1 Style Tweaker | 2026-06-17 | N/A | 7.1 HIGH |
| Cross-Site Request Forgery (CSRF) vulnerability in Mark Barnes Style Tweaker style-tweaker allows Stored XSS.This issue affects Style Tweaker: from n/a through <= 0.11. | |||||
| CVE-2025-25156 | 2026-06-17 | N/A | 7.1 HIGH | ||
| Cross-Site Request Forgery (CSRF) vulnerability in Stanko Metodiev Quote Comments quote-comments allows Stored XSS.This issue affects Quote Comments: from n/a through <= 3.0.0. | |||||
| CVE-2025-25154 | 2026-06-17 | N/A | 7.1 HIGH | ||
| Cross-Site Request Forgery (CSRF) vulnerability in scweber Custom Comment Notifications custom-comment-notifications allows Stored XSS.This issue affects Custom Comment Notifications: from n/a through <= 1.0.8. | |||||
