Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2025-05-17 CVE-2025-4189 The Audio Comments Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4.
network
low complexity
CWE-352
6.1
2025-05-17 CVE-2025-4194 The AlT Monitoring plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3.
network
low complexity
CWE-352
6.1
2025-05-07 CVE-2025-20195 A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a CSRF attack and execute commands on the CLI of an affected device. This vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device.
network
low complexity
CWE-352
4.3
2025-05-07 CVE-2025-47546 Cross-Site Request Forgery (CSRF) vulnerability in Wpcompress WP Compress
Cross-Site Request Forgery (CSRF) vulnerability in AresIT WP Compress allows Cross Site Request Forgery.
network
low complexity
wpcompress CWE-352
8.8
2025-05-07 CVE-2025-47624 Cross-Site Request Forgery (CSRF) vulnerability in Apasionados Dofollow Case BY Case
Cross-Site Request Forgery (CSRF) vulnerability in apasionados DoFollow Case by Case allows Cross Site Request Forgery.
network
low complexity
apasionados CWE-352
8.8
2025-05-07 CVE-2025-47633 Cross-Site Request Forgery (CSRF) vulnerability in Awin - Advertiser Tracking for Woocommerce
Cross-Site Request Forgery (CSRF) vulnerability in Awin Awin – Advertiser Tracking for WooCommerce allows Cross Site Request Forgery.
network
low complexity
awin CWE-352
8.8
2025-05-06 CVE-2025-4337 The AHAthat Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.
network
low complexity
CWE-352
4.3
2025-05-03 CVE-2025-4188 The Advanced Reorder Image Text Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.
network
low complexity
CWE-352
6.1
2025-05-03 CVE-2025-4198 The Alink Tap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.1.
network
low complexity
CWE-352
6.1
2025-05-03 CVE-2025-4199 The Abundatrade Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.02.
network
low complexity
CWE-352
6.1