Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2024-10-20 CVE-2024-49628 Cross-Site Request Forgery (CSRF) vulnerability in Whiletrue Most and Least Read Posts Widget 2.5.16
Cross-Site Request Forgery (CSRF) vulnerability in WhileTrue Most And Least Read Posts Widget allows Cross Site Request Forgery.This issue affects Most And Least Read Posts Widget: from n/a through 2.5.18.
network
low complexity
whiletrue CWE-352
8.8
2024-10-20 CVE-2024-49335 Cross-Site Request Forgery (CSRF) vulnerability in Edush Maxim Googledrive Folder List
Cross-Site Request Forgery (CSRF) vulnerability in Edush Maxim GoogleDrive folder list allows Stored XSS.This issue affects GoogleDrive folder list: from n/a through 2.2.2.
network
low complexity
edush-maxim CWE-352
6.1
2024-10-20 CVE-2024-49605 Cross-Site Request Forgery (CSRF) vulnerability in Avchat.Net Avchat Video Chat
Cross-Site Request Forgery (CSRF) vulnerability in Avchat.Net AVChat Video Chat allows Stored XSS.This issue affects AVChat Video Chat: from n/a through 2.2.
network
low complexity
avchat-net CWE-352
6.1
2024-10-20 CVE-2024-49615 Cross-Site Request Forgery (CSRF) vulnerability in Henriquerodrigues Safetyforms
Cross-Site Request Forgery (CSRF) vulnerability in Henrique Rodrigues SafetyForms allows Blind SQL Injection.This issue affects SafetyForms: from n/a through 1.0.0.
network
low complexity
henriquerodrigues CWE-352
8.8
2024-10-20 CVE-2024-49617 Cross-Site Request Forgery (CSRF) vulnerability in Bhaskardhote Back Link Tracker
Cross-Site Request Forgery (CSRF) vulnerability in Bhaskar Dhote Back Link Tracker allows Blind SQL Injection.This issue affects Back Link Tracker: from n/a through 1.0.0.
network
low complexity
bhaskardhote CWE-352
8.8
2024-10-20 CVE-2024-49629 Cross-Site Request Forgery (CSRF) vulnerability in Androidbubbles Endless Posts Navigation
Cross-Site Request Forgery (CSRF) vulnerability in Fahad Mahmood Endless Posts Navigation allows Stored XSS.This issue affects Endless Posts Navigation: from n/a through 2.2.7.
network
low complexity
androidbubbles CWE-352
6.1
2024-10-20 CVE-2024-49621 Cross-Site Request Forgery (CSRF) vulnerability in APA Register Newsletter Form
Cross-Site Request Forgery (CSRF) vulnerability in Apa APA Register Newsletter Form allows SQL Injection.This issue affects APA Register Newsletter Form: from n/a through 1.0.0.
network
low complexity
apa CWE-352
8.8
2024-10-20 CVE-2024-49622 Cross-Site Request Forgery (CSRF) vulnerability in APA Banner Slider
Cross-Site Request Forgery (CSRF) vulnerability in Apa Apa Banner Slider allows SQL Injection.This issue affects Apa Banner Slider: from n/a through 1.0.0.
network
low complexity
apa CWE-352
8.8
2024-10-19 CVE-2023-6243 Cross-Site Request Forgery (CSRF) vulnerability in Myeventon Eventon-Lite
The EventON PRO - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6.8.
network
low complexity
myeventon CWE-352
4.3
2024-10-18 CVE-2024-10040 Cross-Site Request Forgery (CSRF) vulnerability in Infinite-Scroll
The Infinite-Scroll plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.2.
network
low complexity
infinite-scroll CWE-352
4.3