Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2024-08-27 CVE-2024-45264 Cross-Site Request Forgery (CSRF) vulnerability in Skyss Arfa-Cms
A cross-site request forgery (CSRF) vulnerability in the admin panel in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to add a new administrator, leading to escalation of privileges.
network
low complexity
skyss CWE-352
8.8
2024-08-27 CVE-2024-8200 Cross-Site Request Forgery (CSRF) vulnerability in Smashballoon Reviews Feed
The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2.
network
low complexity
smashballoon CWE-352
4.3
2024-08-26 CVE-2024-39628 Cross-Site Request Forgery (CSRF) vulnerability in Ninjaforms Ninja Forms
Cross-Site Request Forgery (CSRF) vulnerability in Saturday Drive Ninja Forms allows Cross Site Request Forgery.This issue affects Ninja Forms: from n/a through 3.8.6.
network
low complexity
ninjaforms CWE-352
8.8
2024-08-26 CVE-2024-39641 Cross-Site Request Forgery (CSRF) vulnerability in Thimpress Learnpress
Cross-Site Request Forgery (CSRF) vulnerability in ThimPress LearnPress.This issue affects LearnPress: from n/a through 4.2.6.8.2.
network
low complexity
thimpress CWE-352
8.8
2024-08-26 CVE-2024-39645 Cross-Site Request Forgery (CSRF) vulnerability in Themeum Tutor LMS
Cross-Site Request Forgery (CSRF) vulnerability in Themeum Tutor LMS.This issue affects Tutor LMS: from n/a through 2.7.2.
network
low complexity
themeum CWE-352
8.8
2024-08-26 CVE-2024-39657 Cross-Site Request Forgery (CSRF) vulnerability in Sender
Cross-Site Request Forgery (CSRF) vulnerability in Sender Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce.This issue affects Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce: from n/a through 2.6.18.
network
low complexity
sender CWE-352
8.8
2024-08-26 CVE-2024-43116 Cross-Site Request Forgery (CSRF) vulnerability in 10Up Simple Local Avatars
Cross-Site Request Forgery (CSRF) vulnerability in 10up Simple Local Avatars.This issue affects Simple Local Avatars: from n/a through 2.7.10.
network
low complexity
10up CWE-352
8.8
2024-08-26 CVE-2024-43117 Cross-Site Request Forgery (CSRF) vulnerability in Wpmudev Hummingbird
Cross-Site Request Forgery (CSRF) vulnerability in WPMU DEV Hummingbird.This issue affects Hummingbird: from n/a through 3.9.1.
network
low complexity
wpmudev CWE-352
8.8
2024-08-26 CVE-2024-43255 Cross-Site Request Forgery (CSRF) vulnerability in Stormhillmedia Mybook Table Bookstore
Cross-Site Request Forgery (CSRF) vulnerability in Stormhill Media MyBookTable Bookstore allows Cross-Site Scripting (XSS).This issue affects MyBookTable Bookstore: from n/a through 3.3.9.
network
low complexity
stormhillmedia CWE-352
6.1
2024-08-26 CVE-2024-43265 Cross-Site Request Forgery (CSRF) vulnerability in Analytify - Google Analytics Dashboard
Cross-Site Request Forgery (CSRF) vulnerability in Analytify.This issue affects Analytify: from n/a through 5.3.1.
network
low complexity
analytify CWE-352
3.5