Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2019-08-27 CVE-2018-21006 Cross-Site Request Forgery (CSRF) vulnerability in Bbpress Move Topics Project Bbpress Move Topics
The bbp-move-topics plugin before 1.1.6 for WordPress has CSRF.
network
low complexity
bbpress-move-topics-project CWE-352
8.8
2019-08-27 CVE-2018-21002 Cross-Site Request Forgery (CSRF) vulnerability in Joomsky JS Help Desk
The js-support-ticket plugin before 2.0.6 for WordPress has CSRF.
network
low complexity
joomsky CWE-352
8.8
2019-08-27 CVE-2015-9343 Cross-Site Request Forgery (CSRF) vulnerability in Impress WP Rollback
The wp-rollback plugin before 1.2.3 for WordPress has CSRF.
network
low complexity
impress CWE-352
8.8
2019-08-26 CVE-2019-15515 Cross-Site Request Forgery (CSRF) vulnerability in Discourse 2.3.2
Discourse 2.3.2 sends the CSRF token in the query string.
network
low complexity
discourse CWE-352
6.5
2019-08-23 CVE-2019-8447 Cross-Site Request Forgery (CSRF) vulnerability in Atlassian Jira Server
The ServiceExecutor resource in Jira before version 8.3.2 allows remote attackers to trigger the creation of export files via a Cross-site request forgery (CSRF) vulnerability.
network
low complexity
atlassian CWE-352
4.3
2019-08-23 CVE-2019-14999 Cross-Site Request Forgery (CSRF) vulnerability in Atlassian Universal Plugin Manager
The Uninstall REST endpoint in Atlassian Universal Plugin Manager before version 2.22.19, from version 3.0.0 before version 3.0.3 and from version 4.0.0 before version 4.0.3 allows remote attackers to uninstall plugins using a Cross-Site Request Forgery (CSRF) vulnerability on an authenticated administrator.
network
low complexity
atlassian CWE-352
4.3
2019-08-23 CVE-2019-11588 Cross-Site Request Forgery (CSRF) vulnerability in Atlassian Jira
The ViewSystemInfo class doGarbageCollection method in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to trigger garbage collection via a Cross-site request forgery (CSRF) vulnerability.
network
low complexity
atlassian CWE-352
4.3
2019-08-23 CVE-2019-11587 Cross-Site Request Forgery (CSRF) vulnerability in Atlassian Jira
Various exposed resources of the ViewLogging class in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allow remote attackers to modify various settings via Cross-site request forgery (CSRF).
network
low complexity
atlassian CWE-352
6.5
2019-08-23 CVE-2019-11586 Cross-Site Request Forgery (CSRF) vulnerability in Atlassian Jira
The AddResolution.jspa resource in Jira before version 7.13.6, from version 8.0.0 before version 8.2.3, and from version 8.3.0 before version 8.3.2 allows remote attackers to create new resolutions via a Cross-site request forgery (CSRF) vulnerability.
network
low complexity
atlassian CWE-352
4.3
2019-08-23 CVE-2019-15491 Cross-Site Request Forgery (CSRF) vulnerability in It-Novum Openitcockpit
openITCOCKPIT before 3.7.1 has CSRF, aka RVID 2-445b21.
network
low complexity
it-novum CWE-352
8.8