Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2018-05-31 CVE-2018-11632 Cross-Site Request Forgery (CSRF) vulnerability in Multidots ADD Social Share Messenger Buttons Whatsapp and Viber 1.0.8
An issue was discovered in the MULTIDOTS Add Social Share Messenger Buttons Whatsapp and Viber plugin 1.0.8 for WordPress.
network
low complexity
multidots CWE-352
6.5
2018-05-31 CVE-2016-10529 Cross-Site Request Forgery (CSRF) vulnerability in Droppy Project Droppy
Droppy versions <3.5.0 does not perform any verification for cross-domain websocket requests.
network
low complexity
droppy-project CWE-352
8.8
2018-05-30 CVE-2015-7610 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
Cross-site request forgery (CSRF) vulnerability in the login form in Zimbra Collaboration Suite (aka ZCS) before 8.6.0 Patch 10, 8.7.x before 8.7.11 Patch 2, and 8.8.x before 8.8.8 Patch 1 allows remote attackers to hijack the authentication of unspecified victims by leveraging failure to use a CSRF token.
network
low complexity
zimbra synacor CWE-352
8.8
2018-05-29 CVE-2018-11527 Cross-Site Request Forgery (CSRF) vulnerability in Cscms Project Cscms 4.1
An issue was discovered in CScms v4.1.
network
low complexity
cscms-project CWE-352
8.8
2018-05-26 CVE-2018-11500 Cross-Site Request Forgery (CSRF) vulnerability in Publiccms 4.0.20180210
An issue was discovered in PublicCMS V4.0.20180210.
network
low complexity
publiccms CWE-352
8.8
2018-05-26 CVE-2018-11493 Cross-Site Request Forgery (CSRF) vulnerability in Wuzhicms Wuzhi CMS 4.1.0
An issue was discovered in WUZHI CMS 4.1.0.
network
low complexity
wuzhicms CWE-352
8.8
2018-05-25 CVE-2017-9641 Cross-Site Request Forgery (CSRF) vulnerability in Osisoft PI Coresight
PI Coresight 2016 R2 contains a cross-site request forgery vulnerability that may allow access to the PI system.
network
low complexity
osisoft CWE-352
8.8
2018-05-25 CVE-2018-11445 Cross-Site Request Forgery (CSRF) vulnerability in Easyservice Billing Project Easyservice Billing 1.0
A CSRF issue was discovered on the User Add/System Settings Page (system-settings-user-new2.php) in EasyService Billing 1.0.
network
low complexity
easyservice-billing-project CWE-352
8.8
2018-05-25 CVE-2018-11442 Cross-Site Request Forgery (CSRF) vulnerability in Easyservice Billing Project Easyservice Billing 1.0
A CSRF issue was discovered in EasyService Billing 1.0, which was triggered via a quotation-new3-new2.php?add=true&id= URI, as demonstrated by adding a new quotation.
network
low complexity
easyservice-billing-project CWE-352
8.8
2018-05-24 CVE-2018-11405 Cross-Site Request Forgery (CSRF) vulnerability in Kliqqi CMS 2.0.2
Kliqqi 2.0.2 has CSRF in admin/admin_users.php.
network
low complexity
kliqqi CWE-352
8.8