Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2018-06-02 CVE-2018-11679 Cross-Site Request Forgery (CSRF) vulnerability in Cmseasy 6.0
An issue was discovered in CmsEasy 6.1_20180508.
network
low complexity
cmseasy CWE-352
8.8
2018-06-01 CVE-2018-11538 Cross-Site Request Forgery (CSRF) vulnerability in Searchblox 8.6.6
servlet/UserServlet in SearchBlox 8.6.6 has CSRF via the u_name, u_passwd1, u_passwd2, role, and X-XSRF-TOKEN POST parameters because of CSRF Token Bypass.
network
low complexity
searchblox CWE-352
8.8
2018-06-01 CVE-2018-11671 Cross-Site Request Forgery (CSRF) vulnerability in Njtech Greencms 2.3.0603
An issue was discovered in GreenCMS v2.3.0603.
network
low complexity
njtech CWE-352
8.8
2018-06-01 CVE-2018-11670 Cross-Site Request Forgery (CSRF) vulnerability in Njtech Greencms 2.3.0603
An issue was discovered in GreenCMS v2.3.0603.
network
low complexity
njtech CWE-352
8.8
2018-05-31 CVE-2018-11633 Cross-Site Request Forgery (CSRF) vulnerability in Multidots WOO Checkout for Digital Goods 2.1
An issue was discovered in the MULTIDOTS Woo Checkout for Digital Goods plugin 2.1 for WordPress.
network
low complexity
multidots CWE-352
6.5
2018-05-31 CVE-2018-11632 Cross-Site Request Forgery (CSRF) vulnerability in Multidots ADD Social Share Messenger Buttons Whatsapp and Viber 1.0.8
An issue was discovered in the MULTIDOTS Add Social Share Messenger Buttons Whatsapp and Viber plugin 1.0.8 for WordPress.
network
low complexity
multidots CWE-352
6.5
2018-05-31 CVE-2016-10529 Cross-Site Request Forgery (CSRF) vulnerability in Droppy Project Droppy
Droppy versions <3.5.0 does not perform any verification for cross-domain websocket requests.
network
low complexity
droppy-project CWE-352
8.8
2018-05-30 CVE-2015-7610 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
Cross-site request forgery (CSRF) vulnerability in the login form in Zimbra Collaboration Suite (aka ZCS) before 8.6.0 Patch 10, 8.7.x before 8.7.11 Patch 2, and 8.8.x before 8.8.8 Patch 1 allows remote attackers to hijack the authentication of unspecified victims by leveraging failure to use a CSRF token.
network
low complexity
zimbra synacor CWE-352
8.8
2018-05-29 CVE-2018-11527 Cross-Site Request Forgery (CSRF) vulnerability in Cscms Project Cscms 4.1
An issue was discovered in CScms v4.1.
network
low complexity
cscms-project CWE-352
8.8
2018-05-26 CVE-2018-11500 Cross-Site Request Forgery (CSRF) vulnerability in Publiccms 4.0.20180210
An issue was discovered in PublicCMS V4.0.20180210.
network
low complexity
publiccms CWE-352
8.8