Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2025-04-22 CVE-2025-46245 Cross-Site Request Forgery (CSRF) vulnerability in Cminds CM AD Changer
Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Ad Changer allows Cross Site Request Forgery.
network
low complexity
cminds CWE-352
8.8
2025-04-22 CVE-2025-46246 Cross-Site Request Forgery (CSRF) vulnerability in Cminds CM Answers
Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM Answers allows Cross Site Request Forgery.
network
low complexity
cminds CWE-352
8.8
2025-04-22 CVE-2025-46249 Cross-Site Request Forgery (CSRF) vulnerability in Migaweb Simple Calendar for Elementor
Cross-Site Request Forgery (CSRF) vulnerability in Michael Simple calendar for Elementor allows Cross Site Request Forgery.
network
low complexity
migaweb CWE-352
8.8
2025-04-22 CVE-2025-46251 Cross-Site Request Forgery (CSRF) vulnerability in E4Jconnect Vikrestaurants Table Reservations and Take-Away
Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikRestaurants Table Reservations and Take-Away allows Cross Site Request Forgery.
network
low complexity
e4jconnect CWE-352
8.8
2025-04-19 CVE-2025-2111 The Insert Headers And Footers plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.1.
network
high complexity
CWE-352
7.5
2025-04-19 CVE-2025-3284 The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1.3.
network
low complexity
CWE-352
4.3
2025-04-12 CVE-2024-13337 The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.2.
network
low complexity
CWE-352
4.3
2025-04-12 CVE-2024-13338 The Clearfy Cache – WordPress optimization plugin, Minify HTML, CSS & JS, Defer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3.1.
network
low complexity
CWE-352
5.3
2025-04-12 CVE-2025-2871 The WordPress Mega Menu – QuadMenu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.0.
network
low complexity
CWE-352
4.3
2025-04-08 CVE-2025-27189 Cross-Site Request Forgery (CSRF) vulnerability in Adobe Commerce B2B
Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could be exploited to cause a denial-of-service condition.
network
low complexity
adobe CWE-352
4.3