Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2024-02-05 CVE-2024-0428 Cross-Site Request Forgery (CSRF) vulnerability in Kobzarev Index NOW
The Index Now plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.3.
network
low complexity
kobzarev CWE-352
8.8
2024-02-05 CVE-2024-0660 Cross-Site Request Forgery (CSRF) vulnerability in Strategy11 Formidable Forms
The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.7.2.
network
low complexity
strategy11 CWE-352
4.3
2024-02-05 CVE-2024-0790 Cross-Site Request Forgery (CSRF) vulnerability in Pluginus Wolf - Wordpress Posts Bulk Editor and products Manager Professional
The WOLF – WordPress Posts Bulk Editor and Manager Professional plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.8.1.
network
low complexity
pluginus CWE-352
4.3
2024-02-05 CVE-2024-0796 Cross-Site Request Forgery (CSRF) vulnerability in Pluginus Woot
The Active Products Tables for WooCommerce.
network
low complexity
pluginus CWE-352
4.3
2024-02-05 CVE-2024-0859 Cross-Site Request Forgery (CSRF) vulnerability in Wpaffiliatemanager Affiliates Manager
The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.9.34.
network
low complexity
wpaffiliatemanager CWE-352
4.3
2024-02-05 CVE-2024-24468 Cross-Site Request Forgery (CSRF) vulnerability in Flusity 2.33
Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the add_customblock.php.
network
low complexity
flusity CWE-352
8.8
2024-02-05 CVE-2024-24469 Cross-Site Request Forgery (CSRF) vulnerability in Flusity 2.33
Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the delete_post .php.
network
low complexity
flusity CWE-352
8.8
2024-02-02 CVE-2024-23831 Cross-Site Request Forgery (CSRF) vulnerability in Ledgersmb
LedgerSMB is a free web-based double-entry accounting system.
network
high complexity
ledgersmb CWE-352
7.5
2024-02-02 CVE-2024-24470 Cross-Site Request Forgery (CSRF) vulnerability in Flusity 2.33
Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the update_post.php component.
network
low complexity
flusity CWE-352
8.8
2024-02-02 CVE-2023-6676 Cross-Site Request Forgery (CSRF) vulnerability in Nationalkeep Cybermath 1.4
Cross-Site Request Forgery (CSRF) vulnerability in National Keep Cyber Security Services CyberMath allows Cross Site Request Forgery.This issue affects CyberMath: from v1.4 before v1.5.
network
low complexity
nationalkeep CWE-352
8.8