Vulnerabilities > Cross-Site Request Forgery (CSRF)
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-01-18 | CVE-2024-22591 | Cross-Site Request Forgery (CSRF) vulnerability in Flycms Project Flycms 1.0 FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/user/group_save. | 8.8 |
2024-01-18 | CVE-2024-22592 | Cross-Site Request Forgery (CSRF) vulnerability in Flycms Project Flycms 1.0 FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/user/group_update | 8.8 |
2024-01-18 | CVE-2024-22593 | Cross-Site Request Forgery (CSRF) vulnerability in Flycms Project Flycms 1.0 FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/admin/add_group_save | 8.8 |
2024-01-18 | CVE-2024-22416 | Cross-Site Request Forgery (CSRF) vulnerability in Pyload-Ng Project Pyload-Ng pyLoad is a free and open-source Download Manager written in pure Python. | 8.8 |
2024-01-17 | CVE-2024-22715 | Cross-Site Request Forgery (CSRF) vulnerability in Codelyfe Stupid Simple CMS Stupid Simple CMS <=1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin-edit.php. | 8.8 |
2024-01-17 | CVE-2023-5006 | Cross-Site Request Forgery (CSRF) vulnerability in Sarveshmrao WP Discord Invite The WP Discord Invite WordPress plugin before 2.5.1 does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker to perform actions on their behalf by tricking a logged in administrator to submit a crafted request. | 6.5 |
2024-01-16 | CVE-2021-24870 | Cross-Site Request Forgery (CSRF) vulnerability in Wpfastestcache WP Fastest Cache The WP Fastest Cache WordPress plugin before 0.9.5 is lacking a CSRF check in its wpfc_save_cdn_integration AJAX action, and does not sanitise and escape some the options available via the action, which could allow attackers to make logged in high privilege users call it and set a Cross-Site Scripting payload | 6.1 |
2024-01-16 | CVE-2021-25117 | Cross-Site Request Forgery (CSRF) vulnerability in Lesterchan Wp-Postratings The WP-PostRatings WordPress plugin before 1.86.1 does not sanitise the postratings_image parameter from its options page (wp-admin/admin.php?page=wp-postratings/postratings-options.php). | 4.8 |
2024-01-16 | CVE-2022-1617 | Cross-Site Request Forgery (CSRF) vulnerability in Usabilitydynamics Wp-Invoice The WP-Invoice WordPress plugin through 4.3.1 does not have CSRF check in place when updating its settings, and is lacking sanitisation as well as escaping in some of them, allowing attacker to make a logged in admin change them and add XSS payload in them | 6.1 |
2024-01-16 | CVE-2022-1618 | Cross-Site Request Forgery (CSRF) vulnerability in Marcorulicke Coru Lfmember 1.0.2 The Coru LFMember WordPress plugin through 1.0.2 does not have CSRF check in place when adding a new game, and is lacking sanitisation as well as escaping in their settings, allowing attacker to make a logged in admin add an arbitrary game with XSS payloads | 6.1 |