Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2024-06-05 CVE-2024-36668 Cross-Site Request Forgery (CSRF) vulnerability in Idccms Project Idccms 1.35
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/type_deal.php?mudi=del
network
low complexity
idccms-project CWE-352
8.8
2024-06-05 CVE-2024-36669 Cross-Site Request Forgery (CSRF) vulnerability in Idccms Project Idccms 1.35
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/type_deal.php?mudi=add.
network
low complexity
idccms-project CWE-352
8.8
2024-06-04 CVE-2024-36547 Cross-Site Request Forgery (CSRF) vulnerability in Idccms 1.35
idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/vpsClass_deal.php?mudi=add
network
low complexity
idccms CWE-352
8.8
2024-06-04 CVE-2024-36548 Cross-Site Request Forgery (CSRF) vulnerability in Idccms 1.35
idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/vpsCompany_deal.php?mudi=del
network
low complexity
idccms CWE-352
8.8
2024-06-04 CVE-2024-36549 Cross-Site Request Forgery (CSRF) vulnerability in Idccms 1.35
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/vpsCompany_deal.php?mudi=rev&nohrefStr=close
network
low complexity
idccms CWE-352
8.8
2024-06-04 CVE-2024-36550 Cross-Site Request Forgery (CSRF) vulnerability in Idccms 1.35
idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/vpsCompany_deal.php?mudi=add&nohrefStr=close
network
low complexity
idccms CWE-352
8.8
2024-05-31 CVE-2024-34008 Cross-Site Request Forgery (CSRF) vulnerability in Moodle
Actions in the admin management of analytics models did not include the necessary token to prevent a CSRF risk.
network
low complexity
moodle CWE-352
8.8
2024-05-30 CVE-2024-4426 Cross-Site Request Forgery (CSRF) vulnerability in Comparisonslider Comparison Slider
The Comparison Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.5.
network
low complexity
comparisonslider CWE-352
4.3
2024-05-30 CVE-2024-3943 Cross-Site Request Forgery (CSRF) vulnerability in Delower WP to DO
The WP To Do plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.0.
network
low complexity
delower CWE-352
4.3
2024-05-28 CVE-2024-4429 Cross-Site Request Forgery (CSRF) vulnerability in Microfocus Imanager
Cross-Site Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200.
network
low complexity
microfocus CWE-352
7.4