Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2024-05-23 CVE-2023-7045 Cross-Site Request Forgery (CSRF) vulnerability in Gitlab
A CSRF vulnerability exists within GitLab CE/EE from versions 13.11 before 16.10.6, from 16.11 before 16.11.3, from 17.0 before 17.0.1.
network
low complexity
gitlab CWE-352
6.1
2024-05-22 CVE-2024-1446 Cross-Site Request Forgery (CSRF) vulnerability in Nextscripts Social Networks Auto Poster
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.4.3.
network
low complexity
nextscripts CWE-352
4.3
2024-05-14 CVE-2024-4597 Cross-Site Request Forgery (CSRF) vulnerability in Gitlab
An issue has been discovered in GitLab EE affecting all versions from 16.7 before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2.
network
low complexity
gitlab CWE-352
6.5
2024-05-02 CVE-2024-2960 Cross-Site Request Forgery (CSRF) vulnerability in Svs-Websoft SVS Pricing Tables
The SVS Pricing Tables plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4.
network
low complexity
svs-websoft CWE-352
4.3
2024-05-02 CVE-2024-3215 Cross-Site Request Forgery (CSRF) vulnerability in Strangerstudios Paid Memberships PRO
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1.
network
low complexity
strangerstudios CWE-352
4.3
2024-04-24 CVE-2024-32785 Cross-Site Request Forgery (CSRF) vulnerability in Webangon the Pack Elementor Addons
Cross-Site Request Forgery (CSRF) vulnerability in Webangon The Pack Elementor addons allows Cross-Site Scripting (XSS).This issue affects The Pack Elementor addons: from n/a through 2.0.8.3.
network
low complexity
webangon CWE-352
6.1
2024-04-10 CVE-2024-31985 Cross-Site Request Forgery (CSRF) vulnerability in Xwiki
XWiki Platform is a generic wiki platform.
network
low complexity
xwiki CWE-352
5.4
2024-04-10 CVE-2024-31986 Cross-Site Request Forgery (CSRF) vulnerability in Xwiki
XWiki Platform is a generic wiki platform.
network
low complexity
xwiki CWE-352
8.8
2024-04-10 CVE-2024-31988 Cross-Site Request Forgery (CSRF) vulnerability in Xwiki
XWiki Platform is a generic wiki platform.
network
low complexity
xwiki CWE-352
8.8
2024-03-22 CVE-2024-2449 Cross-Site Request Forgery (CSRF) vulnerability in Progress Loadmaster 7.1.35.10/7.2.48.10
A cross-site request forgery vulnerability has been identified in LoadMaster.  It is possible for a malicious actor, who has prior knowledge of the IP or hostname of a specific LoadMaster, to direct an authenticated LoadMaster administrator to a third-party site.
network
high complexity
progress CWE-352
7.5