Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2023-10-16 CVE-2023-45629 Cross-Site Request Forgery (CSRF) vulnerability in Wpdevart Gallery - Image and Video Gallery With Thumbnails
Cross-Site Request Forgery (CSRF) vulnerability in wpdevart Gallery – Image and Video Gallery with Thumbnails plugin <= 2.0.3 versions.
network
low complexity
wpdevart CWE-352
8.8
2023-10-13 CVE-2023-45269 Cross-Site Request Forgery (CSRF) vulnerability in Coleds Simple SEO
Cross-Site Request Forgery (CSRF) vulnerability in David Cole Simple SEO plugin <= 2.0.25 versions.
network
low complexity
coleds CWE-352
5.4
2023-10-12 CVE-2023-43148 Cross-Site Request Forgery (CSRF) vulnerability in Spa-Cart 1.9.0.3
SPA-Cart 1.9.0.3 has a Cross Site Request Forgery (CSRF) vulnerability that allows a remote attacker to delete all accounts.
network
low complexity
spa-cart CWE-352
8.1
2023-10-12 CVE-2023-43149 Cross-Site Request Forgery (CSRF) vulnerability in Spa-Cart 1.9.0.3
SPA-Cart 1.9.0.3 is vulnerable to Cross Site Request Forgery (CSRF) that allows a remote attacker to add an admin user with role status.
network
low complexity
spa-cart CWE-352
8.8
2023-10-12 CVE-2023-43147 Cross-Site Request Forgery (CSRF) vulnerability in PHPjabbers Limo Booking Software 1.0
PHPJabbers Limo Booking Software 1.0 is vulnerable to Cross Site Request Forgery (CSRF) to add an admin user via the Add Users Function, aka an index.php?controller=pjAdminUsers&action=pjActionCreate URI.
network
low complexity
phpjabbers CWE-352
8.8
2023-10-12 CVE-2023-45103 Cross-Site Request Forgery (CSRF) vulnerability in Yasglobalizer Permalinks Customizer
Cross-Site Request Forgery (CSRF) vulnerability in YAS Global Team Permalinks Customizer plugin <= 2.8.2 versions.
network
low complexity
yasglobalizer CWE-352
8.8
2023-10-12 CVE-2023-45047 Cross-Site Request Forgery (CSRF) vulnerability in Leadsquared Suite
Cross-Site Request Forgery (CSRF) vulnerability in LeadSquared, Inc LeadSquared Suite plugin <= 0.7.4 versions.
network
low complexity
leadsquared CWE-352
8.8
2023-10-10 CVE-2023-44995 Cross-Site Request Forgery (CSRF) vulnerability in Wpdoctor Woocommerce Login Redirect 2.2.4
Cross-Site Request Forgery (CSRF) vulnerability in WP Doctor WooCommerce Login Redirect plugin <= 2.2.4 versions.
network
low complexity
wpdoctor CWE-352
8.8
2023-10-10 CVE-2023-44476 Cross-Site Request Forgery (CSRF) vulnerability in Wp-Copyrightpro
Cross-Site Request Forgery (CSRF) vulnerability in Andres Felipe Perea V.
network
low complexity
wp-copyrightpro CWE-352
8.8
2023-10-10 CVE-2023-4837 Cross-Site Request Forgery (CSRF) vulnerability in Smod Smodbip
SmodBIP is vulnerable to Cross-Site Request Forgery, that could be used to induce logged in users to perform unintended actions, including creation of additional accounts with administrative privileges.
network
low complexity
smod CWE-352
8.8