Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2023-11-16 CVE-2023-47687 Cross-Site Request Forgery (CSRF) vulnerability in Vjinfotech WOO Custom and Sequential Order Number 2.6.0
Cross-Site Request Forgery (CSRF) vulnerability in VJInfotech Woo Custom and Sequential Order Number plugin <= 2.6.0 versions.
network
low complexity
vjinfotech CWE-352
8.8
2023-11-16 CVE-2023-47688 Cross-Site Request Forgery (CSRF) vulnerability in Alexufo Youtube Speedload 0.6.3
Cross-Site Request Forgery (CSRF) vulnerability in Alexufo Youtube SpeedLoad plugin <= 0.6.3 versions.
network
low complexity
alexufo CWE-352
8.8
2023-11-16 CVE-2023-43275 Cross-Site Request Forgery (CSRF) vulnerability in Dedecms 5.7
Cross-Site Request Forgery (CSRF) vulnerability in DedeCMS v5.7 in 110 backend management interface via /catalog_add.php, allows attackers to create crafted web pages due to a lack of verification of the token value of the submitted form.
network
low complexity
dedecms CWE-352
8.8
2023-11-15 CVE-2023-4689 Cross-Site Request Forgery (CSRF) vulnerability in Webtechstreet Elementor Addon Elements
The Elementor Addon Elements plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.12.7.
network
low complexity
webtechstreet CWE-352
4.3
2023-11-15 CVE-2023-4690 Cross-Site Request Forgery (CSRF) vulnerability in Webtechstreet Elementor Addon Elements
The Elementor Addon Elements plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.12.7.
network
low complexity
webtechstreet CWE-352
4.3
2023-11-14 CVE-2023-47550 Cross-Site Request Forgery (CSRF) vulnerability in Rednao Donations Made Easy - Smart Donations
Cross-Site Request Forgery (CSRF) vulnerability in RedNao Donations Made Easy – Smart Donations allows Stored XSS.This issue affects Donations Made Easy – Smart Donations: from n/a through 4.0.12.
network
low complexity
rednao CWE-352
6.1
2023-11-14 CVE-2023-39412 Cross-Site Request Forgery (CSRF) vulnerability in Intel Unison Software 20.14.2.3053/20.14.4244
Cross-site request forgery in some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access.
network
low complexity
intel CWE-352
8.8
2023-11-14 CVE-2023-48020 Cross-Site Request Forgery (CSRF) vulnerability in Iteachyou Dreamer CMS 4.1.3
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/task/changeStatus.
network
low complexity
iteachyou CWE-352
8.8
2023-11-14 CVE-2023-48021 Cross-Site Request Forgery (CSRF) vulnerability in Iteachyou Dreamer CMS 4.1.3
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/task/update.
network
low complexity
iteachyou CWE-352
8.8
2023-11-13 CVE-2023-31230 Cross-Site Request Forgery (CSRF) vulnerability in Baidu-Tongji-Generator Project Baidu-Tongji-Generator 1.0.2
Cross-Site Request Forgery (CSRF) vulnerability in Haoqisir Baidu Tongji generator allows Stored XSS.This issue affects Baidu Tongji generator: from n/a through 1.0.2.
network
low complexity
baidu-tongji-generator-project CWE-352
6.1