Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2023-11-09 CVE-2023-47238 Cross-Site Request Forgery (CSRF) vulnerability in Webberzone TOP 10
Cross-Site Request Forgery (CSRF) vulnerability in WebberZone Top 10 – WordPress Popular posts by WebberZone plugin <= 3.3.2 versions.
network
low complexity
webberzone CWE-352
8.8
2023-11-09 CVE-2023-45884 Cross-Site Request Forgery (CSRF) vulnerability in Nasa Openmct
Cross Site Request Forgery (CSRF) vulnerability in NASA Open MCT (aka openmct) through 3.1.0 allows attackers to view sensitive information via the flexibleLayout plugin.
network
low complexity
nasa CWE-352
6.5
2023-11-08 CVE-2023-45857 Cross-Site Request Forgery (CSRF) vulnerability in Axios 1.5.1
An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.
network
low complexity
axios CWE-352
6.5
2023-11-07 CVE-2023-5982 Cross-Site Request Forgery (CSRF) vulnerability in Updraftplus
The UpdraftPlus: WordPress Backup & Migration Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.23.10.
network
low complexity
updraftplus CWE-352
5.4
2023-11-07 CVE-2023-5818 Cross-Site Request Forgery (CSRF) vulnerability in Gara Amazonify 0.8.1
The Amazonify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.8.1.
network
low complexity
gara CWE-352
4.3
2023-11-07 CVE-2023-46242 Cross-Site Request Forgery (CSRF) vulnerability in Xwiki
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it.
network
low complexity
xwiki CWE-352
8.8
2023-11-07 CVE-2023-5532 Cross-Site Request Forgery (CSRF) vulnerability in Imagemapper Project Imagemapper 1.2.6
The ImageMapper plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.6.
network
low complexity
imagemapper-project CWE-352
4.3
2023-11-07 CVE-2023-5975 Cross-Site Request Forgery (CSRF) vulnerability in Imagemapper Project Imagemapper 1.2.6
The ImageMapper plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.6.
network
low complexity
imagemapper-project CWE-352
4.3
2023-11-07 CVE-2023-5900 Cross-Site Request Forgery (CSRF) vulnerability in SFU PKP web Application Library
Cross-Site Request Forgery in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
network
low complexity
sfu CWE-352
4.3
2023-11-07 CVE-2023-5902 Cross-Site Request Forgery (CSRF) vulnerability in SFU PKP web Application Library
Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
network
low complexity
sfu CWE-352
4.3