Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2022-11-08 CVE-2022-27855 Cross-Site Request Forgery (CSRF) vulnerability in Fatcatapps Analytics CAT
Cross-Site Request Forgery (CSRF) vulnerability in Fatcat Apps Analytics Cat plugin <= 1.0.9 on WordPress allows Plugin Settings Change.
network
low complexity
fatcatapps CWE-352
4.3
2022-11-08 CVE-2022-32587 Cross-Site Request Forgery (CSRF) vulnerability in Codeandmore WP Page Widget
Cross-Site Request Forgery (CSRF) vulnerability in CodeAndMore WP Page Widget plugin <= 3.9 on WordPress leading to plugin settings change.
network
low complexity
codeandmore CWE-352
4.3
2022-11-08 CVE-2022-38137 Cross-Site Request Forgery (CSRF) vulnerability in Analytify - Google Analytics Dashboard
Cross-Site Request Forgery (CSRF) vulnerability in Analytify plugin <= 4.2.2 on WordPress.
network
low complexity
analytify CWE-352
8.8
2022-11-08 CVE-2022-40128 Cross-Site Request Forgery (CSRF) vulnerability in Algolplus Advanced Order Export for Woocommerce
Cross-Site Request Forgery (CSRF) vulnerability in Advanced Order Export For WooCommerce plugin <= 3.3.2 on WordPress leading to export file download.
network
low complexity
algolplus CWE-352
6.5
2022-11-08 CVE-2022-40632 Cross-Site Request Forgery (CSRF) vulnerability in Gvectors Wpforo Forum
Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 on WordPress leading to topic deletion.
network
low complexity
gvectors CWE-352
5.4
2022-11-08 CVE-2022-41136 Cross-Site Request Forgery (CSRF) vulnerability in Getshortcodes Shortcodes Ultimate
Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in Vladimir Anokhin's Shortcodes Ultimate plugin <= 5.12.0 on WordPress.
network
low complexity
getshortcodes CWE-352
8.8
2022-11-08 CVE-2022-43481 Cross-Site Request Forgery (CSRF) vulnerability in Rymera Advanced Coupons
Cross-Site Request Forgery (CSRF) vulnerability in Advanced Coupons for WooCommerce Coupons plugin <= 4.5 on WordPress leading to notice dismissal.
network
low complexity
rymera CWE-352
4.3
2022-11-08 CVE-2022-43491 Cross-Site Request Forgery (CSRF) vulnerability in Algolplus Advanced Dynamic Pricing for Woocommerce
Cross-Site Request Forgery (CSRF) vulnerability in Advanced Dynamic Pricing for WooCommerce plugin <= 4.1.5 on WordPress leading to plugin settings import.
network
low complexity
algolplus CWE-352
4.3
2022-11-08 CVE-2022-44741 Cross-Site Request Forgery (CSRF) vulnerability in Slidervilla Testimonial Slider
Cross-Site Request Forgery (CSRF) vulnerability leading to Cross-Site Scripting (XSS) in David Anderson Testimonial Slider plugin <= 1.3.1 on WordPress.
network
low complexity
slidervilla CWE-352
8.8
2022-11-04 CVE-2022-38660 Cross-Site Request Forgery (CSRF) vulnerability in Hcltech Domino 9.0/9.0.1
HCL XPages applications are susceptible to a Cross Site Request Forgery (CSRF) vulnerability.
network
low complexity
hcltech CWE-352
8.8