Vulnerabilities > Cross-Site Request Forgery (CSRF)

DATE CVE VULNERABILITY TITLE RISK
2022-11-17 CVE-2022-45072 Cross-Site Request Forgery (CSRF) vulnerability in Wpml
Cross-Site Request Forgery (CSRF) vulnerability in WPML Multilingual CMS premium plugin <= 4.5.13 on WordPress.
network
low complexity
wpml CWE-352
4.3
2022-11-17 CVE-2022-42246 Cross-Site Request Forgery (CSRF) vulnerability in Duofoxtechnologies Duofox CMS 0.0.4
Doufox 0.0.4 contains a CSRF vulnerability that can add system administrator account.
network
low complexity
duofoxtechnologies CWE-352
8.8
2022-11-16 CVE-2022-4021 Cross-Site Request Forgery (CSRF) vulnerability in Permalink Manager Lite Project Permalink Manager Lite
The Permalink Manager Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2.20.1.
network
low complexity
permalink-manager-lite-project CWE-352
4.3
2022-11-16 CVE-2022-4013 Cross-Site Request Forgery (CSRF) vulnerability in Hospital Management Center Project Hospital Management Center
A vulnerability classified as problematic was found in Hospital Management Center.
8.8
2022-11-16 CVE-2022-4014 Cross-Site Request Forgery (CSRF) vulnerability in Feehi Feehicms
A vulnerability, which was classified as problematic, has been found in FeehiCMS.
network
low complexity
feehi CWE-352
4.3
2022-11-15 CVE-2022-45393 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Delete LOG 1.0
A cross-site request forgery (CSRF) vulnerability in Jenkins Delete log Plugin 1.0 and earlier allows attackers to delete build logs.
network
low complexity
jenkins CWE-352
3.5
2022-11-15 CVE-2022-45398 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Cluster Statistics 0.4.6
A cross-site request forgery (CSRF) vulnerability in Jenkins Cluster Statistics Plugin 0.4.6 and earlier allows attackers to delete recorded Jenkins Cluster Statistics.
network
low complexity
jenkins CWE-352
4.3
2022-11-15 CVE-2022-3240 Cross-Site Request Forgery (CSRF) vulnerability in Follow ME Plugin Project Follow ME Plugin
The "Follow Me Plugin" plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.1.
network
low complexity
follow-me-plugin-project CWE-352
8.8
2022-11-15 CVE-2022-35613 Cross-Site Request Forgery (CSRF) vulnerability in Konker Platform 2.3.9
Konker v2.3.9 was to discovered to contain a Cross-Site Request Forgery (CSRF).
network
low complexity
konker CWE-352
8.8
2022-11-14 CVE-2022-43323 Cross-Site Request Forgery (CSRF) vulnerability in Eyoucms 1.5.9
EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Top Up Balance component under the Edit Member module.
network
low complexity
eyoucms CWE-352
8.8