| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| The js-jobs plugin before 1.0.7 for WordPress has CSRF. |
| The companion-auto-update plugin before 3.2.1 for WordPress has CSRF. |
| The church-admin plugin before 1.2550 for WordPress has CSRF affecting the upload of a bible reading plan. |
| The wp-ultimate-exporter plugin before 1.4.2 for WordPress has CSRF. |
| The wp-ultimate-csv-importer plugin before 5.6.1 for WordPress has CSRF. |
| The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF. |
| DrayTek routers before 2018-05-23 allow CSRF attacks to change DNS or DHCP settings, a related issue to CVE-2017-11649. |
| Advisto PEEL SHOPPING 9.0.0 has CSRF via en/achat/caddie_ajout.php and en/achat/caddie_affichage.php, as demonstrated by an XSS payload in the couleurId[0] parameter to the latter. |
| An XSS combined with CSRF vulnerability discovered in SalesAgility SuiteCRM 7.x before 7.8.24 and 7.10.x before 7.10.11 leads to cookie stealing, aka session hijacking. This issue affects the "add dashboard pages" feature where users can receive a malicious attack through a phished URL, with script executed. |
| Traq 3.7.1 allows admin/users/new CSRF to create an admin account (aka group_id=1). |
| A cross site request forgery (CSRF) vulnerability in NeDi before 1.7Cp3 allows remote attackers to escalate privileges via User-Management.php. |
| PHP Scripts Mall Car Rental Script 2.0.8 has Cross-Site Request Forgery (CSRF) via accountedit.php. |
| PHP Scripts Mall Basic B2B Script 2.0.9 has Cross-Site Request Forgery (CSRF) via the Edit profile feature. |
| PHP Scripts Mall Entrepreneur Job Portal Script 3.0.1 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature. |
| PHP Scripts Mall Advance B2B Script 2.1.4 has Cross-Site Request Forgery (CSRF) via the Edit Profile feature. |
| TEMMOKU T1.09 Beta allows admin/user/add CSRF. |
| UWA 2.3.11 allows index.php?g=admin&c=admin&a=add_admin_do CSRF. |
| Lei Feng TV CMS (aka LFCMS) 3.8.6 allows admin.php?s=/Member/add.html CSRF. |
| UCMS 1.4.7 has ?do=user_addpost CSRF. |
| A CSRF issue was discovered in web/authorization/oauth2/controller/OAuth2ClientController.java in hsweb 3.0.4 because the state parameter in the request is not compared with the state parameter in the session after user authentication is successful. |