Vulnerabilities (CVE)

Filtered by CWE-352
Total 6068 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-52401 2024-11-20 N/A 9.6 CRITICAL
Cross-Site Request Forgery (CSRF) vulnerability in 荒野无灯 Hacklog DownloadManager allows Upload a Web Shell to a Web Server.This issue affects Hacklog DownloadManager: from n/a through 2.1.4.
CVE-2024-52424 1 Sureshkumar 1 Wp-login Customizer 2024-11-20 N/A 6.1 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in Suresh Kumar wp-login customizer allows Stored XSS.This issue affects wp-login customizer: from n/a through 1.0.
CVE-2023-32104 1 Target-info 1 Mycurator Content Curation 2024-11-20 N/A 6.5 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in Mark Tilly MyCurator Content Curation plugin <= 3.74 versions.
CVE-2022-40128 1 Algolplus 1 Advanced Order Export For Woocommerce 2024-11-20 N/A 6.5 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in Advanced Order Export For WooCommerce plugin <= 3.3.2 on WordPress leading to export file download.
CVE-2024-52451 2024-11-20 N/A 8.2 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Aaron Robbins Post Ideas allows SQL Injection.This issue affects Post Ideas: from n/a through 2.
CVE-2024-52446 2024-11-20 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Buying Buddy Buying Buddy IDX CRM allows Object Injection.This issue affects Buying Buddy IDX CRM: from n/a through 1.1.12.
CVE-2024-52392 2024-11-19 N/A 6.3 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in W3speedster W3SPEEDSTER.This issue affects W3SPEEDSTER: from n/a through 7.25.
CVE-2024-51669 2024-11-19 N/A 4.3 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in Vivwebs Dynamic Widgets.This issue affects Dynamic Widgets: from n/a through 1.6.4.
CVE-2024-51637 2024-11-19 N/A 7.1 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Scott E. Royalty Admin SMS Alert allows Stored XSS.This issue affects Admin SMS Alert: from n/a through 1.1.0.
CVE-2024-51652 2024-11-19 N/A 7.1 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Prem Nawaz Khan, Victor Tsaran, Ron Feathers, and Marc Kocher Skip To allows Stored XSS.This issue affects Skip To: from n/a through 2.0.0.
CVE-2024-51656 2024-11-19 N/A 7.1 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in litefeel Flash Show And Hide Box allows Stored XSS.This issue affects Flash Show And Hide Box: from n/a through 1.6.
CVE-2024-51638 2024-11-19 N/A 7.1 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Sanjeev Mohindra Awesome Shortcodes For Genesis allows Stored XSS.This issue affects Awesome Shortcodes For Genesis: from n/a through .8.
CVE-2024-51632 2024-11-19 N/A 7.1 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Sam Hoe SH Slideshow allows Stored XSS.This issue affects SH Slideshow: from n/a through 4.3.
CVE-2024-51641 2024-11-19 N/A 7.1 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in jcmlmorav Advanced PDF Generator allows Stored XSS.This issue affects Advanced PDF Generator: from n/a through 0.4.0.
CVE-2024-51633 2024-11-19 N/A 7.1 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in IvyCat Web Services Simple Page Specific Sidebars allows Stored XSS.This issue affects Simple Page Specific Sidebars: from n/a through 2.14.1.
CVE-2024-51644 2024-11-19 N/A 7.1 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Sam Wilson Addressbook allows Stored XSS.This issue affects Addressbook: from n/a through 1.1.3.
CVE-2024-51655 2024-11-19 N/A 7.1 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Microkid Custom Author URL allows Stored XSS.This issue affects Custom Author URL: from n/a through 2.0.1.
CVE-2024-51653 2024-11-19 N/A 7.1 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Mario Spinaci UPDATE NOTIFICATIONS allows Stored XSS.This issue affects UPDATE NOTIFICATIONS: from n/a through 0.3.4.
CVE-2024-51649 2024-11-19 N/A 7.1 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Patrick Lumumba Mobilize allows Stored XSS.This issue affects Mobilize: from n/a through 3.0.7.
CVE-2024-43338 2024-11-19 N/A 4.3 MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & more allows Cross Site Request Forgery.This issue affects Crowdsignal Dashboard – Polls, Surveys & more: from n/a through 3.1.2.