Show filters
1,150 Total Results
Displaying 31-40 of 1,150
Sort by:
Attacker Value
Unknown

CVE-2022-25614

Disclosure Date: April 11, 2022 (last updated February 23, 2025)
Cross-Site Request Forgery (CSRF) in StylemixThemes eRoom – Zoom Meetings & Webinar (WordPress plugin) <= 1.3.7 allows an attacker to Sync with Zoom Meetings.
Attacker Value
Unknown

CVE-2022-27847

Disclosure Date: April 11, 2022 (last updated February 23, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Yooslider Yoo Slider <= 2.0.0 on WordPress allows attackers to import templates.
Attacker Value
Unknown

CVE-2022-27846

Disclosure Date: April 11, 2022 (last updated February 23, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Yooslider Yoo Slider <= 2.0.0 on WordPress allows attackers to create or modify slider.
Attacker Value
Unknown

CVE-2022-0914

Disclosure Date: April 11, 2022 (last updated February 23, 2025)
The Export All URLs WordPress plugin before 4.3 does not have CSRF in place when exporting data, which could allow attackers to make a logged in admin export all posts and pages (including private and draft) into an arbitrary CSV file, which the attacker can then download and retrieve the list of titles for example
Attacker Value
Unknown

CVE-2021-32162

Disclosure Date: April 11, 2022 (last updated February 23, 2025)
A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 through the File Manager feature.
Attacker Value
Unknown

CVE-2021-32159

Disclosure Date: April 11, 2022 (last updated February 23, 2025)
A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Upload and Download feature.
Attacker Value
Unknown

CVE-2021-32156

Disclosure Date: April 11, 2022 (last updated February 23, 2025)
A cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.
Attacker Value
Unknown

CVE-2022-26588

Disclosure Date: April 08, 2022 (last updated February 23, 2025)
A Cross-Site Request Forgery (CSRF) in IceHrm 31.0.0.OS allows attackers to delete arbitrary users or achieve account takeover via the app/service.php URI.
Attacker Value
Unknown

CVE-2022-26180

Disclosure Date: April 08, 2022 (last updated February 23, 2025)
qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI.
Attacker Value
Unknown

CVE-2022-24820

Disclosure Date: April 08, 2022 (last updated February 23, 2025)
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages of the wiki can still list documents by rendering some velocity documents. The problem has been patched in XWiki versions 12.10.11, 13.4.4, and 13.9-rc-1. There is no known workaround for this problem.