Show filters
952 Total Results
Displaying 51-60 of 952
Sort by:
Attacker Value
Unknown

CVE-2021-24696

Disclosure Date: January 24, 2022 (last updated February 23, 2025)
The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerability (fixed in 3.9.6), 2) delete logs (fixed in 3.9.9), 3) remove thumbnail image from downloads
Attacker Value
Unknown

CVE-2021-46028

Disclosure Date: January 20, 2022 (last updated February 23, 2025)
In mblog <= 3.5.0 there is a CSRF vulnerability in the background article management. The attacker constructs a CSRF load. Once the administrator clicks a malicious link, the article will be deleted.
Attacker Value
Unknown

CVE-2021-46027

Disclosure Date: January 19, 2022 (last updated February 23, 2025)
mysiteforme, as of 19-12-2022, has a CSRF vulnerability in the background blog management. The attacker constructs a CSRF load. Once the administrator clicks a malicious link, a blog tag will be added
Attacker Value
Unknown

CVE-2022-0215

Disclosure Date: January 18, 2022 (last updated February 23, 2025)
The Login/Signup Popup, Waitlist Woocommerce ( Back in stock notifier ), and Side Cart Woocommerce (Ajax) WordPress plugins by XootiX are vulnerable to Cross-Site Request Forgery via the save_settings function found in the ~/includes/xoo-framework/admin/class-xoo-admin-settings.php file which makes it possible for attackers to update arbitrary options on a site that can be used to create an administrative user account and grant full privileged access to a compromised site. This affects versions <= 2.2 in Login/Signup Popup, versions <= 2.5.1 in Waitlist Woocommerce ( Back in stock notifier ), and versions <= 2.0 in Side Cart Woocommerce (Ajax).
Attacker Value
Unknown

CVE-2022-0154

Disclosure Date: January 18, 2022 (last updated February 23, 2025)
An issue has been discovered in GitLab affecting all versions starting from 7.7 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to a Cross-Site Request Forgery attack that allows a malicious user to have their GitHub project imported on another GitLab user account.
Attacker Value
Unknown

CVE-2021-43353

Disclosure Date: January 18, 2022 (last updated February 23, 2025)
The Crisp Live Chat WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the crisp_plugin_settings_page function found in the ~/crisp.php file, which made it possible for attackers to inject arbitrary web scripts in versions up to, and including 0.31.
Attacker Value
Unknown

CVE-2022-0245

Disclosure Date: January 18, 2022 (last updated February 23, 2025)
Cross-Site Request Forgery (CSRF) in GitHub repository livehelperchat/livehelperchat prior to 2.0.
Attacker Value
Unknown

CVE-2021-4164

Disclosure Date: January 17, 2022 (last updated February 23, 2025)
calibre-web is vulnerable to Cross-Site Request Forgery (CSRF)
Attacker Value
Unknown

CVE-2021-25025

Disclosure Date: January 17, 2022 (last updated February 23, 2025)
The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_event AJAX actions, allowing users with a role as low as subscriber to create events
Attacker Value
Unknown

CVE-2022-0180

Disclosure Date: January 17, 2022 (last updated February 23, 2025)
Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to hijack the authentication of administrators and conduct arbitrary operations via a specially crafted web page.