Show filters
952 Total Results
Displaying 51-60 of 952
Sort by:
Attacker Value
Unknown
CVE-2021-24696
Disclosure Date: January 24, 2022 (last updated February 23, 2025)
The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerability (fixed in 3.9.6), 2) delete logs (fixed in 3.9.9), 3) remove thumbnail image from downloads
0
Attacker Value
Unknown
CVE-2021-46028
Disclosure Date: January 20, 2022 (last updated February 23, 2025)
In mblog <= 3.5.0 there is a CSRF vulnerability in the background article management. The attacker constructs a CSRF load. Once the administrator clicks a malicious link, the article will be deleted.
0
Attacker Value
Unknown
CVE-2021-46027
Disclosure Date: January 19, 2022 (last updated February 23, 2025)
mysiteforme, as of 19-12-2022, has a CSRF vulnerability in the background blog management. The attacker constructs a CSRF load. Once the administrator clicks a malicious link, a blog tag will be added
0
Attacker Value
Unknown
CVE-2022-0215
Disclosure Date: January 18, 2022 (last updated February 23, 2025)
The Login/Signup Popup, Waitlist Woocommerce ( Back in stock notifier ), and Side Cart Woocommerce (Ajax) WordPress plugins by XootiX are vulnerable to Cross-Site Request Forgery via the save_settings function found in the ~/includes/xoo-framework/admin/class-xoo-admin-settings.php file which makes it possible for attackers to update arbitrary options on a site that can be used to create an administrative user account and grant full privileged access to a compromised site. This affects versions <= 2.2 in Login/Signup Popup, versions <= 2.5.1 in Waitlist Woocommerce ( Back in stock notifier ), and versions <= 2.0 in Side Cart Woocommerce (Ajax).
0
Attacker Value
Unknown
CVE-2022-0154
Disclosure Date: January 18, 2022 (last updated February 23, 2025)
An issue has been discovered in GitLab affecting all versions starting from 7.7 before 14.4.5, all versions starting from 14.5.0 before 14.5.3, all versions starting from 14.6.0 before 14.6.2. GitLab was vulnerable to a Cross-Site Request Forgery attack that allows a malicious user to have their GitHub project imported on another GitLab user account.
0
Attacker Value
Unknown
CVE-2021-43353
Disclosure Date: January 18, 2022 (last updated February 23, 2025)
The Crisp Live Chat WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the crisp_plugin_settings_page function found in the ~/crisp.php file, which made it possible for attackers to inject arbitrary web scripts in versions up to, and including 0.31.
0
Attacker Value
Unknown
CVE-2022-0245
Disclosure Date: January 18, 2022 (last updated February 23, 2025)
Cross-Site Request Forgery (CSRF) in GitHub repository livehelperchat/livehelperchat prior to 2.0.
0
Attacker Value
Unknown
CVE-2021-4164
Disclosure Date: January 17, 2022 (last updated February 23, 2025)
calibre-web is vulnerable to Cross-Site Request Forgery (CSRF)
0
Attacker Value
Unknown
CVE-2021-25025
Disclosure Date: January 17, 2022 (last updated February 23, 2025)
The EventCalendar WordPress plugin before 1.1.51 does not have proper authorisation and CSRF checks in the add_calendar_event AJAX actions, allowing users with a role as low as subscriber to create events
0
Attacker Value
Unknown
CVE-2022-0180
Disclosure Date: January 17, 2022 (last updated February 23, 2025)
Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to hijack the authentication of administrators and conduct arbitrary operations via a specially crafted web page.
0