Vulnerabilities (CVE)

Filtered by CWE-352
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-29050 1 Jenkins 1 Publish Over Ftp 2023-12-22 6.8 MEDIUM 8.8 HIGH
A cross-site request forgery (CSRF) vulnerability in Jenkins Publish Over FTP Plugin 1.16 and earlier allows attackers to connect to an FTP server using attacker-specified credentials.
CVE-2023-47787 1 Automattic 1 Woocommerce Bookings 2023-12-22 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce WooCommerce Bookings.This issue affects WooCommerce Bookings: from n/a through 2.0.3.
CVE-2023-47789 1 Automattic 1 Canada Post Shipping Method 2023-12-22 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce Canada Post Shipping Method.This issue affects Canada Post Shipping Method: from n/a through 2.8.3.
CVE-2023-49163 1 Mtrv 1 Teachpress 2023-12-22 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Michael Winkler teachPress.This issue affects teachPress: from n/a through 9.0.5.
CVE-2023-49164 1 Oceanwp 1 Ocean Extra 2023-12-22 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in OceanWP Ocean Extra.This issue affects Ocean Extra: from n/a through 2.2.2.
CVE-2023-48768 1 Codeastrology 1 Quantity Plus Minus Button For Woocommerce 2023-12-22 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in CodeAstrology Team Quantity Plus Minus Button for WooCommerce by CodeAstrology.This issue affects Quantity Plus Minus Button for WooCommerce by CodeAstrology: from n/a through 1.1.9.
CVE-2023-48772 1 Arulprasadj 1 Prevent Landscape Rotation 2023-12-22 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Arul Prasad J Prevent Landscape Rotation.This issue affects Prevent Landscape Rotation: from n/a through 2.0.
CVE-2023-48778 1 Villatheme 1 Product Size Chart For Woocommerce 2023-12-22 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in VillaTheme Product Size Chart For WooCommerce.This issue affects Product Size Chart For WooCommerce: from n/a through 1.1.5.
CVE-2023-48769 1 Bluecoral 1 Chat Bubble 2023-12-22 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Blue Coral Chat Bubble – Floating Chat with Contact Chat Icons, Messages, Telegram, Email, SMS, Call me back.This issue affects Chat Bubble – Floating Chat with Contact Chat Icons, Messages, Telegram, Email, SMS, Call me back: from n/a through 2.3.
CVE-2023-48773 1 Wpdoctor 1 Woocommerce Login Redirect 2023-12-22 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in WP Doctor WooCommerce Login Redirect.This issue affects WooCommerce Login Redirect: from n/a through 2.2.4.
CVE-2023-48781 1 Marketingrapel 1 Mkrapel Regiones Y Ciudades De Chile Para Wc 2023-12-22 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Marketing Rapel MkRapel Regiones y Ciudades de Chile para WC.This issue affects MkRapel Regiones y Ciudades de Chile para WC: from n/a through 4.3.0.
CVE-2023-49155 1 Wow-company 1 Button Generator 2023-12-21 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Button Generator – easily Button Builder.This issue affects Button Generator – easily Button Builder: from n/a through 2.3.8.
CVE-2023-6904 1 Nxfilter 1 Nxfilter 2023-12-21 N/A 8.8 HIGH
A vulnerability classified as problematic was found in Jahastech NxFilter 4.3.2.5. This vulnerability affects unknown code of the file /config,admin.jsp. The manipulation of the argument admin_name leads to cross-site request forgery. The attack can be initiated remotely. VDB-248266 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2023-5882 1 Soflyy 2 Export Any Wordpress Data To Xml\/csv, Wp All Export 2023-12-21 N/A 8.8 HIGH
The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not check nonce tokens early enough in the request lifecycle, allowing attackers to make logged in users perform unwanted actions leading to remote code execution.
CVE-2023-5886 1 Soflyy 2 Export Any Wordpress Data To Xml\/csv, Wp All Export 2023-12-21 N/A 8.8 HIGH
The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not check nonce tokens early enough in the request lifecycle, allowing attackers with the ability to upload files to make logged in users perform unwanted actions leading to PHAR deserialization, which may lead to remote code execution.
CVE-2023-47806 1 Saintsystems 1 Disable User Login 2023-12-21 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Saint Systems Disable User Login.This issue affects Disable User Login: from n/a through 1.3.7.
CVE-2023-33214 1 Taggbox 1 Taggbox 2023-12-21 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Tagbox Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics.This issue affects Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics: from n/a through 3.1.
CVE-2023-49749 1 Suretriggers 1 Suretriggers 2023-12-21 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in SureTriggers SureTriggers – Connect All Your Plugins, Apps, Tools & Automate Everything!.This issue affects SureTriggers – Connect All Your Plugins, Apps, Tools & Automate Everything!: from n/a through 1.0.23.
CVE-2023-49744 1 Giftup 1 Gift Up Gift Cards For Wordpress And Woocommerce 2023-12-21 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Gift Up Gift Up Gift Cards for WordPress and WooCommerce.This issue affects Gift Up Gift Cards for WordPress and WooCommerce: from n/a through 2.21.3.
CVE-2023-49197 1 Apasionados 1 Dofollow Case By Case 2023-12-21 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Apasionados, Apasionados del Marketing, NetConsulting DoFollow Case by Case.This issue affects DoFollow Case by Case: from n/a through 3.4.2.
CVE-2023-49760 1 Giannopouloskostas 1 Wpsoononlinepage 2023-12-21 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Giannopoulos Kostas WPsoonOnlinePage.This issue affects WPsoonOnlinePage: from n/a through 1.9.
CVE-2023-49759 1 Gvectors 1 Woodiscuz - Woocommerce Comments 2023-12-21 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team WooDiscuz – WooCommerce Comments.This issue affects WooDiscuz – WooCommerce Comments: from n/a through 2.3.0.
CVE-2023-49761 1 Gravitymaster 1 Product Enquiry For Woocommerce 2023-12-21 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Gravity Master Product Enquiry for WooCommerce.This issue affects Product Enquiry for WooCommerce: from n/a through 3.0.
CVE-2023-49763 1 Creatomatic 1 Csprite 2023-12-21 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Creatomatic Ltd CSprite.This issue affects CSprite: from n/a through 1.1.
CVE-2021-21665 1 Jenkins 1 Xebialabs Xl Deploy 2023-12-21 6.0 MEDIUM 8.8 HIGH
A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing Username/password credentials stored in Jenkins.
CVE-2020-2241 1 Jenkins 1 Database 2023-12-21 6.8 MEDIUM 8.8 HIGH
A cross-site request forgery (CSRF) vulnerability in Jenkins database Plugin 1.6 and earlier allows attackers to connect to an attacker-specified database server using attacker-specified credentials.
CVE-2022-28136 1 Jenkins 1 Jiratestresultreporter 2023-12-21 6.8 MEDIUM 8.8 HIGH
A cross-site request forgery (CSRF) vulnerability in Jenkins JiraTestResultReporter Plugin 165.v817928553942 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials.
CVE-2023-48755 1 Teachpress Project 1 Teachpress 2023-12-20 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Michael Winkler teachPress.This issue affects teachPress: from n/a through 9.0.4.
CVE-2023-49153 1 Codeastrology 1 Add To Cart Text Changer And Customize Button\, Add Custom Icon 2023-12-20 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Saiful Islam Add to Cart Text Changer and Customize Button, Add Custom Icon.This issue affects Add to Cart Text Changer and Customize Button, Add Custom Icon: from n/a through 2.0.
CVE-2023-49855 1 Binarycarpenter 1 Menu Bar Cart Icon For Woocommerce 2023-12-20 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in BinaryCarpenter Menu Bar Cart Icon For WooCommerce By Binary Carpenter.This issue affects Menu Bar Cart Icon For WooCommerce By Binary Carpenter: from n/a through 1.49.3.
CVE-2023-49854 1 Madebytribe 1 Caddy 2023-12-20 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Tribe Interactive Caddy – Smart Side Cart for WooCommerce.This issue affects Caddy – Smart Side Cart for WooCommerce: from n/a through 1.9.7.
CVE-2023-49844 1 Reviewsignal 1 Wpperformancetester 2023-12-20 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Kevin Ohashi WPPerformanceTester.This issue affects WPPerformanceTester: from n/a through 2.0.0.
CVE-2023-49843 1 Quanticedge 1 First Order Discount Woocommerce 2023-12-20 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in QuanticEdge First Order Discount Woocommerce.This issue affects First Order Discount Woocommerce: from n/a through 1.21.
CVE-2023-50372 1 Wpgogo 1 Custom Post Type Page Template 2023-12-20 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Hiroaki Miyashita Custom Post Type Page Template.This issue affects Custom Post Type Page Template: from n/a through 1.1.
CVE-2023-49840 1 Palscode 1 Multi Currency For Woocommerce 2023-12-20 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Palscode Multi Currency For WooCommerce.This issue affects Multi Currency For WooCommerce: from n/a through 1.5.5.
CVE-2023-49853 1 Paytr 1 Paytr Taksit Tablosu - Woocommerce 2023-12-20 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in PayTR Ödeme ve Elektronik Para Kurulu?u A.?. PayTR Taksit Tablosu – WooCommerce.This issue affects PayTR Taksit Tablosu – WooCommerce: from n/a through 1.3.1.
CVE-2023-49834 1 Pluginus 1 Fox - Currency Switcher Professional For Woocommerce 2023-12-20 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in realmag777 FOX – Currency Switcher Professional for WooCommerce.This issue affects FOX – Currency Switcher Professional for WooCommerce: from n/a through 1.4.1.4.
CVE-2023-24380 1 Webbjocke 1 Simple Wp Sitemap 2023-12-20 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Webbjocke Simple Wp Sitemap.This issue affects Simple Wp Sitemap: from n/a through 1.2.1.
CVE-2023-49824 1 Pixelyoursite 1 Product Catalog Feed 2023-12-20 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in PixelYourSite Product Catalog Feed by PixelYourSite.This issue affects Product Catalog Feed by PixelYourSite: from n/a through 2.1.1.
CVE-2023-49751 1 Getbutterfly 1 Block For Font Awesome 2023-12-20 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Ciprian Popescu Block for Font Awesome.This issue affects Block for Font Awesome: from n/a through 1.4.0.
CVE-2023-49775 1 Wpcore 1 Csv Importer 2023-12-20 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Denis Kobozev CSV Importer.This issue affects CSV Importer: from n/a through 0.3.8.
CVE-2023-49769 1 Softlabbd 1 Integrate Google Drive 2023-12-20 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.4.
CVE-2023-48766 1 Svgator 1 Svgator 2023-12-20 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in SVGator SVGator – Add Animated SVG Easily.This issue affects SVGator – Add Animated SVG Easily: from n/a through 1.2.4.
CVE-2023-48762 1 Crocoblock 1 Jetelements For Elementor 2023-12-20 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.
CVE-2023-46617 1 Wpfoxly 1 Adfoxly 2023-12-20 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in AdFoxly AdFoxly – Ad Manager, AdSense Ads & Ads.Txt.This issue affects AdFoxly – Ad Manager, AdSense Ads & Ads.Txt: from n/a through 1.8.5.
CVE-2023-49816 1 Whereyoursolutionis 1 Fix My Feed Rss Repair 2023-12-20 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in Innovative Solutions Fix My Feed RSS Repair.This issue affects Fix My Feed RSS Repair: from n/a through 1.4.
CVE-2023-50722 1 Xwiki 1 Xwiki 2023-12-19 N/A 8.8 HIGH
XWiki Platform is a generic wiki platform. Starting in 2.3 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, there is a reflected XSS or also direct remote code execution vulnerability in the code for displaying configurable admin sections. The code that can be passed through a URL parameter is only executed when the user who is visiting the crafted URL has edit right on at least one configuration section. While any user of the wiki could easily create such a section, this vulnerability doesn't require the attacker to have an account or any access on the wiki. It is sufficient to trick any admin user of the XWiki installation to visit the crafted URL. This vulnerability allows full remote code execution with programming rights and thus impacts the confidentiality, integrity and availability of the whole XWiki installation. This has been fixed in XWiki 14.10.15, 15.5.2 and 15.7RC1. The patch can be manually applied to the document `XWiki.ConfigurableClass`.
CVE-2022-27488 1 Fortinet 6 Fortiai, Fortimail, Fortindr and 3 more 2023-12-19 N/A 8.8 HIGH
A cross-site request forgery (CSRF) in Fortinet FortiVoiceEnterprise version 6.4.x, 6.0.x, FortiSwitch version 7.0.0 through 7.0.4, 6.4.0 through 6.4.10, 6.2.0 through 6.2.7, 6.0.x, FortiMail version 7.0.0 through 7.0.3, 6.4.0 through 6.4.6, 6.2.x, 6.0.x FortiRecorder version 6.4.0 through 6.4.2, 6.0.x, 2.7.x, 2.6.x, FortiNDR version 1.x.x allows a remote unauthenticated attacker to execute commands on the CLI via tricking an authenticated administrator to execute malicious GET requests.
CVE-2023-50870 1 Jetbrains 1 Teamcity 2023-12-19 N/A 8.8 HIGH
In JetBrains TeamCity before 2023.11.1 a CSRF on login was possible
CVE-2023-50017 1 Iteachyou 1 Dreamer Cms 2023-12-19 N/A 8.8 HIGH
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/database/backup