CVE-2022-36095

CVSS v3 Score
4.3
Medium

Vulnerability Description

XWiki Platform is a generic wiki platform. Prior to versions 13.10.5 and 14.3, it is possible to perform a Cross-Site Request Forgery (CSRF) attack for adding or removing tags on XWiki pages. The problem has been patched in XWiki 13.10.5 and 14.3. As a workaround, one may locally modify the `documentTags.vm` template in one's filesystem, to apply the changes exposed there.

CVSS:4.3(Medium)

Cross-site request forgery (CSRF) vulnerability in Invision Gallery before 1.3.1 allows remote attackers to delete albums and images as another user via a link or IMG tag to the (1) albums or (2) deli...

CVSS:4.3(Medium)

The feature-comments plugin before 1.2.5 for WordPress has CSRF for featuring or burying a comment.

CVSS:4.3(Medium)

JBoss KeyCloak is vulnerable to soft token deletion via CSRF

CVSS:4.3(Medium)

The WP-Stats WordPress plugin before 2.52 does not have CSRF check when saving its settings, and did not escape some of them when outputting them, allowing attacker to make logged in high privilege us...

CVSS:4.3(Medium)

The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validation on the circle_thumbnail...

CVSS:4.3(Medium)

The Watu Pro plugin before 4.9.0.8 for WordPress has CSRF that allows an attacker to delete quizzes.