Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18839

18839 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-10487 Advanced Ads <= 2.0.12 - Unauthenticated Limited Code Execution — Advanced Ads – Ad Manager & AdSenseCWE-94 7.3 High2025-11-01
CVE-2025-11499 Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent <= 1.1.32 - Unauthenticated Arbitrary File Upload — Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, FluentCWE-434 9.8 Critical2025-11-01
CVE-2025-11995 Community Events <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting — Community EventsCWE-79 7.2 High2025-11-01
CVE-2025-11833 Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing Authorization to Account Takeover via Unauthenticated Email Log Disclosure — Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile AppCWE-862 9.8 Critical2025-11-01
CVE-2025-11174 Document Library Lite <= 1.1.6 - Missing Authorization to Sensitive Information Exposure — Document Library LiteCWE-285 5.3 Medium2025-11-01
CVE-2025-11816 Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages <= 3.5.1 - Missing Authorization to Unauthenticated API Disconnect — Privacy Policy Generator – WPLP Legal PagesCWE-862 5.3 Medium2025-11-01
CVE-2025-12521 Analytify Pro <= 7.0.3 - Unauthenticated Information Exposure — Analytify ProCWE-200 5.3 Medium2025-10-31
CVE-2025-12115 WPC Name Your Price for WooCommerce <= 2.1.9 - Unauthenticated Price Alteration — WPC Name Your Price for WooCommerceCWE-602 7.5 High2025-10-31
CVE-2025-12041 ERI File Library <= 1.1.0 - Missing Authorization to Unauthenticated Protected File Download — ERI File LibraryCWE-862 5.3 Medium2025-10-31
CVE-2025-8383 Depicter <= 4.0.4 - Cross-Site Request Forgery — Depicter — Popup & Slider BuilderCWE-352 4.3 Medium2025-10-31
CVE-2025-12094 OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA) <= 1.2.53 - Unauthenticated IP Header Spoofing — OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA)CWE-693 5.3 Medium2025-10-31
CVE-2025-10897 WooCommerce Designer Pro <= 1.9.28 - Unauthenticated Arbitrary File Read — WooCommerce Designer ProCWE-22 8.6 High2025-10-31
CVE-2025-5397 Jobmonster - Job Board WordPress Theme <= 4.8.1 - Authentication Bypass — Noo JobMonsterCWE-288 9.8 Critical2025-10-31
CVE-2025-8489 King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor 24.12.92 - 51.1.14 - Unauthenticated Privilege Escalation — King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for ElementorCWE-269 9.8 Critical2025-10-31
CVE-2025-58152 Century Systems FutureNet MA-X series 安全漏洞 — FutureNet MA-X seriesCWE-552 5.3 Medium2025-10-31
CVE-2025-11975 FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) <= 1.1.23.0 - Missing Authorization to Authenticated (Subscriber+) Sync Rule Creation — FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.)CWE-862 4.3 Medium2025-10-31
CVE-2020-36862 Nagios XI < 5.6.11 Unauthenticated XSS and SSRF via Highcharts — XICWE-79 6.1AIMediumAI2025-10-30
CVE-2024-14006 Nagios XI < 2024R1.2.2 Host Header Injection — XICWE-346 5.4AIMediumAI2025-10-30
CVE-2025-36592 Dell Secure Connect Gateway Policy Manager 跨站脚本漏洞 — Secure Connect Gateway SCG Policy ManagerCWE-79 5.4 Medium2025-10-30
CVE-2025-53880 susemanager-tftpsync-recv allows arbitrary file creation and deletion due to path traversal — Container suse/manager/4.3/proxy-httpd:latestCWE-35 6.5AIMediumAI2025-10-30
CVE-2025-11881 AppPresser – Mobile App Framework <= 4.5.0 - Missing Authorization to Unauthenticated Limited Sensitive Information Exposure — AppPresser – Mobile App FrameworkCWE-862 5.3 Medium2025-10-30
CVE-2025-10008 Translate WordPress and go Multilingual – Weglot <= 5.1 - Missing Authorization to Unauthenticated Limited Transient Deletion — Translate WordPress with Weglot – Multilingual AI TranslationCWE-862 5.3 Medium2025-10-30
CVE-2025-11627 Site Checkup AI Troubleshooting with Wizard and Tips for Each Issue <= 1.47 - Unauthenticated Log File Poisoning — Site Checkup Debug AI Troubleshooting with Wizard and Tips for Each IssueCWE-117 6.5 Medium2025-10-30
CVE-2025-52179 Zucchetti Ad Hoc Revolution 安全漏洞 — n/a 6.1AIMediumAI2025-10-30
CVE-2025-52180 Zucchetti Ad Hoc Infinity 安全漏洞 — n/a 6.1AIMediumAI2025-10-30
CVE-2025-61959 Vertikal Systems Hospital Manager Backend Services Generation of Error Message Containing Sensitive Information — Hospital Manager Backend ServicesCWE-209 5.3 Medium2025-10-29
CVE-2025-54459 Vertikal Systems Hospital Manager Backend Services Exposure of Sensitive System Information to an Unauthorized Control Sphere — Hospital Manager Backend ServicesCWE-497 7.5 High2025-10-29
CVE-2018-25120 D-Link DNS-343 ShareCenter <= 1.05 Command Injection via /goform/Mail_Test — DNS-343 ShareCenterCWE-78 9.8AICriticalAI2025-10-29
CVE-2025-12450 LiteSpeed Cache <= 7.5.0.1 - Reflected Cross-Site Scripting — LiteSpeed CacheCWE-79 6.1 Medium2025-10-29
CVE-2023-7320 WooCommerce <= 7.8.2 - Sensitive Information Exposure — WooCommerceCWE-200 5.3 Medium2025-10-29

Vulnerabilities classified as access:pre-auth represent 18839 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.