Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18855

18855 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-13498 NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.8.1 - Unauthenticated Sensitive Information Exposure — NEX-Forms – Ultimate Forms Plugin for WordPressCWE-200 5.3 Medium2025-03-12
CVE-2025-2077 Simple Amazon Affiliate <= 1.0.9 - Reflected Cross-Site Scripting — Simple Amazon AffiliateCWE-79 6.1 Medium2025-03-12
CVE-2025-25683 AlekSIS-Core 安全漏洞 — n/a 5.3 -2025-03-12
CVE-2023-48790 Fortinet FortiNDR 跨站请求伪造漏洞 — FortiNDRCWE-352 7.1 High2025-03-11
CVE-2024-52285 Siemens SiPass Integrated 访问控制错误漏洞 — SiPass integrated AC5102 (ACC-G2)CWE-306 5.3 Medium2025-03-11
CVE-2024-13413 ProductDyno <= 1.0.24 - Reflected Cross-Site Scripting via 'res' Parameter — ProductDynoCWE-79 6.1 Medium2025-03-11
CVE-2024-13436 Appsero Helper <= 1.3.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Appsero HelperCWE-352 6.1 Medium2025-03-11
CVE-2025-2169 WPCS – WordPress Currency Switcher Professional <= 1.2.0.4 - Unauthenticated Arbitrary Shortcode Execution — WPCS – WordPress Currency Switcher ProfessionalCWE-94 7.3 High2025-03-11
CVE-2025-1661 HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion — HUSKY – Products Filter Professional for WooCommerceCWE-22 9.8 Critical2025-03-11
CVE-2025-27434 Cross-Site Scripting (XSS) vulnerability in SAP Commerce (Swagger UI) — SAP Commerce (Swagger UI)CWE-79 8.8 High2025-03-11
CVE-2024-11638 Gtbabel < 6.6.9 - Unauthenticated Admin Account Takeover — Gtbabel 8.1 -2025-03-10
CVE-2025-1926 Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.8 - Cross-Site Request Forgery (CSRF) To Post Contents Modification — Page Builder: Pagelayer – Drag and Drop website builderCWE-352 4.3 Medium2025-03-10
CVE-2024-43107 Gallagher Milestone Integration Plugin 信任管理问题漏洞 — Milestone Integration PluginCWE-295 7.2 High2025-03-10
CVE-2024-13924 Starter Templates by FancyWP <= 2.0.0 - Unauthenticated Blind Server-Side Request Forgery — Starter Templates by FancyWPCWE-918 5.3 Medium2025-03-08
CVE-2024-11640 VikRentCar Car Rental Management System <= 1.4.2 - Cross-Site Request Forgery to Authenticated (Subscriber+) Arbitrary File Upload — VikRentCar Car Rental Management SystemCWE-352 8.8 High2025-03-08
CVE-2025-1322 WP-Recall – Registration, Profile, Commerce & More <= 16.26.10 - Authenticated (Contributor+) Protected Post Disclosure — WP-Recall – Registration, Profile, Commerce & MoreCWE-200 4.3 Medium2025-03-08
CVE-2025-1323 WP-Recall – Registration, Profile, Commerce & More <= 16.26.10 - Unauthenticated SQL Injection — WP-Recall – Registration, Profile, Commerce & MoreCWE-89 7.5 High2025-03-08
CVE-2024-13359 Product Input Fields for WooCommerce <= 1.12.0 - Unauthenticated Limited File Upload — Product Input Fields for WooCommerceCWE-434 8.1 High2025-03-08
CVE-2025-0177 Javo Core <= 3.0.0.080 - Unauthenticated Privilege Escalation in ajax_signup — Javo CoreCWE-269 9.8 Critical2025-03-08
CVE-2024-11087 miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon <= 200.3.9 - Authentication Bypass — miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn)CWE-287 8.1 High2025-03-08
CVE-2024-13640 Print Invoice & Delivery Notes for WooCommerce <= 5.4.1 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory — Print Invoice & Delivery Notes for WooCommerceCWE-200 5.9 Medium2025-03-08
CVE-2024-13774 Wishlist for WooCommerce: Multi Wishlists Per Customer <= 3.1.7 - Cross-Site Request Forgery to Cross-Site Scriping via Wishlist Name — Wishlist for WooCommerce: Multi Wishlists Per CustomerCWE-352 6.1 Medium2025-03-08
CVE-2024-12634 Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins <= 2.0.59 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPluginsCWE-352 6.1 Medium2025-03-07
CVE-2024-13552 SupportCandy – Helpdesk & Customer Support Ticket System <= 3.3.0 - Insecure Direct Object Reference — SupportCandy – Helpdesk & Customer Support Ticket SystemCWE-285 4.3 Medium2025-03-07
CVE-2024-12876 Golo - Directory & Listing, Travel WordPress Theme <= 1.6.10 - Missing Authorization to Privilege Escalation via Unauthenticated Arbitrary User Password Change — Golo - City Travel Guide WordPress ThemeCWE-862 9.8 Critical2025-03-07
CVE-2024-13431 Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.8.3 - Reflected Cross-Site Scripting — Appointment Booking Calendar — Simply Schedule Appointments Booking PluginCWE-79 6.1 Medium2025-03-07
CVE-2025-1315 InWave Jobs <= 3.5.1 - Unauthenticated Privilege Escalation via Password Reset — InWave JobsCWE-288 9.8 Critical2025-03-07
CVE-2024-12610 School Management System for Wordpress <= 93.0.0 - Missing Authorization to Unauthenticated Arbitrary Post Deletion — School Management System for WordpressCWE-862 5.3 Medium2025-03-07
CVE-2024-13904 Platform.ly for WooCommerce <= 1.1.6 - Unauthenticated Blind Server-Side Request Forgery — Platform.ly for WooCommerceCWE-918 5.3 Medium2025-03-07
CVE-2024-10804 Ultimate Video Player <= 10.0 - Unauthenticated Arbitrary File Download — Ultimate Video Player WordPress & WooCommerce PluginCWE-22 7.5 High2025-03-07

Vulnerabilities classified as access:pre-auth represent 18855 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.