Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18857

18857 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-1262 Advanced Google reCaptcha <= 1.27 - Built-in Math CAPTCHA Bypass — Advanced Google reCAPTCHACWE-804 5.3 Medium2025-02-25
CVE-2024-13693 Enfold <= 6.0.9 - Missing Authorization to Sensitive Information Disclosure in avia-export-class.php — Enfold - Responsive Multi-Purpose ThemeCWE-284 5.3 Medium2025-02-25
CVE-2024-13494 WordPress File Upload <= 4.25.2 - Cross-Site Request Forgery in wfu_file_details — Iptanus File UploadCWE-352 4.3 Medium2025-02-25
CVE-2025-1063 Classified Listing – Classified ads & Business Directory Plugin <= 4.0.4 - Unauthenticated Settings Exposure — Classified Listing – AI-Powered Classified ads & Business Directory PluginCWE-200 5.3 Medium2025-02-25
CVE-2025-1128 Everest Forms <= 3.0.9.4 - Unauthenticated Arbitrary File Upload, Read, and Deletion — Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form BuilderCWE-434 9.8 Critical2025-02-25
CVE-2025-1648 Yawave <= 2.9.1 - Unauthenticated SQL Injection — YawaveCWE-89 7.5 High2025-02-25
CVE-2025-1488 WPO365 | MICROSOFT 365 GRAPH MAILER <= 3.2 - Open Redirect via 'redirect_to' Parameter — WPO365 | MICROSOFT 365 GRAPH MAILERCWE-601 4.7 Medium2025-02-24
CVE-2025-26201 GreaterWMS 安全漏洞 — n/a 9.8 -2025-02-24
CVE-2024-13728 Accept Donations with PayPal & Stripe <= 1.4.4 - Reflected Cross-Site Scripting — Accept Donations with PayPal & StripeCWE-79 6.1 Medium2025-02-23
CVE-2025-0957 Vulnerability: SMTP for Amazon SES <= 1.8 - Unauthenticated Stored Cross-Site Scripting via Email Logs — SMTP for Amazon SES – YaySMTPCWE-79 7.2 High2025-02-22
CVE-2025-0953 SMTP for Sendinblue – YaySMTP <= 1.2 - Unauthenticated Stored Cross-Site Scripting via Email Logs — SMTP for Sendinblue – YaySMTPCWE-79 7.2 High2025-02-22
CVE-2025-0918 SMTP for SendGrid – YaySMTP <= 1.4 - Unauthenticated Stored Cross-Site Scripting via Email Logs — SMTP for SendGrid – YaySMTPCWE-79 7.2 High2025-02-22
CVE-2025-1361 IP2Location Country Blocker <= 2.38.8 - Missing Authorization to Unauthenticated Information Exposure via admin_init Function — IP2Location Country BlockerCWE-285 7.5 High2025-02-22
CVE-2024-12467 Pago por Redsys <= 1.0.12 - Reflected Cross-Site Scripting — Pago por RedsysCWE-79 6.1 Medium2025-02-22
CVE-2024-13474 LTL Freight Quotes – Purolator Edition <= 2.2.3 - Unauthenticated SQL Injection — LTL Freight Quotes – Purolator EditionCWE-89 7.5 High2025-02-22
CVE-2024-13798 Post Grid and Gutenberg Blocks – ComboBlocks <= 2.3.5 - Unauthenticated Paid Order Creation — Post GridCWE-20 5.3 Medium2025-02-22
CVE-2025-1509 Show Me The Cookies <= 1.0 - Unauthenticated Arbitrary Shortcode Execution — Show Me The CookiesCWE-94 7.3 High2025-02-22
CVE-2025-1510 Custom Post Type Date Archives <= 2.7.1 - Missing Authorization to Unauthenticated Arbitrary Shortcode Execution — Custom Post Type Date ArchivesCWE-94 7.3 High2025-02-22
CVE-2019-8900 SecureROM 安全漏洞 — SecureROM 6.4 -2025-02-21
CVE-2024-11260 Events Manager – Calendar, Bookings, Tickets, and more! <= 6.6.3 - Unauthenticated SQL Injection via Event Status Parameter — Events Manager – Calendar, Bookings, Tickets, and more!CWE-89 7.5 High2025-02-21
CVE-2024-13537 C9 Blocks <= 1.7.7 - Unauthenticated Full Path Disclosure — C9 BlocksCWE-209 5.3 Medium2025-02-21
CVE-2024-13818 Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction <= 3.8.4 - Sensitive Information Exposure via Log Files — Pie Register – User Registration, Profiles & Content RestrictionCWE-532 5.3 Medium2025-02-21
CVE-2024-13883 WPUpper Share Buttons <= 3.51 - Cross-Site Request Forgery to Custom CSS Update — WPUpper Share ButtonsCWE-352 4.3 Medium2025-02-21
CVE-2025-27091 OpenH264 Decoding Functions Heap Overflow Vulnerability — openh264CWE-122 6.8 -2025-02-20
CVE-2025-1039 Lenix Elementor Leads addon <= 1.8.2 - Unauthenticated Stored Cross-Site Scripting via URL Form Field — Lenix Leads CollectorCWE-79 7.2 High2025-02-20
CVE-2024-13792 WooCommerce Food - Restaurant Menu & Food ordering <= 3.3.2 - Unauthenticated Arbitrary Shortcode Execution via ids — WooCommerce Food - Restaurant Menu & Food orderingCWE-94 7.3 High2025-02-20
CVE-2024-13476 LTL Freight Quotes – GlobalTranz Edition <= 2.3.11 - Unauthenticated SQL Injection — LTL Freight Quotes – GlobalTranz EditionCWE-89 7.5 High2025-02-20
CVE-2024-13753 Ultimate Classified Listings <= 1.5 - Cross-Site Request Forgery to Account Takeover — Ultimate Classified ListingsCWE-352 8.1 High2025-02-20
CVE-2024-13789 Ravpage <= 2.31 - PHP Object Injection — ravpageCWE-502 9.8 Critical2025-02-20
CVE-2024-13520 Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) <= 4.4.9 - Missing Authorization to Unauthenticated Price, Date, and Note Updates — Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported)CWE-862 5.3 Medium2025-02-20

Vulnerabilities classified as access:pre-auth represent 18857 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.