Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18866

18866 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-11133 Eventer <= 3.9.9.5 - Missing Authorization to Unauthenticated Event Ticket Download — Eventer - WordPress Event & Booking Manager PluginCWE-862 5.3 Medium2025-02-03
CVE-2024-13371 WP Job Portal <= 2.2.6 - Missing Authorization to Unauthenticated Arbitrary Email Sending — WP Job Portal – AI-Powered Recruitment System for Company or Job Board websiteCWE-862 5.3 Medium2025-02-01
CVE-2024-13372 WP Job Portal <= 2.2.6 - Insecure Direct Object Reference to Unauthenticated Arbitrary Resume Download — WP Job Portal – AI-Powered Recruitment System for Company or Job Board websiteCWE-639 5.3 Medium2025-02-01
CVE-2024-13428 WP Job Portal <= 2.2.6 - Insecure Direct Object Reference to Unauthenticated Company Logo Deletion — WP Job Portal – AI-Powered Recruitment System for Company or Job Board websiteCWE-639 5.3 Medium2025-02-01
CVE-2024-12041 Directorist – AI-Powered WordPress Business Directory Plugin with Classified Ads Listings <= 8.0.12 - Unauthenticated User Information Exposure — Directorist: AI-Powered Business Directory, Listings & Classified AdsCWE-359 5.3 Medium2025-02-01
CVE-2024-12184 WordPress Contact Forms by Cimatti <= 1.9.4 - Missing Authorization to Unauthenticated Form Submission Download — Contact Forms by CimattiCWE-862 5.3 Medium2025-02-01
CVE-2024-12620 AnimateGL Animations for WordPress – Elementor & Gutenberg Blocks Animations <= 1.4.23 - Missing Authorization to Unauthenticated Settings Update — AnimateGL Animations for WordPress – Elementor & Gutenberg Blocks AnimationsCWE-862 5.3 Medium2025-02-01
CVE-2024-12415 AI Infographic Maker <= 4.9.0 - Unauthenticated Arbitrary Shortcode Execution — AI Infographic MakerCWE-94 6.5 Medium2025-01-31
CVE-2024-12267 Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.8.5 - Limited Arbitrary File Deletion — Drag and Drop Multiple File Upload for Contact Form 7CWE-73 5.3 Medium2025-01-31
CVE-2024-13472 WooCommerce Product Table Lite <= 3.9.4 - Unauthenticated Arbitrary Shortcode Execution & Reflected Cross-Site Scripting — Product Table and List Builder for WooCommerce LiteCWE-94 7.3 High2025-01-31
CVE-2024-13623 Order Export for WooCommerce <= 3.24 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory — Order Export for WooCommerceCWE-200 5.9 Medium2025-01-31
CVE-2024-13504 Shared Files – Frontend File Upload Form & Secure File Sharing <= 1.7.42 - Limited Unauthenticated Stored Cross-Site Scripting via File Upload — Shared Files – Frontend File Upload Form & Secure File SharingCWE-79 7.2 High2025-01-31
CVE-2025-0809 Link Fixer <= 3.4 - Unauthenticated Stored Cross-Site Scripting — Link FixerCWE-79 7.2 High2025-01-31
CVE-2025-0493 MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.14 - Unauthenticated Limited Local File Inclusion — MultiVendorX – WooCommerce Multivendor Marketplace SolutionsCWE-22 9.8 Critical2025-01-31
CVE-2025-0470 Forminator <= 1.38.2 - Reflected Cross-Site Scripting via Title Parameter — Forminator Forms – Contact Form, Payment Form & Custom Form BuilderCWE-79 6.1 Medium2025-01-31
CVE-2024-55062 EasyVirt DC Scope和EasyVirt CO2 Scope 安全漏洞 — n/a 9.8 -2025-01-31
CVE-2024-57587 EasyVirt DC Scope和EasyVirt CO2 Scope 安全漏洞 — n/a 9.8 -2025-01-31
CVE-2025-24502 Broadcom Symantec Privileged Access Management 安全漏洞 — Symantec Privileged Access Management 8.2 -2025-01-30
CVE-2025-24501 Broadcom Symantec Privileged Access Management 安全漏洞 — Symantec Privileged Access ManagementCWE-20 5.3 -2025-01-30
CVE-2025-24500 Broadcom Symantec Privileged Access Management 安全漏洞 — Symantec Privileged Access Management 7.5 -2025-01-30
CVE-2024-12299 System Dashboard <= 2.8.17 - Reflected Cross-Site Scripting via Filename Parameter — System DashboardCWE-79 6.1 Medium2025-01-30
CVE-2024-12822 Media Manager for UserPro <= 3.12.0 - Missing Authorization to Unauthenticated Arbitrary Options Update — Media Manager for UserProCWE-862 9.8 Critical2025-01-30
CVE-2024-12177 Ai Image Alt Text Generator for WP <= 1.0.6 - Reflected Cross-Site Scripting — Ai Image Alt Text Generator for WPCWE-79 6.1 Medium2025-01-30
CVE-2024-12320 Team Rosters <= 4.7 - Reflected Cross-Site Scripting via 'tab' — Team RostersCWE-79 6.1 Medium2025-01-30
CVE-2024-13707 WP Image Uploader <= 1.0.1 - Cross-Site Request Forgery to Arbitrary File Deletion — WP Image UploaderCWE-352 8.8 High2025-01-30
CVE-2024-13742 iControlWP – Multiple WordPress Site Manager <= 4.4.5 - Unauthenticated PHP Object Injection — iControlWPCWE-502 9.8 Critical2025-01-30
CVE-2024-12269 Safe Ai Malware Protection for WP <= 1.0.17 - Missing Authorization to Unauthenticated Database Export — Safe Ai Malware Protection for WPCWE-862 7.5 High2025-01-30
CVE-2024-13671 Music Sheet Viewer <= 4.1 - Unauthenticated Arbitrary File Read — Music Sheet ViewerCWE-22 7.5 High2025-01-30
CVE-2024-13705 StageShow <= 9.8.6 - Reflected Cross-Site Scripting — StageShowCWE-79 6.1 Medium2025-01-30
CVE-2024-13512 Wonder FontAwesome <= 0.8 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Wonder FontAwesomeCWE-352 6.1 Medium2025-01-30

Vulnerabilities classified as access:pre-auth represent 18866 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.