Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18866

18866 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-13720 WP Image Uploader <= 1.0.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Deletion — WP Image UploaderCWE-352 8.8 High2025-01-30
CVE-2024-12409 Simple:Press Forum <= 6.10.11 - Reflected Cross-Site Scripting — Simple:Press ForumCWE-79 6.1 Medium2025-01-30
CVE-2024-13453 Contact Form & SMTP Plugin for WordPress by PirateForms <= 2.6.0 - Unauthenticated Arbitrary Shortcode Execution — Contact Form & SMTP Plugin for WordPress by PirateFormsCWE-94 7.3 High2025-01-30
CVE-2024-13706 WP Image Uploader <= 1.0.1 - Reflected Cross-Site Scripting — WP Image UploaderCWE-79 6.1 Medium2025-01-30
CVE-2025-0860 VR-Frases (collect & share quotes) <= 3.0.1 - Reflected Cross-Site Scripting — VR-FrasesCWE-79 6.1 Medium2025-01-30
CVE-2025-0861 VR-Frases (collect & share quotes) <= 3.0.1 - Authenticated (Admin+) SQL Injection — VR-FrasesCWE-89 4.9 Medium2025-01-30
CVE-2024-13694 WooCommerce Wishlist <= 1.8.7 - Unauthenticated Wishlist Disclosure via download_pdf_file Function — MoreConvert Wishlist for WooCommerceCWE-285 7.5 High2025-01-30
CVE-2024-13758 CP Contact Form with PayPal <= 1.3.52 - Cross-Site Request Forgery — CP Contact Form with PayPalCWE-352 6.5 Medium2025-01-30
CVE-2024-13457 Event Tickets <= 5.18.1 - Insecure Direct Object Reference to Sensitive Information Exposure — Event Tickets and RegistrationCWE-284 5.3 Medium2025-01-30
CVE-2024-13696 Flexible Wishlist for WooCommerce <= 1.2.25 - Unauthenticated Stored Cross-Site Scripting via wishlist_name Parameter — Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for laterCWE-79 7.2 High2025-01-29
CVE-2024-54852 Teedy 安全漏洞 — n/a 9.8 -2025-01-29
CVE-2025-24481 FactoryTalk® View Site Edition - Incorrect Permission Assignment — FactoryTalk® View Site EditionCWE-732 9.8 -2025-01-28
CVE-2025-22217 VMware Avi Load Balancer 安全漏洞 — VMware AVI Load BalancerCWE-89 8.6 High2025-01-28
CVE-2024-13521 MailUp Auto Subscription <= 1.1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting — MailUp Auto SubscriptionCWE-352 6.1 Medium2025-01-28
CVE-2024-13448 ThemeREX Addons <= 2.32.3 - Unauthenticated Arbitrary File Upload in trx_addons_uploads_save_data — ThemeREX AddonsCWE-434 9.8 Critical2025-01-28
CVE-2024-13509 WS Form LITE and PRO <= 1.10.13 - Unauthenticated Stored Cross-Site Scripting — WS Form LITE – Drag & Drop Contact Form BuilderCWE-79 7.2 High2025-01-28
CVE-2024-11135 Eventer <= 3.9.8 - Unauthenticated SQL Injection via eventer_get_attendees — Eventer - WordPress Event & Booking Manager PluginCWE-89 7.5 High2025-01-28
CVE-2024-57376 D-Link多款产品 安全漏洞 — n/a 9.8 -2025-01-28
CVE-2024-54542 Apple iOS 安全漏洞 — Safari 7.5 -2025-01-27
CVE-2024-54488 Apple iOS和iPadOS 安全漏洞 — iOS and iPadOS 7.5 -2025-01-27
CVE-2025-24814 Apache Solr: Core-creation with "trusted" configset can use arbitrary untrusted files — Apache SolrCWE-250 9.8 -2025-01-27
CVE-2024-13117 Social Share Buttons for WordPress <= 2.7 - Unauthenticated Image Upload & Path Traversal — Social Share Buttons for WordPress 5.3 -2025-01-27
CVE-2024-56316 Axiros AXESS ACS 安全漏洞 — n/a 7.5 -2025-01-27
CVE-2024-11641 VikBooking Hotel Booking Engine & PMS <= 1.7.2 - Cross-Site Request Forgery to Authenticated (Subscriber+) Arbitrary File Upload — VikBooking Hotel Booking Engine & PMSCWE-352 8.8 High2025-01-26
CVE-2024-12334 WC Affiliate – A Complete WooCommerce Affiliate Plugin <= 2.4 - Reflected Cross-Site Scripting — WC Affiliate – WooCommerce Affiliate PluginCWE-79 6.1 Medium2025-01-26
CVE-2024-11090 Membership Plugin – Restrict Content <= 3.2.13 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure — Membership Plugin – Restrict ContentCWE-200 5.3 Medium2025-01-26
CVE-2024-10633 Quiz Maker Business, Developer, and Agency <= (Multiple Versions) - Unauthenticated Arbitrary Shortcode Execution via content — Quiz Maker DeveloperCWE-95 7.3 High2025-01-26
CVE-2024-10574 Quiz Maker Business, Developer, and Agency <= (Multiple Versions) - Missing Authorization to Google Sheets Integration Credentials Modification and Stored Cross-Site Scripting — Quiz Maker DeveloperCWE-862 7.2 High2025-01-26
CVE-2024-10628 Quiz Maker Business, Developer, and Agency <= (Multiple Versions) - Unauthenticated SQL Injection via id — Quiz Maker BusinessCWE-89 7.5 High2025-01-26
CVE-2024-10636 Quiz Maker Business, Developer, and Agency <= (Multiple Versions) - Reflected DOM-Based Cross-Site Scripting via content — Quiz Maker DeveloperCWE-79 6.1 Medium2025-01-26

Vulnerabilities classified as access:pre-auth represent 18866 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.