Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18867

18867 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-21623 ClipBucket V5 Unauthenticated Template Directory Update to Denial-of-Service — clipbucket-v5CWE-22 7.5 High2025-01-07
CVE-2024-12738 User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.12.9 - Unauthenticated Stored Cross-Site Scripting — User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role EditorCWE-79 6.1 Medium2025-01-07
CVE-2024-12711 RSVP and Event Management <= 2.7.13 - Missing Authorization — RSVP and Event ManagementCWE-862 5.3 Medium2025-01-07
CVE-2024-12316 Jupiter X Core <= 4.8.5 - Missing Authorization to Unauthenticated Popup Template Export — Jupiter X CoreCWE-862 5.3 Medium2025-01-07
CVE-2024-12152 MIPL WC Multisite Sync <= 1.1.5 - Unauthenticated Arbitrary File Download — MIPL Multistore Sync for WooCommerce. Sync Products, Stock and Orders.CWE-22 7.5 High2025-01-07
CVE-2024-12077 Booking Calendar and Booking Calendar Pro <= Multiple Versions - Reflected Cross-Site Scripting via 'calendar_id' — Booking calendar, Appointment Booking SystemCWE-79 6.1 Medium2025-01-07
CVE-2024-10866 Export Import Menus <= 1.9.1 - Missing Authorization to Unauthenticated Menu Export — Export Import MenusCWE-862 5.3 Medium2025-01-07
CVE-2024-9354 Estatik Mortgage Calculator <= 2.0.11 - Reflected Cross-Site Scripting — Estatik Mortgage CalculatorCWE-79 6.1 Medium2025-01-07
CVE-2024-11282 Passster – Password Protect Pages and Content <= 4.2.10 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure — Passster – Password Protect Pages and ContentCWE-200 5.3 Medium2025-01-07
CVE-2024-12384 Binary MLM Woocommerce <= 2.0 - Reflected Cross-Site Scripting via 'page' — Binary MLM For WooCommerceCWE-79 6.1 Medium2025-01-07
CVE-2024-12383 Binary MLM Woocommerce <= 2.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Binary MLM For WooCommerceCWE-352 6.1 Medium2025-01-07
CVE-2024-12438 WooCommerce Digital Content Delivery (incl. DRM) – FlickRocket <= 4.75 - Reflected Cross-Site Scripting — Digital Content Delivery (incl. DRM) by Flickrocket for WooCommerceCWE-79 6.1 Medium2025-01-07
CVE-2024-12633 JoomSport <= 5.6.17 - Reflected Cross-Site Scripting via page — JoomSport – for Sports: Team & League, Football, Hockey & moreCWE-79 7.1 High2025-01-07
CVE-2024-12535 Host PHP Info <= 1.0.4 - Missing Authorization to Unauthenticated Sensitive Information Disclosure — Host PHP InfoCWE-862 8.6 High2025-01-07
CVE-2024-12261 SmartEmailing.cz <= 2.2.0 - Reflected Cross-Site Scripting — SmartEmailingCWE-79 6.1 Medium2025-01-07
CVE-2024-12849 Error Log Viewer By WP Guru <= 1.0.1.3 - Missing Authorization to Unauthenticated Arbitrary File Read — Error Log Viewer By WP GuruCWE-22 7.5 High2025-01-07
CVE-2024-11369 Store credit / Gift cards for woocommerce <= 1.0.49.46 - Reflected Cross-Site Scripting — Store credit / Gift cards for woocommerceCWE-79 6.1 Medium2025-01-07
CVE-2024-12324 Unilevel MLM Plan <= 1.1.0 - Reflected Cross-Site Scripting via 'page' — Unilevel MLM PlanCWE-79 6.1 Medium2025-01-07
CVE-2024-12435 Compare Products for WooCommerce <= 3.2.1 - Reflected Cross-Site Scripting — Compare Products for WooCommerceCWE-79 6.1 Medium2025-01-07
CVE-2024-11810 PayGreen Payment Gateway <= 1.0.26 - Reflected Cross-Site Scripting — PayGreen Payment GatewayCWE-79 6.1 Medium2025-01-07
CVE-2024-12322 ThePerfectWedding.nl Widget <= 2.8 - Cross-Site Request Forgery to Stored Cross-Site Scripting — ThePerfectWedding.nl WidgetCWE-352 8.8 High2025-01-07
CVE-2024-12470 School Management System – SakolaWP <= 1.0.8 - Unauthenticated Privilege Escalation — School Management System – SakolaWPCWE-266 9.8 Critical2025-01-07
CVE-2024-9208 Enable Accessibility <= 1.4.1 - Reflected Cross-Site Scripting — Enable AccessibilityCWE-79 6.1 Medium2025-01-07
CVE-2024-12159 Optimize Your Campaigns – Google Shopping – Google Ads – Google Adwords <= 3.1 - Information Exposure — Optimize Your Campaigns – Google Shopping – Google Ads – Google AdwordsCWE-200 5.3 Medium2025-01-07
CVE-2024-12176 WordLift – AI powered SEO – Schema <= 3.54.2 - Missing Authorization to Authenticated (Subscriber+) Settings Update — WordLift – AI powered SEO – SchemaCWE-862 5.3 Medium2025-01-07
CVE-2024-12256 Simple Video Management System <= 1.0.4 - Reflected Cross-Site Scripting — Simple Video Management SystemCWE-79 6.1 Medium2025-01-07
CVE-2024-11290 Member Access <= 1.1.6 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure — Member AccessCWE-200 5.3 Medium2025-01-07
CVE-2024-12264 PayU CommercePro Plugin <= 3.8.3 - Unauthenticated Privilege Escalation — PayU CommercePro PluginCWE-287 9.8 Critical2025-01-07
CVE-2024-11377 Automate Hub Free by Sperse.IO <= 1.7.0 - Reflected Cross-Site Scripting — Automate Hub Free by Sperse.IOCWE-79 6.1 Medium2025-01-07
CVE-2024-12158 Popup – MailChimp, GetResponse and ActiveCampaign Intergrations <= 3.2.6 - Missing Authorization to Unauthenticated DB Table Truncation — Popup – MailChimp, GetResponse and ActiveCampaign IntergrationsCWE-862 5.3 Medium2025-01-07

Vulnerabilities classified as access:pre-auth represent 18867 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.