Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18872

18872 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-12417 Simple Link Directory <= 8.4.5 - Unauthenticated Arbitrary Shortcode Execution — Simple Link DirectoryCWE-94 6.5 Medium2024-12-13
CVE-2024-12414 Themify Store Locator <= 1.1.9 - Cross-Site Request Forgery — Themify Store LocatorCWE-352 4.3 Medium2024-12-13
CVE-2024-12420 WPMobile.App — Android and iOS Mobile Application <= 11.52 - Unauthenticated Arbitrary Shortcode Execution — WPMobile.AppCWE-94 6.5 Medium2024-12-13
CVE-2024-12421 Coupon Affiliates – Affiliate Plugin for WooCommerce <= 5.16.7.1 - Unauthenticated Arbitrary Shortcode Execution and Reflected Cross-Site Scripting — Coupon Affiliates – Affiliate Plugin for WooCommerceCWE-94 6.5 Medium2024-12-13
CVE-2024-11809 Primer MyData for Woocommerce <= 4.2.1 - Reflected Cross-Site Scripting — Primer MyData for WoocommerceCWE-79 6.1 Medium2024-12-13
CVE-2024-12574 SVG Shortcode <= 1.0.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload — SVG ShortcodeCWE-79 5.4 Medium2024-12-13
CVE-2024-12579 Minify HTML <= 2.1.10 - - Regular Expressions Denial of Service — Minify HTMLCWE-400 5.3 Medium2024-12-13
CVE-2024-12300 AR for WordPress <= 7.3 - Missing Authorization to Unauthenticated Limited File Upload — AR for WordPressCWE-862 3.7 Low2024-12-13
CVE-2024-12572 Hello in All Languages <= 1.0.6 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Hello In All LanguagesCWE-352 6.1 Medium2024-12-13
CVE-2019-25221 Responsive Filterable Portfolio <=1.0.8 - Authenticated (Admin+) SQL Injection — Responsive Filterable PortfolioCWE-89 6.5 Medium2024-12-13
CVE-2024-55956 Cleo多款产品 安全漏洞 — n/a 9.8 -2024-12-13
CVE-2024-28145 Unauthenticated SQL Injection — Scan2NetCWE-89 9.8 -2024-12-12
CVE-2024-12160 Seraphinite Bulk Discounts for WooCommerce <= 2.4.6 - Reflected Cross-Site Scripting — Seraphinite Bulk Discounts for WooCommerceCWE-79 6.1 Medium2024-12-12
CVE-2024-12333 WoodMart <= 8.0.3 - Unauthenticated Arbitrary Shortcode Execution — WoodmartCWE-94 6.5 Medium2024-12-12
CVE-2024-12312 Print Science Designer <= 1.3.152 - Unauthenticated PHP Object Injection — Print Science DesignerCWE-502 8.1 High2024-12-12
CVE-2024-11052 Ninja Forms – The Contact Form Builder That Grows With You <= 3.8.19 - Unauthenticated Stored Cross-Site Scripting via Form Calculations — Ninja Forms – The Contact Form Builder That Grows With YouCWE-79 7.2 High2024-12-12
CVE-2024-12265 Web3 Cryptocurrency Payments by DePay for WooCommerce <= 2.12.17 - Missing Authorization to Information Exposure — Web3 Crypto Payments by DePay for WooCommerceCWE-862 5.3 Medium2024-12-12
CVE-2024-10124 Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce <= 1.1.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation — Vayu Blocks – Website Builder for the Block EditorCWE-284 9.8 Critical2024-12-12
CVE-2024-12255 Accept Stripe Payments Using Contact Form 7 <= 2.5 - Unauthenticated Information Exposure — Accept Stripe Payments Using Contact Form 7CWE-200 5.3 Medium2024-12-12
CVE-2024-12072 Analytics Cat – Google Analytics Made Easy <= 1.1.2 - Reflected Cross-Site Scripting — Analytics Cat – Google Analytics Made EasyCWE-79 6.1 Medium2024-12-12
CVE-2024-11359 Library Bookshelves <= 5.8 - Reflected Cross-Site Scripting — Library BookshelvesCWE-79 6.1 Medium2024-12-12
CVE-2024-12526 Arena.IM – Live Blogging for real-time events <= 0.4.1 - Cross-Site Request Forgery to Settings Update — Arena.IM – Live Blogging for real-time eventsCWE-352 4.3 Medium2024-12-12
CVE-2024-12156 AI Content Writer, RSS Feed to Post, Autoblogging SEO Help <= 6.1.3 - Reflected Cross-Site Scripting — QC SEO Help for llms.txt, AI Analytics, AI Content Writer, Subtitle to ArticleCWE-79 6.1 Medium2024-12-12
CVE-2024-12441 BP Email Assign Templates <= 1.5 - Reflected Cross-Site Scripting — BP Email Assign TemplatesCWE-79 6.1 Medium2024-12-12
CVE-2024-11459 Country Blocker <= 3.2 - Reflected Cross-Site Scripting — Country BlockerCWE-79 6.1 Medium2024-12-12
CVE-2024-11804 Planaday API <= 11.4 - Reflected Cross-Site Scripting — Planaday APICWE-79 6.1 Medium2024-12-12
CVE-2024-12162 Video & Photo Gallery for Ultimate Member <= 1.1.1 - Reflected Cross-Site Scripting — Video & Photo Gallery for Ultimate MemberCWE-79 6.1 Medium2024-12-12
CVE-2024-10910 Grid Plus – Unlimited grid layout <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via grid_plus_load_by_category — Grid Plus – Unlimited grid layoutCWE-94 7.3 High2024-12-12
CVE-2024-11723 kvCORE IDX <= 2.3.35 - Reflected Cross-Site Scripting — kvCORE IDXCWE-79 6.1 Medium2024-12-12
CVE-2024-11683 Newsletter Subscriptions <= 2.1 - Reflected Cross-Site Scripting — Newsletter SubscriptionsCWE-79 6.1 Medium2024-12-12

Vulnerabilities classified as access:pre-auth represent 18872 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.