Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18872

18872 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2024-9504 Booking calendar, Appointment Booking System <= 3.2.15 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload — Booking calendar, Appointment Booking SystemCWE-434 7.2 High2024-11-26
CVE-2024-10542 Spam protection, Anti-Spam, FireWall by CleanTalk <= 6.43.2 - Authorization Bypass via Reverse DNS Spoofing to Unauthenticated Arbitrary Plugin Installation — Spam protection, Honeypot, Anti-Spam by CleanTalkCWE-862 9.8 Critical2024-11-26
CVE-2024-10781 Spam protection, Anti-Spam, FireWall by CleanTalk <= 6.44 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Arbitrary Plugin Installation — Spam protection, Honeypot, Anti-Spam by CleanTalkCWE-703 8.1 High2024-11-26
CVE-2024-10570 Security & Malware scan by CleanTalk <= 2.145 - Authorization Bypass via Reverse DNS Spoofing to Unauthenticated SQL Injection — Login Security, FireWall, Malware removal by CleanTalkCWE-89 7.5 High2024-11-26
CVE-2024-11418 Additional Order Filters for WooCommerce <= 1.21 - Reflected Cross-Site Scripting — Additional Order Filters for WooCommerceCWE-79 6.1 Medium2024-11-26
CVE-2024-11342 Skt NURCaptcha <= 3.5.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting — Skt NURCaptchaCWE-352 6.1 Medium2024-11-26
CVE-2024-50672 Adapt Authoring Tool 安全漏洞 — n/a 9.8AICriticalAI2024-11-25
CVE-2024-11666 Unauthenticated Remote Command Injection in eCharge Salia PLCC — cph2_echarge_firmwareCWE-345 9.0 Critical2024-11-24
CVE-2024-11034 Request a Quote for WooCommerce and Elementor – Get a Quote Button – Product Enquiry Form Popup – Product Quotation <= 1.4 - Unauthenticated Arbitrary Shortcode Execution via fire_contact_form — Request a Quote for WooCommerce – Get a Quote ButtonCWE-94 7.3 High2024-11-23
CVE-2024-10519 Wishlist for WooCommerce: Multi Wishlists Per Customer PRO 3.0.8 - 3.1.2 - Reflected Cross-Site Scripting via wtab Parameter — Wishlist for WooCommerce: Multi Wishlists Per Customer PROCWE-79 6.1 Medium2024-11-23
CVE-2024-9659 School Management <= 91.5.0 - Unauthenticated Arbitrary File Upload — School Management System for WordpressCWE-434 9.8 Critical2024-11-23
CVE-2024-9511 FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider <= 2.2.82 - Unauthenticated PHP Object Injection — FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP ProviderCWE-502 9.8 Critical2024-11-23
CVE-2024-9942 WPGYM <= 67.1.0 - Unauthenticated Arbitrary File Upload — WPGYM - Wordpress Gym Management SystemCWE-434 9.8 Critical2024-11-23
CVE-2024-10803 MP3 Sticky Player <= 8.0 - Unauthenticated Arbitrary File Read/Download — MP3 Sticky PlayerCWE-22 7.5 High2024-11-23
CVE-2024-9635 Checkout with Cash App on WooCommerce <= 6.0.2 - Reflected Cross-Site Scripting — Checkout with Cash App on WooCommerceCWE-79 6.1 Medium2024-11-23
CVE-2024-11446 Chessgame Shizzle <= 1.3.0 - Reflected Cross-Site Scripting — Chessgame ShizzleCWE-79 6.1 Medium2024-11-23
CVE-2024-11330 Custom CSS, JS & PHP <= 2.3.0 - Reflected Cross-Site Scripting — Custom CSS, JS & PHPCWE-79 6.1 Medium2024-11-23
CVE-2024-11188 Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder <= 6.16.1.2 - Reflected Cross-Site Scripting via Custom HTML Form Parameter — Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form BuilderCWE-79 6.1 Medium2024-11-23
CVE-2024-11361 PDF Invoices & Packing Slips Generator for WooCommerce <= 2.2.1 - Reflected Cross-Site Scripting — PDF Invoices & Packing Slips Generator for WooCommerceCWE-79 6.1 Medium2024-11-23
CVE-2024-10880 JobBoardWP – Job Board Listings and Submissions <= 1.3.0 - Reflected Cross-Site Scripting — JobBoardWP – Job Board Listings and SubmissionsCWE-79 6.1 Medium2024-11-23
CVE-2024-11415 WP-Orphanage Extended <= 1.2 - Cross-Site Request Forgery to Orphan Account Privilege Escalation — WP-Orphanage ExtendedCWE-352 8.8 High2024-11-23
CVE-2024-10813 Product Table for WooCommerce by CodeAstrology (wooproducttable.com) <= 3.5.1 - Information Exposure — Product Table for WooCommerceCWE-862 5.3 Medium2024-11-23
CVE-2024-11362 Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net <= 1.112.0 - Reflected Cross-Site Scripting — PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI)CWE-79 6.1 Medium2024-11-23
CVE-2024-10961 Social Login <= 5.9.0 - Authentication Bypass via Disqus OAuth provider — Social LoginCWE-288 9.8 Critical2024-11-23
CVE-2024-10869 GuardGiant Brute Force Protection <= 2.2.6 - Reflected Cross-Site Scripting — WordPress Brute Force Protection – Stop Brute Force AttacksCWE-79 6.1 Medium2024-11-23
CVE-2024-11463 DeBounce Email Validator <= 5.6.5 - Reflected Cross-Site Scripting — DeBounce Email ValidatorCWE-79 6.1 Medium2024-11-23
CVE-2024-52034 mySCADA myPRO OS Command Injection — myPRO ManagerCWE-78 10.0 Critical2024-11-22
CVE-2024-47407 mySCADA myPRO OS Command Injection — myPRO ManagerCWE-78 10.0 Critical2024-11-22
CVE-2024-8806 Cohesive Networks VNS3 Command Injection Remote Code Execution Vulnerability — VNS3CWE-78 9.8 -2024-11-22
CVE-2024-8735 MailMunch – Grow your Email List <= 3.1.8 - Reflected Cross-Site Scripting — MailMunch – Grow your Email ListCWE-79 6.1 Medium2024-11-22

Vulnerabilities classified as access:pre-auth represent 18872 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.