Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18829

18829 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2026-26338 Hyland Alfresco Transformation Service SSRF — Alfresco Transformation Service (Enterprise)CWE-918 9.8 Critical2026-02-19
CVE-2026-26337 Hyland Alfresco Transformation Service Absolute Path Traversal Arbitrary File Read and SSRF — Alfresco Transformation Service (Enterprise)CWE-36 8.2 High2026-02-19
CVE-2026-2232 Product Table and List Builder for WooCommerce Lite <= 4.6.2 - Unauthenticated Time-Based SQL Injection via 'search' Parameter — Product Table and List Builder for WooCommerce LiteCWE-89 7.5 High2026-02-19
CVE-2026-1581 wpForo Forum <= 2.4.14 - Unauthenticated Time-Based SQL Injection — wpForo ForumCWE-89 7.5 High2026-02-19
CVE-2026-26336 Hyland Alfresco Improper Authorization Arbitrary File Read — Alfresco EnterpriseCWE-863 7.5 High2026-02-19
CVE-2026-25766 Echo has a Windows path traversal via backslash in middleware.Static default filesystem — echoCWE-22 5.3 Medium2026-02-19
CVE-2026-25738 Indico has Server-Side Request Forgery (SSRF) in multiple places — indicoCWE-367 7.5AIHighAI2026-02-19
CVE-2026-25527 changedetection.io vulnerable to unauthenticated static path traversal — changedetection.ioCWE-22 5.3 Medium2026-02-19
CVE-2019-25430 Comodo Dome Firewall 2.7.0 Reflected Cross-Site Scripting via vpn_users — Comodo Dome FirewallCWE-79 6.1 Medium2026-02-19
CVE-2019-25414 Comodo Dome Firewall 2.7.0 Reflected Cross-Site Scripting via ID Parameter Appid — Comodo Dome FirewallCWE-79 6.1 Medium2026-02-19
CVE-2019-25413 Comodo Dome Firewall 2.7.0 Reflected Cross-Site Scripting via ID Parameter — Comodo Dome FirewallCWE-79 6.1 Medium2026-02-19
CVE-2019-25402 Comodo Dome Firewall 2.7.0 Cross-Site Scripting via login — Comodo Dome FirewallCWE-79 6.1 Medium2026-02-19
CVE-2025-15563 Broken Access Control results in Denial of Service in NesterSoft WorkTime — WorkTime (on-prem/cloud)CWE-862 5.3AIMediumAI2026-02-19
CVE-2025-15559 Unauthenticated OS Command Injection in NesterSoft WorkTime — WorkTime (on-prem/cloud)CWE-78 9.8AICriticalAI2026-02-19
CVE-2026-1219 MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar 4.0 - 5.10 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Exposure — MP3 Audio Player – Music Player, Podcast Player & Radio by SonaarCWE-639 5.3 Medium2026-02-19
CVE-2026-1461 Simple Membership <= 4.7.0 - Unauthenticated Improper Handling of Missing Values — Simple MembershipCWE-230 6.5 Medium2026-02-19
CVE-2026-1994 s2Member <= 260127 - Unauthenticated Privilege Escalation via Account Takeover — s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access SubscriptionsCWE-269 9.8 Critical2026-02-19
CVE-2026-2731 Unauthenticated RCE in Dynamicweb 9 and Dynamicweb 8 — DynamicWeb 9CWE-22 9.1AICriticalAI2026-02-19
CVE-2026-0722 Shield Security <= 21.0.8 - Cross-Site Request Forgery to SQL Injection — Shield: Blocks Bots, Protects Users, and Prevents Security BreachesCWE-89 6.5 Medium2026-02-19
CVE-2025-13851 Buyent Theme (with Buyent Classified Plugin) <= 1.0.7 - Unauthenticated Privilege Escalation via User Registration — BuyentCWE-269 9.8 Critical2026-02-19
CVE-2026-1455 Whatsiplus Scheduled Notification for Woocommerce <= 1.0.1 - Cross-Site Request Forgery to 'wsnfw_save_users_settings' AJAX Action — Whatsiplus Scheduled Notification for WoocommerceCWE-352 4.3 Medium2026-02-19
CVE-2026-0926 Prodigy Commerce <= 3.3.0 - Unauthenticated Local File Inclusion via parameters[template_name] — Prodigy CommerceCWE-98 9.8 Critical2026-02-19
CVE-2026-0561 Shield Security <= 21.0.8 - Unauthenticated Reflected Cross-Site Scripting via 'message' Parameter — Shield: Blocks Bots, Protects Users, and Prevents Security BreachesCWE-79 6.1 Medium2026-02-19
CVE-2025-14452 WP Customer Reviews <= 3.7.5 - Reflected Cross-Site Scripting via 'wpcr3_fname' Parameter — WP Customer ReviewsCWE-79 7.2 High2026-02-19
CVE-2025-14167 Remove Post Type Slug <= 1.0.2 - Cross-Site Request Forgery to Settings Update — Remove Post Type SlugCWE-352 4.3 Medium2026-02-19
CVE-2025-13563 Lizza LMS Pro <= 1.0.3 - Unauthenticated Privilege Escalation — Lizza LMS ProCWE-269 9.8 Critical2026-02-19
CVE-2025-14076 iXML – Google XML sitemap generator <= 0.6 - Reflected Cross-Site Scripting via 'iXML_email' Parameter — iXML – Google XML sitemap generatorCWE-79 6.1 Medium2026-02-19
CVE-2025-13438 Page Title, Description & Open Graph Updater <= 1.02 - Cross-Site Request Forgery to Arbitrary Page Title Modification — Page Title, Description & Open Graph UpdaterCWE-352 4.3 Medium2026-02-19
CVE-2025-13842 Breadcrumb NavXT <= 7.5.0 - Missing Authorization to Sensitive Information Exposure — Breadcrumb NavXTCWE-639 5.3 Medium2026-02-19
CVE-2025-13864 Breeze – WordPress Cache Plugin <= 2.2.21 - Missing Authorization to Cache Deletion — Breeze CacheCWE-862 5.3 Medium2026-02-19

Vulnerabilities classified as access:pre-auth represent 18829 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.