Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18829

18829 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2026-1657 EventPrime <= 4.2.8.4 - Missing Authorization to Unauthenticated Image Upload via 'ep_upload_file_media' AJAX Endpoint — EventPrime – Events Calendar, Bookings and TicketsCWE-862 5.3 Medium2026-02-17
CVE-2026-2592 Zarinpal Gateway for WooCommerce <= 5.0.16 - Improper Access Control to Payment Status Update — Zarinpal GatewayCWE-284 7.7 High2026-02-17
CVE-2026-26220 LightLLM <= 1.1.0 PD Mode Unsafe Deserialization RCE — LightLLMCWE-502 9.8AICriticalAI2026-02-17
CVE-2019-25393 Smoothwall Express 3.1 'smoothinfo.cgi' Cross-Site Scripting — Smoothwall ExpressCWE-79 6.1 Medium2026-02-16
CVE-2019-25392 Smoothwall Express 3.1 'iptools.cgi' Cross-Site Scripting — Smoothwall ExpressCWE-79 6.1 Medium2026-02-16
CVE-2019-25389 Smoothwall Express 3.1 'timedaccess.cgi' Cross-Site Scripting — Smoothwall ExpressCWE-79 6.1 Medium2026-02-16
CVE-2019-25388 Smoothwall Express 3.1 'ipblock.cgi' Cross-Site Scripting — Smoothwall ExpressCWE-79 6.1 Medium2026-02-16
CVE-2019-25387 Smoothwall Express 3.1 'xtaccess.cgi' Cross-Site Scripting — Smoothwall ExpressCWE-79 6.1 Medium2026-02-16
CVE-2019-25382 Smoothwall Express 3.1 'time.cgi' Cross-Site Scripting — Smoothwall ExpressCWE-79 6.1 Medium2026-02-16
CVE-2026-2577 Nanobot Unauthenticated WhatsApp Session Hijack via WebSocket Bridge — nanobotCWE-306 10.0 Critical2026-02-16
CVE-2026-2537 Comfast CF-E4 HTTP POST Request mbox-config command injection — CF-E4CWE-77 4.7 Medium2026-02-16
CVE-2026-2533 Tosei Self-service Washing Machine tosei_datasend.php command injection — Self-service Washing MachineCWE-77 7.3 High2026-02-16
CVE-2026-26366 JUNG eNet SMART HOME server 2.2.1/2.3.1 Use of Default Credentials — eNet SMART HOME serverCWE-1392 9.8 Critical2026-02-15
CVE-2019-25375 OPNsense 19.1 Reflected XSS via monit interface — OPNsenseCWE-79 6.1 Medium2026-02-15
CVE-2019-25376 OPNsense 19.1 Reflected XSS via proxy endpoint — OPNsenseCWE-79 6.1 Medium2026-02-15
CVE-2019-25371 OPNsense 19.1 Reflected XSS via diag_ping.php — OPNsenseCWE-79 6.1 Medium2026-02-15
CVE-2019-25372 OPNsense 19.1 Reflected XSS via diag_traceroute.php — OPNsenseCWE-79 6.1 Medium2026-02-15
CVE-2026-1490 Spam protection, Honeypot, Anti-Spam by CleanTalk <= 6.71 - Authorization Bypass via Reverse DNS (PTR record) Spoofing to Unauthenticated Arbitrary Plugin Installation — Spam protection, Honeypot, Anti-Spam by CleanTalkCWE-350 9.8 Critical2026-02-15
CVE-2025-8572 Truelysell Core <= 1.8.7 - Unauthenticated Privilege Escalation via Registration — Truelysell CoreCWE-269 9.8 Critical2026-02-14
CVE-2026-1843 Super Page Cache <= 5.2.2 - Unauthenticated Stored Cross-Site Scripting via Activity Log — Super Page CacheCWE-79 7.2 High2026-02-14
CVE-2026-0753 Super Simple Contact Form <= 1.6.2 - Reflected Cross-Site Scripting via 'sscf_name' Parameter — Super Simple Contact FormCWE-79 7.2 High2026-02-14
CVE-2026-1306 midi-Synth <= 1.1.0 - Unauthenticated Arbitrary File Upload via 'export' AJAX Action — midi-SynthCWE-434 9.8 Critical2026-02-14
CVE-2026-1394 WP Quick Contact Us <= 1.0 - Cross-Site Request Forgery to Settings Update — WP Quick Contact UsCWE-352 4.3 Medium2026-02-14
CVE-2026-1944 CallbackKiller service widget <= 1.2 - Missing Authorization to Unauthenticated Arbitrary Plugin Settings Update — CallbackKiller service widgetCWE-862 5.3 Medium2026-02-14
CVE-2025-14852 MDirector Newsletter <= 4.5.8 - Cross-Site Request Forgery to Plugin Settings Update — MDirector Newsletter WordPress PluginCWE-352 4.3 Medium2026-02-14
CVE-2026-2024 PhotoStack Gallery <= 0.4.1 - Unauthenticated SQL Injection via 'postid' Parameter — PhotoStack GalleryCWE-89 7.5 High2026-02-14
CVE-2026-1795 Address Bar Ads <= 1.0.0 - Reflected Cross-Site Scripting — Address Bar AdsCWE-79 6.1 Medium2026-02-14
CVE-2026-1792 Geo Widet <= 1.0 - Reflected Cross-Site Scripting — Geo WidgetCWE-79 6.1 Medium2026-02-14
CVE-2025-14873 LatePoint – Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Cross-Site Request Forgery — LatePoint – Calendar Booking Plugin for Appointments and EventsCWE-352 4.3 Medium2026-02-14
CVE-2025-6792 One to one user Chat by WPGuppy <= 1.1.4 - Unauthenticated Information Disclosure via Chat Message Interception — One to one user Chat by WPGuppyCWE-306 5.3 Medium2026-02-14

Vulnerabilities classified as access:pre-auth represent 18829 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.