Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18834

18834 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-14348 weMail <= 2.0.7 - Insufficient Authorization via x-wemail-user Header to Sensitive Information Disclosure — weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerceCWE-285 5.3 Medium2026-01-20
CVE-2025-14798 LearnPress – WordPress LMS Plugin <= 4.3.2.4 - Missing Authorization to Unauthenticated Sensitive User Information Disclosure via REST API — LearnPress – WordPress LMS Plugin for Create and Sell Online CoursesCWE-862 5.3 Medium2026-01-20
CVE-2025-14351 Custom Fonts – Host Your Fonts Locally <= 2.1.16 - Missing Authorization to Unauthenticated Font Deletion — Custom Fonts – Host Your Fonts LocallyCWE-862 5.3 Medium2026-01-20
CVE-2026-1051 Newsletter – Send awesome emails from WordPress <= 9.1.0 - Cross-Site Request Forgery to Newsletter Unsubscription — Newsletter – Send awesome emails from WordPressCWE-352 4.3 Medium2026-01-20
CVE-2025-14978 PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net) <= 1.119.8 - Missing Authorization to Unauthenticated Order Status Modification — PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI)CWE-862 5.3 Medium2026-01-20
CVE-2026-23944 Arcane allows unauthenticated proxy access to remote environments — arcaneCWE-306 8.6AIHighAI2026-01-19
CVE-2026-23849 File Browser vulnerable to Username Enumeration via Timing Attack in /api/login — filebrowserCWE-208 5.3 Medium2026-01-19
CVE-2026-23848 MyTube has Rate Limiting Bypass via X-Forwarded-For Header Spoofing — MyTubeCWE-807 6.5 Medium2026-01-19
CVE-2026-23837 MyTube has an Authorization Bypass vulnerability — MyTubeCWE-863 9.8 Critical2026-01-19
CVE-2026-23838 Tandoor Recipes module allows SQLite database to be externally accessible with the default settings — nixpkgsCWE-538 7.5AIHighAI2026-01-19
CVE-2026-23833 ESPHome vulnerable to denial-of-service via out-of-bounds check bypass in the API component — esphomeCWE-190 8.6AIHighAI2026-01-19
CVE-2026-23646 OpenProject users can delete other user's session, causing them to be logged out — openprojectCWE-488 6.5 Medium2026-01-19
CVE-2026-22850 Koko Analytics vulnerable to arbitrary SQL execution through unescaped analytics export/import and permissive admin SQL import — koko-analyticsCWE-89 8.4 High2026-01-19
CVE-2025-11043 Improper Server Certificate Validation in Automation Studio — B&R Automation StudioCWE-295 7.4 High2026-01-19
CVE-2026-1119 itsourcecode Society Management System delete_activity.php sql injection — Society Management SystemCWE-89 7.3 High2026-01-18
CVE-2025-14078 PAYGENT for WooCommerce <= 2.4.6 - Missing Authorization to Unauthenticated Payment Callback Manipulation — PAYGENT for WooCommerceCWE-862 5.3 Medium2026-01-17
CVE-2025-10484 Registration & Login with Mobile Phone Number for WooCommerce <= 1.3.1 - Authentication Bypass — Registration & Login with Mobile Phone Number for WooCommerceCWE-288 9.8 Critical2026-01-17
CVE-2025-12129 CubeWP – All-in-One Dynamic Content Framework <= 1.1.27 - Unauthenticated Information Exposure — CubeWP FrameworkCWE-200 5.3 Medium2026-01-17
CVE-2026-0808 Spin Wheel <= 2.1.0 - Unauthenticated Client-Side Prize Manipulation via 'prize_index' Parameter — Spin Wheel – Interactive spinning wheel that offers couponsCWE-602 5.3 Medium2026-01-17
CVE-2025-12825 User Registration Using Contact Form 7 <= 2.5 - Authenticated (Subscriber+) Information Exposure — User Registration Using Contact Form 7CWE-862 5.3 Medium2026-01-17
CVE-2025-14029 Community Events <= 1.5.6 - Missing Authorization to Unauthenticated Arbitrary Event Approval via 'eventlist' Parameter — Community EventsCWE-862 5.3 Medium2026-01-17
CVE-2025-14463 Payment Button for PayPal <= 1.2.3.41 - Missing Authorization to Unauthenticated Arbitrary Order Creation — Payment Button for PayPalCWE-862 5.3 Medium2026-01-17
CVE-2025-12002 Feeds for YouTube Pro <= 2.6.0 - Unauthenticated Arbitrary File Read via Path Traversal — YouTube Feed ProCWE-22 5.9 Medium2026-01-17
CVE-2025-12718 Quick Contact Form <= 8.2.6 - Unauthenticated Open Mail Relay — Quick Contact FormCWE-20 5.8 Medium2026-01-17
CVE-2025-15403 RegistrationMagic <= 6.0.7.1 - Unauthenticated Privilege Escalation via admin_order — RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User LoginCWE-269 9.8 Critical2026-01-17
CVE-2025-14075 WP Hotel Booking <= 2.2.7 - Unauthenticated Sensitive Information Exposure via 'email' Parameter — WP Hotel BookingCWE-200 5.3 Medium2026-01-17
CVE-2019-25297 Poll, Survey & Quiz Maker Plugin by Opinion Stage < 19.6.25 Stored XSS — Poll, Survey & Quiz Maker Plugin by Opinion StageCWE-79 6.1 -2026-01-16
CVE-2012-10064 Omni Secure Files < 0.1.14 Unauthenticated Arbitrary File Upload — Omni Secure FilesCWE-434 9.8 -2026-01-16
CVE-2026-23722 WeGIA has a Reflected Cross-Site Scripting (XSS) vulnerability allowing arbitrary code execution and UI redressing. — WeGIACWE-79 9.1 Critical2026-01-16
CVE-2025-14844 Membership Plugin – Restrict Content <= 3.2.16 - Missing Authentication to Insecure Direct Object Reference and Sensitive Information Exposure — Membership Plugin – Restrict ContentCWE-639 8.2 High2026-01-16

Vulnerabilities classified as access:pre-auth represent 18834 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.