Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18834

18834 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-14173 Perfit WooCommerce <= 1.0.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Settings Deletion — Perfit WooCommerceCWE-862 5.3 Medium2026-01-14
CVE-2025-14846 SocialChamp with WordPress <= 1.3.5 - Cross-Site Request Forgery to Plugin Settings Update — Auto Post to Social Media from Social ChampCWE-352 4.3 Medium2026-01-14
CVE-2025-15376 Stopwords for comments <= 1.1 - Missing Authorization to Cross-Site Request Forgery — Stopwords for commentsCWE-352 4.3 Medium2026-01-14
CVE-2025-15513 Float Payment Gateway <= 1.1.9 - Improper Authorization to Unauthenticated Order Status Manipulation — Float Payment GatewayCWE-863 5.3 Medium2026-01-14
CVE-2025-15512 Aplazo Payment Gateway <= 1.4.3 - Missing Authorization to Unauthenticated Order Status Manipulation — Aplazo Payment GatewayCWE-862 5.3 Medium2026-01-14
CVE-2025-14770 Shipping Rate By Cities <= 2.0.0 - Unauthenticated SQL Injection via 'city' Parameter — Shipping Rate By CitiesCWE-89 7.5 High2026-01-14
CVE-2025-14502 News and Blog Designer Bundle <= 1.1 - Unauthenticated Local File Inclusion — News and Blog Designer BundleCWE-98 9.8 Critical2026-01-14
CVE-2025-15266 GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation <= 1.1.8 - Unauthenticated Stored Cross-Site Scripting — GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead GenerationCWE-79 7.2 High2026-01-14
CVE-2025-14464 PDF Resume Parser <= 1.0 - Unauthenticated Sensitive Information Disclosure in SMTP Credentials — PDF Resume ParserCWE-200 5.3 Medium2026-01-14
CVE-2025-14880 Netcash WooCommerce Payment Gateway <= 4.1.3 - Missing Authorization to Unauthenticated Order Status Modification — Netcash WooCommerce Payment GatewayCWE-862 5.3 Medium2026-01-14
CVE-2025-15378 AJS Footnotes <= 1.0 - Unauthenticated Stored Cross-Site Scripting — AJS FootnotesCWE-79 7.2 High2026-01-14
CVE-2025-15283 Name Directory <= 1.30.3 - Unauthenticated Stored Cross-Site Scripting via Multiple Parameters — Name DirectoryCWE-79 7.2 High2026-01-14
CVE-2025-15377 Sosh Share Buttons <= 1.1.0 - Cross-Site Request Forgery — Sosh Share ButtonsCWE-352 4.3 Medium2026-01-14
CVE-2025-14301 Integration Opvius AI for WooCommerce <= 1.3.0 - Unauthenticated Arbitrary File Deletion/Read via Path Traversal — Integration Opvius AI for WooCommerceCWE-22 9.8 Critical2026-01-14
CVE-2026-0717 LottieFiles – Lottie block for Gutenberg <= 3.0.0 - Unauthenticated Sensitive Information Exposure — LottieFilesCWE-200 5.3 Medium2026-01-14
CVE-2025-14389 WPBlogSyn <= 1.0 - Cross-Site Request Forgery to Arbitrary Remote Sync Configuration Update — WPBlogSynCWE-352 4.3 Medium2026-01-14
CVE-2025-14615 DASHBOARD BUILDER <= 1.5.7 - Cross-Site Request Forgery to SQL Injection — DASHBOARD BUILDER – WordPress plugin for Charts and GraphsCWE-352 7.1 High2026-01-14
CVE-2026-0594 List Site Contributors <= 1.1.8 - Reflected Cross-Site Scripting via alpha — List Site ContributorsCWE-79 6.1 Medium2026-01-14
CVE-2025-67833 Paessler PRTG Network Monitor 安全漏洞 — n/a 6.1AIMediumAI2026-01-14
CVE-2025-67834 Paessler PRTG Network Monitor 安全漏洞 — n/a 6.1AIMediumAI2026-01-14
CVE-2022-50893 VIAVIWEB Wallpaper Admin 1.0 - Code Execution via Image Upload — VIAVIWEB Wallpaper AdminCWE-434 9.8 Critical2026-01-13
CVE-2023-54341 Webgrind 1.1 - Reflected Cross-Site Scripting (XSS) via file Parameter — WebgrindCWE-79 6.1 Medium2026-01-13
CVE-2023-54339 Webgrind 1.1 - Remote Command Execution (RCE) via dataFile Parameter — WebgrindCWE-78 9.8 Critical2026-01-13
CVE-2023-54340 WorkOrder CMS 0.1.0 - SQL Injection — WorkOrder CMSCWE-89 8.2 High2026-01-13
CVE-2023-54330 Inbit Messenger 4.9.0 - Unauthenticated Remote SEH Overflow — Inbit MessengerCWE-121 9.8 Critical2026-01-13
CVE-2023-54329 Inbit Messenger 4.9.0 - Unauthenticated Remote Command Execution (RCE) — Inbit MessengerCWE-121 9.8 Critical2026-01-13
CVE-2022-50932 Kyocera Command Center RX ECOSYS M2035dn - Directory Traversal File Disclosure (Unauthenticated) — Kyocera Command Center RXCWE-22 7.5 High2026-01-13
CVE-2022-50926 WAGO 750-8212 PFC200 G2 2ETH RS Privilege Escalation — WAGO 750-8212 PFC200CWE-565 9.8 Critical2026-01-13
CVE-2022-50919 Tdarr 2.00.15 - Command Injection — TdarrCWE-78 9.8 Critical2026-01-13
CVE-2021-47749 YouPHPTube <= 7.8 - Directory Traversal — YouPHPTubeCWE-22 5.5 Medium2026-01-13

Vulnerabilities classified as access:pre-auth represent 18834 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.