Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18839

18839 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-14855 SureForms <= 2.2.0 - Unauthenticated Stored Cross-Site Scripting — SureForms – Contact Form, Payment Form & Other Custom Form BuilderCWE-79 7.2 High2025-12-21
CVE-2025-13361 Web to SugarCRM Lead <= 1.0.0 - Cross-Site Request Forgery to Custom Field Deletion — Web to SugarCRM LeadCWE-352 4.3 Medium2025-12-21
CVE-2025-12398 Product Table for WooCommerce <= 5.0.8 - Reflected Cross-Site Scripting — Product Table for WooCommerceCWE-79 6.1 Medium2025-12-21
CVE-2025-9343 ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.4 - Unauthenticated Stored Cross-Site Scripting — ELEX WordPress HelpDesk & Customer Ticketing SystemCWE-79 7.2 High2025-12-21
CVE-2025-12980 Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX <= 5.0.3 - Missing Authorization to Unauthenticated Sensitive Information Exposure — Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostXCWE-862 7.5 High2025-12-21
CVE-2025-14043 Tainacan <= 1.0.1 - Missing Authorization to Unauthenticated Arbitrary Metadata Section Creation — TainacanCWE-862 5.3 Medium2025-12-21
CVE-2025-14080 Frontend Post Submission Manager Lite <= 1.2.5 - Missing Authorization to Unauthenticated Arbitrary Post Modification — Frontend Post Submission Manager Lite – Frontend Posting WordPress PluginCWE-862 5.3 Medium2025-12-21
CVE-2025-11496 Five Star Restaurant Reservations – WordPress Booking Plugin <= 2.7.5 - Unauthenticated Stored Cross-Site Scripting — Five Star Restaurant Reservations – WordPress Booking PluginCWE-79 6.1 Medium2025-12-21
CVE-2025-12492 Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.11.0 - Unauthenticated Sensitive Information Exposure — Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership PluginCWE-200 5.3 Medium2025-12-20
CVE-2025-13619 Flex Store Users <= 1.1.0 - Unauthenticated Privilege Escalation — Flex Store UsersCWE-269 9.8 Critical2025-12-20
CVE-2025-12581 Attachments Handler <= 1.1.7 - Reflected Cross-Site Scripting — Attachments HandlerCWE-79 6.1 Medium2025-12-20
CVE-2025-13365 WP Hallo Welt <= 1.4. - Cross-Site Request Forgery to Stored Cross-Site Scripting — WP Hallo WeltCWE-352 6.1 Medium2025-12-20
CVE-2025-13329 File Uploader for WooCommerce <= 1.0.3 - Unauthenticated Arbitrary File Upload via add-image-data — File Uploader for WooCommerceCWE-434 9.8 Critical2025-12-20
CVE-2025-13624 Overstock Affiliate Links <= 1.1 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] — Overstock Affiliate LinksCWE-79 6.1 Medium2025-12-20
CVE-2025-14168 WP DB Booster <= 1.0.1 - Cross-Site Request Forgery to Database Cleanup — WP DB BoosterCWE-352 4.3 Medium2025-12-20
CVE-2025-14633 F70 Lead Document Download <= 1.4.4 - Missing Authorization to Unauthenticated Arbitrary Media File Download — F70 Lead Document DownloadCWE-862 5.3 Medium2025-12-20
CVE-2025-12898 Pretty Google Calendar <= 2.0.0 - Missing Authorization to Unauthenticated Google API Key Exposure — Pretty Google CalendarCWE-862 5.3 Medium2025-12-20
CVE-2025-14164 Quran Gateway <= 1.5 - Cross-Site Request Forgery to Settings Update — Quran GatewayCWE-352 4.3 Medium2025-12-20
CVE-2025-14734 Amazon affiliate lite Plugin <= 1.0.0 - Cross-Site Request Forgery to Plugin Settings Update — Amazon affiliate lite PluginCWE-352 5.4 Medium2025-12-20
CVE-2025-14300 Unauthenticated Access to connectAP API Endpoint on Tapo C100 and C200 — Tapo C200 V3CWE-306 7.1AIHighAI2025-12-20
CVE-2025-14299 Improper Content-Length Validation in HTTPS Requests on Tapo C200 — Tapo C200 V3CWE-770 5.7AIMediumAI2025-12-20
CVE-2025-8065 Remote Code Execution via Stack-based Buffer Overflow in ONVIF SOAP Parser in TP-Link Tapo C200 and C520WS — Tapo C200 V3CWE-121 6.5AIMediumAI2025-12-20
CVE-2025-67712 HTML injection issue in ArcGIS Web App Builder — ArcGIS Web AppBuilder {Developer Edition)CWE-79 4.7 Medium2025-12-19
CVE-2023-30971 Gaia unauthenticated endpoints — com.palantir.acme.gaia:gaiaCWE-592 6.8 Medium2025-12-19
CVE-2025-34433 AVideo < 20.1 Unauthenticated RCE via Predictable Installation Salt — AVideoCWE-94 9.8AICriticalAI2025-12-19
CVE-2025-14847 Zlib compressed protocol header length confusion may allow memory read — MongoDB ServerCWE-130 7.5 High2025-12-19
CVE-2025-14151 SlimStat Analytics <= 5.3.2 - Unauthenticated Stored Cross-Site Scripting — SlimStat AnalyticsCWE-79 7.2 High2025-12-19
CVE-2025-13999 HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player 2.4.0 - 2.5.1 - Unauthenticated Server-Side Request Forgery — HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio PlayerCWE-918 7.2 High2025-12-19
CVE-2025-13754 Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.9.16 - Missing Authorization to Unauthenticated Sensitive Information Exposure — Appointment Booking Calendar — Simply Schedule Appointments Booking PluginCWE-862 5.3 Medium2025-12-19
CVE-2025-14910 Edimax BR-6208AC FTP Daemon Service handle_retr path traversal — BR-6208ACCWE-22 4.3 Medium2025-12-19

Vulnerabilities classified as access:pre-auth represent 18839 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.