Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18839

18839 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-13950 OneSignal – Web Push Notifications <= 3.6.1 - Missing Authorization to Unauthenticated Plugin Settings Update — OneSignal – Web Push NotificationsCWE-862 5.3 Medium2025-12-15
CVE-2025-14156 Fox LMS – WordPress LMS Plugin 1.0.4.7 - 1.0.5.1 - Unauthenticated Privilege Escalation via 'createOrder' — Fox LMS – WordPress LMS PluginCWE-20 9.8 Critical2025-12-15
CVE-2025-14383 Booking Calendar <= 10.14.8 - Unauthenticated SQL Injection via dates_to_check — Booking CalendarCWE-89 7.5 High2025-12-15
CVE-2025-14709 Shiguangwu sgwbox N3 WIRELESSCFGGET http_eshell_server buffer overflow — sgwbox N3CWE-120 9.8 Critical2025-12-15
CVE-2025-11363 Royal Elementor Addons and Templates < 1.7.1037 - Unauthenticated Media File Upload — Royal Addons for Elementor 7.5AIHighAI2025-12-15
CVE-2025-14712 JHENG GAO|Student Learning Assessment and Support System - Exposure of Sensitive Information — Student Learning Assessment and Support SystemCWE-497 7.5 High2025-12-15
CVE-2025-65742 Newgen OmniDocs 安全漏洞 — n/a 9.8AICriticalAI2025-12-15
CVE-2025-65779 WeKan 安全漏洞 — n/a 8.6AIHighAI2025-12-15
CVE-2025-65835 PhoneGap / Cordova Social Sharing plugin 安全漏洞 — n/a 7.5AIHighAI2025-12-15
CVE-2025-12696 HelloLeads CRM Form Shortcode <= 1.0 - Unauthenticated Settings Reset — HelloLeads CRM Form Shortcode 5.3AIMediumAI2025-12-14
CVE-2025-13126 wpForo Forum <= 2.4.12 - Unauthenticated SQL Injection — wpForo ForumCWE-89 7.5 High2025-12-14
CVE-2025-10289 Filter & Grids <= 3.2.0 - Unauthenticated SQL Injection — YMC FilterCWE-89 5.9 Medium2025-12-13
CVE-2025-9207 TI WooCommerce Wishlist <= 2.10.0 - Unauthenticated HTML Injection — TI WooCommerce WishlistCWE-20 5.3 Medium2025-12-13
CVE-2025-10738 URL Shortener Plugin For WordPress <= 3.0.7 - Unauthenticated SQL Injection — URL Shortener Plugin For WordPressCWE-89 9.8 Critical2025-12-13
CVE-2025-12362 myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program <= 2.9.7 - Missing Authorization to Unauthenticated Withdrawal Request Approval — Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCredCWE-862 5.3 Medium2025-12-13
CVE-2025-11693 Export WP Page to Static HTML & PDF <= 4.3.4 - Unauthenticated Cookie Exposure via Log File — Export WordPress Pages to Static HTML & PDF — Static Site ExportCWE-200 9.8 Critical2025-12-13
CVE-2025-13092 Devs CRM – Manage tasks, attendance and teams all together <= 1.1.8 - Unauthenticated Information Expsoure — Devs CRM – Manage tasks, attendance and teams all togetherCWE-862 5.3 Medium2025-12-13
CVE-2025-14365 Eyewear prescription form <= 6.0.1 - Missing Authorization to Unauthenticated Arbitrary WooCommerce Category Deletion — Eyewear prescription formCWE-862 5.3 Medium2025-12-13
CVE-2025-14394 Popover Windows <= 1.2 - Cross-Site Request Forgery to Arbitrary Popover Configuration Update — Popover WindowsCWE-352 4.3 Medium2025-12-13
CVE-2025-11707 Login Lockdown & Protection <= 2.14 - IP Block Bypass — Login Lockdown & ProtectionCWE-330 5.3 Medium2025-12-13
CVE-2025-12077 WP to LinkedIn Auto Publish <= 1.9.8 - Reflected Cross-Site Scripting via PostMessage — WP to LinkedIn Auto PublishCWE-79 6.1 Medium2025-12-13
CVE-2025-14440 JAY Login & Register <= 2.4.01 - Authentication Bypass via Cookie — JAY Login & RegisterCWE-565 9.8 Critical2025-12-13
CVE-2025-14539 Shortcode Loader <= 1.0 - Unauthenticated Arbitrary Shortcode Execution via 'code' Parameter — Shortcode AjaxCWE-94 5.4 Medium2025-12-13
CVE-2025-12076 Social Media Auto Publish <= 3.6.5 - Reflected Cross-Site Scripting via PostMessage — Social Media Auto PublishCWE-79 6.1 Medium2025-12-13
CVE-2025-13077 افزونه پیامک ووکامرس فوق حرفه ای (جدید) payamito sms woocommerce <= 1.3.5 - Unauthenticated Time-Based Blind SQL Injection — افزونه پیامک ووکامرس فوق حرفه ای (جدید) payamito sms woocommerceCWE-89 7.5 High2025-12-13
CVE-2025-13093 Devs CRM – Manage tasks, attendance and teams all together <= 1.1.8 - Missing Authorization to Unauthenticated Lead Tag Update — Devs CRM – Manage tasks, attendance and teams all togetherCWE-862 5.3 Medium2025-12-13
CVE-2025-14451 Solutions Ad Manager <= 1.0.0 - Unauthenticated Open Redirect via 'sam-redirect-to' Parameter — Solutions Ad ManagerCWE-601 4.7 Medium2025-12-13
CVE-2025-9218 rtMedia for WordPress, BuddyPress and bbPress 4.7.0 - 4.7.3 - Missing Authorization to Unauthenticated Information Disclosure via handle_rest_pre_dispatch Function — rtMedia for WordPress, BuddyPress and bbPressCWE-862 3.7 Low2025-12-13
CVE-2025-14475 Extensive VC Addons for WPBakery page builder <= 1.9.1 - Unauthenticated Local File Inclusion via 'shortcode_name' Parameter — Extensive VC Addons for WPBakery page builderCWE-98 8.1 High2025-12-13
CVE-2025-14462 Lucky Draw Contests <= 4.2 - Cross-Site Request Forgery to Plugin Settings Update — Lucky Draw ContestsCWE-352 4.3 Medium2025-12-13

Vulnerabilities classified as access:pre-auth represent 18839 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.