Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18839

18839 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-14366 Eyewear prescription form <= 6.0.1 - Missing Authorization to Unauthenticated Arbitrary WooCommerce Product Creation — Eyewear prescription formCWE-862 5.3 Medium2025-12-13
CVE-2025-14454 Image Slider by Ays- Responsive Slider and Carousel <= 2.7.0 - Cross-Site Request Forgery to Arbitrary Slider Deletion — Image Slider by Ays- Responsive Slider and CarouselCWE-352 4.3 Medium2025-12-13
CVE-2025-13089 WP Directory Kit <= 1.4.7 - Unauthenticated SQL Injection — WP Directory KitCWE-89 7.5 High2025-12-13
CVE-2025-13970 OpenPLC_V3 Cross-Site Request Forgery — OpenPLC_V3CWE-352 8.0 High2025-12-13
CVE-2025-14611 Gladinet CentreStack and TrioFox Hard Coded AES Keys — CentreStack and TrioFox 9.8AICriticalAI2025-12-12
CVE-2025-36743 SolarEdge SE3680H - Exposed Debug interface — SE3680H 9.8AICriticalAI2025-12-12
CVE-2025-36744 SolarEdge SE3680H - Information Exposure during Bootloader Loop — SE3680H 7.5AIHighAI2025-12-12
CVE-2025-12407 Events Manager – Calendar, Bookings, Tickets, and more! <= 7.2.2.2 - Cross-Site Request Forgery to Location Deletion — Events Manager – Calendar, Bookings, Tickets, and more!CWE-352 4.3 Medium2025-12-12
CVE-2025-12408 Events Manager <= 7.2.2.2 - Unauthenticated Information Exposure — Events Manager – Calendar, Bookings, Tickets, and more!CWE-200 5.3 Medium2025-12-12
CVE-2025-14159 Secure Copy Content Protection and Content Locking <= 4.9.2 - Cross-Site Request Forgery to Data Export — Secure Copy Content Protection and Content LockingCWE-352 4.3 Medium2025-12-12
CVE-2025-14442 Secure Copy Content Protection and Content Locking <= 4.9.2 - Unauthenticated Sensitive Information Exposure via Exposed CSV Export File — Secure Copy Content Protection and Content LockingCWE-552 5.3 Medium2025-12-12
CVE-2025-12841 Bookit < 2.5.1 – Unauthenticated Settings Update — Bookit 7.5AIHighAI2025-12-12
CVE-2025-12348 Email Subscribers & Newsletters <= 5.9.10 - Missing Authentication to Unauthenticated Action Scheduler Task Execution — Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPressCWE-306 5.3 Medium2025-12-12
CVE-2025-14169 FunnelKit – Funnel Builder for WooCommerce Checkout <= 3.13.1.5 - Unauthenticated SQL Injection — FunnelKit – Funnel Builder for WooCommerce CheckoutCWE-89 7.5 High2025-12-12
CVE-2025-14049 VikRentItems Flexible Rental Management System <= 1.2.0 - Reflected Cross-Site Scripting via 'delto' Parameter — VikRentItems Flexible Rental Management SystemCWE-79 6.1 Medium2025-12-12
CVE-2025-67728 Fireshare Public Uploads feature is vulnerable to OS Command Injection (RCE) — fireshareCWE-77 9.8 Critical2025-12-12
CVE-2025-12655 Hippoo Mobile App for WooCommerce <= 1.7.1 - Missing Authorization to Unauthenticated Limited File Write — Hippoo Mobile App for WooCommerceCWE-862 5.3 Medium2025-12-12
CVE-2025-14068 WPNakama <= 0.6.3 - Unauthenticated SQL Injection via 'order_by' Parameter — WPNakama – Team and multi-Client Collaboration, Editorial and Project ManagementCWE-89 7.5 High2025-12-12
CVE-2025-12570 Fancy Product Designer <= 6.4.8 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload — Fancy Product DesignerCWE-79 7.2 High2025-12-12
CVE-2025-13660 Guest Support <= 1.2.3 - Unauthenticated User Email Disclosure in guest_support_handler AJAX Endpoint — Guest SupportCWE-200 5.3 Medium2025-12-12
CVE-2025-14138 WPLG Default Mail From <= 1.0.0 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] — WPLG Default Mail FromCWE-79 6.1 Medium2025-12-12
CVE-2025-13366 Rabbit Hole <= 1.1 - Cross-Site Request Forgery to Settings Reset — Rabbit HoleCWE-352 4.3 Medium2025-12-12
CVE-2025-14391 Simple Theme Changer <= 1.0 - Cross-Site Request Forgery to Arbitrary Theme Switcher Configuration Update — Simple Theme ChangerCWE-352 4.3 Medium2025-12-12
CVE-2025-14137 Simple AL Slider <= 1.2.10 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] — Simple AL SliderCWE-79 6.1 Medium2025-12-12
CVE-2025-12834 Accept Stripe Payments Using Contact Form 7 <= 3.1 - Reflected Cross-Site Scripting via failure_message — Accept Stripe Payments Using Contact Form 7CWE-79 6.1 Medium2025-12-12
CVE-2025-14160 Upcoming for Calendly <= 1.2.4 - Cross-Site Request Forgery to Settings Update — Upcoming for CalendlyCWE-352 4.3 Medium2025-12-12
CVE-2025-13314 Product Filtering by Categories, Tags, Price Range for WooCommerce <= 1.1.6 - Missing Authorization to Unauthenticated Plugin Settings Modification — Filter Plus – Product Filter & WordPress FilterCWE-862 5.3 Medium2025-12-12
CVE-2025-13987 Purchase and Expense Manager <= 1.1.2 - Cross-Site Request Forgery to Arbitrary Purchase Record Deletion — Purchase and Expense ManagerCWE-352 4.3 Medium2025-12-12
CVE-2025-14062 Animated Pixel Marquee Creator <= 1.0.0 - Cross-Site Request Forgery via 'marquee' Parameter — Animated Pixel Marquee CreatorCWE-352 4.3 Medium2025-12-12
CVE-2025-12963 LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart <= 1.2.29 - Missing Authorization to Uanuthenticated Privilege Escalation — LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt ChartCWE-862 9.8 Critical2025-12-12

Vulnerabilities classified as access:pre-auth represent 18839 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.