Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18839

18839 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-14092 Edimax BR-6478AC V3 formDebugDiagnosticRun sub_416898 os command injection — BR-6478AC V3CWE-78 4.7 Medium2025-12-05
CVE-2025-14090 AMTT Hotel Broadband Operation System cardmake_down.php sql injection — Hotel Broadband Operation SystemCWE-89 4.7 Medium2025-12-05
CVE-2025-13620 Wp Social Login and Register Social Counter <= 3.1.3 - Missing Authorization in Cache REST Endpoints to Social Counter Tampering — Wp Social Login and Register Social CounterCWE-862 5.3 Medium2025-12-05
CVE-2025-12876 Projectopia – WordPress Project Management <= 5.1.19 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion — Projectopia – Project Management ToolCWE-862 5.3 Medium2025-12-05
CVE-2025-12879 User Generator and Importer <= 1.2.2 - Cross-Site Request Forgery to Privilege Escalation via Arbitrary Administrator Account Creation — User Generator and ImporterCWE-352 8.8 High2025-12-05
CVE-2025-12851 My auctions allegro <= 3.6.32 - Unauthenticated Local File Inclusion via controller — My auctions allegroCWE-98 8.1 High2025-12-05
CVE-2025-12130 WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors <= 2.6.4 - Cross-Site Request Forgery to Vendor Product Deletion — WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product VendorsCWE-352 4.3 Medium2025-12-05
CVE-2025-13684 ARK Related Posts <= 2.19 - Cross-Site Request Forgery to Settings Update — ARK Related PostsCWE-352 4.3 Medium2025-12-05
CVE-2025-12850 My auctions allegro <= 3.6.32 - Unauthenticated SQL Injection via auction_id — My auctions allegroCWE-89 7.5 High2025-12-05
CVE-2025-12093 Voidek Employee Portal <= 1.0.7 - Missing Authorization — Voidek Employee PortalCWE-862 5.3 Medium2025-12-05
CVE-2025-12355 Payaza <= 0.3.8 - Missing Authorization to Unauthenticated Order Status Update — PayazaCWE-862 5.3 Medium2025-12-05
CVE-2025-13515 Nouri.sh Newsletter <= 1.0.1.3 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] — Nouri.sh NewsletterCWE-79 6.1 Medium2025-12-05
CVE-2025-12374 Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login – User Verification <= 2.0.44 - Authentication Bypass to Account Takeover — User Verification by PickPluginsCWE-287 9.8 Critical2025-12-05
CVE-2025-12373 Torod – The smart shipping and delivery portal for e-shops and retailers <= 1.9 - Cross-Site Request Forgery To Plugin's Settings Modification — Torod – The smart shipping and delivery portal for e-shops and retailersCWE-352 4.3 Medium2025-12-05
CVE-2025-13528 Feedback Modal for Website <= 1.0.1 - Missing Authorization to Unauthenticated Arbitrary Feedback Data Exfiltration via 'export_data' Parameter — Feedback Modal for WebsiteCWE-862 5.3 Medium2025-12-05
CVE-2025-12190 Image Optimizer by wps.sk <= 1.2.0 - Cross-Site Request Forgery to Bulk Image Optimization — Image Optimizer by wps.skCWE-352 4.3 Medium2025-12-05
CVE-2025-12128 Hide Categories Or Products On Shop Page <= 1.0.7 - Cross-Site Request Forgery to Settings Update — Hide Categories Or Products On Shop PageCWE-352 4.3 Medium2025-12-05
CVE-2025-12189 Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents <= 7.11.1374 - Cross-Site Request Forgery to Arbitrary File Upload — Bread & Butter: AI-Powered Lead IntelligenceCWE-352 4.3 Medium2025-12-05
CVE-2025-13622 Jabbernotification <= 0.99-RC2 - Reflected Cross-Site Scripting via admin.php PATH_INFO — JabbernotificationCWE-79 6.1 Medium2025-12-05
CVE-2025-13623 Twitscription <= 0.1.1 - Reflected Cross-Site Scripting via admin.php PATH_INFO — TwitscriptionCWE-79 6.1 Medium2025-12-05
CVE-2025-10055 Time Sheets <= 2.1.3 - Cross-Site Request Forgery — Time SheetsCWE-352 4.3 Medium2025-12-05
CVE-2025-13360 Quantic Social Image Hover <= 1.0.8 - Cross-Site Request Forgery to Settings Update — Quantic Social Image HoverCWE-352 4.3 Medium2025-12-05
CVE-2025-13625 WP-SOS-Donate Donation Sidebar Plugin <= 0.9.2 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] — WP-SOS-Donate Donation Sidebar PluginCWE-79 6.1 Medium2025-12-05
CVE-2025-13621 dream gallery <= 1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting via 'dreampluginsmain' AJAX Action — dream galleryCWE-352 6.1 Medium2025-12-05
CVE-2025-13512 CoSign Single Signon <= 0.3.1 - Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] — CoSign Single SignonCWE-79 6.1 Medium2025-12-05
CVE-2025-13144 ContentStudio <= 1.3.7 - Cross-Site Request Forgery to Settings Update — ContentStudioCWE-352 4.3 Medium2025-12-05
CVE-2025-13006 SurveyFunnel – Survey Plugin for WordPress <= 1.1.5 - Unauthenticated Information Exposure — SurveyFunnel – Survey Plugin for WordPressCWE-200 5.3 Medium2025-12-05
CVE-2025-13312 CRM Memberships <= 2.5 - Missing Authorization to Unauthenticated 'ntzcrm_add_new_tag' AJAX Action — CRM MembershipsCWE-862 5.3 Medium2025-12-05
CVE-2025-13313 CRM Memberships <= 2.6 - Missing Authorization to Privilege Escalation via Unauthenticated Password Reset in 'ntzcrm_changepassword' AJAX Endpoint — CRM MembershipsCWE-862 9.8 Critical2025-12-05
CVE-2025-13362 Norby AI <= 1.0.3 - Cross-Site Request Forgery to Settings Update — Norby AICWE-352 4.3 Medium2025-12-05

Vulnerabilities classified as access:pre-auth represent 18839 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.