Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

access:pre-auth — CVE vulnerabilities tagged 18839

18839 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

CVE IDTitleCVSSSeverityPublished
CVE-2025-12358 ShopEngine <= 4.8.5 - Cross-Site Request Forgery to Wishlist Manipulation — ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce SolutionCWE-352 4.3 Medium2025-12-03
CVE-2025-13342 Frontend Admin by DynamiApps <= 3.28.20 - Unauthenticated Arbitrary Options Update — Frontend Admin by DynamiAppsCWE-862 9.8 Critical2025-12-03
CVE-2025-39665 Livestatus Injection in dynmaps — NagvisCWE-203 5.3AIMediumAI2025-12-03
CVE-2025-13486 Advanced Custom Fields: Extended 0.9.0.5 - 0.9.1.1 - Unauthenticated Remote Code Execution in prepare_form — Advanced Custom Fields: ExtendedCWE-94 9.8 Critical2025-12-03
CVE-2025-10304 Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin <= 2.3.8 - Missing Authorization to Unauthenticated Backup Failure — Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning PluginCWE-862 5.3 Medium2025-12-03
CVE-2025-12585 MxChat – AI Chatbot for WordPress <= 2.5.5 - Unauthenticated Information Exposure — MxChat – AI Chatbot & Content Generation for WordPressCWE-200 5.3 Medium2025-12-03
CVE-2025-55076 Plugin Alliance Installation Manager 安全漏洞 — n/a 7.8AIHighAI2025-12-03
CVE-2025-64055 Fanvil x210 安全漏洞 — n/a 7.8AIHighAI2025-12-03
CVE-2025-13658 Industrial Video & Control Longwatch has a Code Injection vulnerability — LongwatchCWE-94 9.8AICriticalAI2025-12-02
CVE-2025-13510 Iskra iHUB and iHUB Lite has a Missing Authentication for Critical Function vulnerabilitiy — iHUB and iHUB LiteCWE-306 9.1AICriticalAI2025-12-02
CVE-2025-13542 DesignThemes LMS <= 1.0.4 - Unauthenticated Privilege Escalation — DesignThemes LMSCWE-269 9.8 Critical2025-12-02
CVE-2025-66454 Arcade MCP Default Hardcoded Worker Secret Allows Full Unauthorized Access to All HTTP MCP Worker Endpoints — arcade-mcpCWE-321 6.5 Medium2025-12-02
CVE-2025-66416 DNS Rebinding Protection Disabled by Default in Model Context Protocol Python SDK for Servers Running on Localhost — python-sdkCWE-1188 7.1 -2025-12-02
CVE-2025-66414 DNS Rebinding Protection Disabled by Default in Model Context Protocol TypeScript SDK for Servers Running on Localhost — typescript-sdkCWE-1188 7.5AIHighAI2025-12-02
CVE-2025-41066 Disclosure of sensitive information in Horde Groupware — GroupwareCWE-200 5.3AIMediumAI2025-12-02
CVE-2025-41015 User Enumeration vulnerability in TCMAN GIM — GIMCWE-200 5.3AIMediumAI2025-12-02
CVE-2025-41014 User Enumeration vulnerability in TCMAN GIM — GIMCWE-200 5.3AIMediumAI2025-12-02
CVE-2025-41012 Unauthorized access vulnerability in TCMAN GIM — GIMCWE-862 7.5AIHighAI2025-12-02
CVE-2025-13871 The feature to manage resources is prone to Cross-Site Request Forgery attacks — OpinioCWE-352 8.8AIHighAI2025-12-02
CVE-2025-13516 SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other Providers <= 1.9.0 - Unauthenticated Arbitrary File Upload — SureMail – SMTP and Email Logs Plugin with Amazon SES, Postmark, and Other ProvidersCWE-434 8.1 High2025-12-02
CVE-2025-13696 Zigaform <= 7.6.5 - Unauthenticated Form Submission Data Disclosure in rocket_front_payment_seesummary AJAX Endpoint — Zigaform – Price Calculator & Cost Estimation Form Builder LiteCWE-200 5.3 Medium2025-12-02
CVE-2025-13140 SurveyJS: Drag & Drop WordPress Form Builder <= 1.12.20 - Cross-Site Request Forgery to Survey Deletion — SurveyJS: Drag & Drop Form BuilderCWE-352 4.3 Medium2025-12-02
CVE-2025-13685 Photo Gallery by Ays <= 6.4.8 - Cross-Site Request Forgery to Bulk Actions — Photo Gallery by Ays – Responsive Image GalleryCWE-352 4.3 Medium2025-12-02
CVE-2025-13007 WP Social Ninja – Embed Social Feeds, Customer Reviews, Chat Widgets (Google Reviews, YouTube Feed, Photo Feeds, and More) <= 3.20.3 - Unauthenticated Stored Cross-Site Scripting via External Content Import — WP Social Ninja – Embed Social Feeds, User Reviews & Chat WidgetsCWE-79 6.1 Medium2025-12-02
CVE-2025-13387 Kadence WooCommerce Email Designer <= 1.5.17 - Unauthenticated Stored Cross-Site Scripting — Kadence WooCommerce Email DesignerCWE-79 7.2 High2025-12-02
CVE-2025-13606 Export All Posts, Products, Orders, Refunds & Users <= 2.19 - Cross-Site Request Forgery to Sensitive Information Exposure — Export All Posts, Products, Orders, Refunds & UsersCWE-352 6.5 Medium2025-12-02
CVE-2025-12529 Cost Calculator Builder <= 3.6.3 - Unauthenticated Arbitrary File Deletion — Cost Calculator BuilderCWE-73 8.8 High2025-12-02
CVE-2025-59695 Entrust nShield Connect XC 安全漏洞 — n/a 4.9AIMediumAI2025-12-02
CVE-2025-65844 EverShop 安全漏洞 — n/a 7.5AIHighAI2025-12-02
CVE-2025-66294 Grav is vulnerable to RCE via SSTI through Twig Sandbox Bypass — gravCWE-94 7.2AIHighAI2025-12-01

Vulnerabilities classified as access:pre-auth represent 18839 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.