Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Unknown — Vulnerabilities & Security Advisories 4789

Browse all 4789 CVE security advisories affecting Unknown. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2026-14832 ShopSmart Loyalty for WooCommerce <= 1.0.0 - Unauthenticated Sensitive Information Disclosure via shopsmart_check_phone — ShopSmart Loyalty for WooCommerce--2026-08-17
CVE-2026-13700 WooMS <= 9.14 - Unauthenticated Server-Side Request Forgery and Sensitive Information Disclosure — WooMS--2026-08-17
CVE-2026-19726 Visualizer < 4.0.7 - Contributor+ Cross-User Chart Configuration Disclosure — Visualizer--2026-08-16
CVE-2026-19728 Extra Product Options Builder for WooCommerce < 1.2.176 - Unauthenticated Customer File Disclosure via getpublicfileupload — Extra Product Options Builder for WooCommerce--2026-08-16
CVE-2026-19725 WPvivid Backup & Migration < 0.9.131 - Unauthenticated Path Traversal via send_to_site_connect — WPvivid — Backup, Migration & Staging--2026-08-16
CVE-2026-18653 WP Directory Kit < 1.5.7 - Admin+ SQL Injection via section Parameter — WP Directory Kit--2026-08-16
CVE-2026-19712 Masteriyo LMS < 2.3.3 - Instructor+ Stored XSS via Quiz Description — Masteriyo LMS--2026-08-16
CVE-2026-19613 ECS < 4.3.10 - Contributor+ Arbitrary Post Meta Disclosure via Dynamic Repeater ACF Source — ECS--2026-08-16
CVE-2026-19717 CatFolders Document Gallery < 2.0.7 - Unauthenticated Attachment Disclosure via REST API — CatFolders Document Gallery & PDF Library--2026-08-16
CVE-2026-19714 Simple JWT Login < 3.6.8 - Unauthenticated Account Takeover via Missing Google id_token Audience Validation — Simple JWT Login--2026-08-16
CVE-2026-19711 Premium Packages – Sell Digital Products Securely < 7.0.7 - Subscriber+ Arbitrary Amount Withdrawal Request — Premium Packages--2026-08-16
CVE-2026-15384 Manual Image Crop < 1.15 - Subscriber+ Arbitrary Attachment Image Overwrite via IDOR — Manual Image Crop--2026-08-16
CVE-2026-13712 Divi 5.0 - 5.8.1 - Contributor+ Stored XSS via Social Media Follow Skype URL — Divi--2026-08-16
CVE-2026-17533 All-in-One WP Migration and Backup < 7.108 - Multisite Subsite Admin+ Network-Wide PHP Code Execution via REST Import — All-in-One WP Migration and Backup--2026-08-16
CVE-2026-16541 Simply Schedule Appointments < 1.6.12.17 - Team Member+ User Email Disclosure via Users and Customers REST Endpoints — Simply Schedule Appointments--2026-08-15
CVE-2026-16611 Product Feed PRO for WooCommerce < 13.5.7 - Unauthenticated Feed Configuration Disclosure — Product Feed PRO for WooCommerce by AdTribes--2026-08-15
CVE-2026-18807 ECS < 4.3.8 - Contributor+ Arbitrary Post Binding and Global Preset Modification via Dynamic Repeater Handlers — ECS--2026-08-15
CVE-2026-18216 Backup Migration < 2.1.7 - Admin+ Privilege Escalation via Post-Restore Auto-Login — Backup Migration--2026-08-15
CVE-2026-14230 ECS < 4.3.8 - Contributor+ Stored XSS via Dynamic Repeater Bindings — ECS--2026-08-15
CVE-2026-14229 ECS < 4.3.8 - Unauthenticated Private Content Disclosure via ecsload — ECS--2026-08-15
CVE-2026-18039 Essential Addons for Elementor < 6.7.2 - Unauthenticated Privilege Escalation via Custom Profile Field Mass Assignment — Essential Addons for Elementor--2026-08-14
CVE-2026-15205 Paymob for WooCommerce < 4.1.9 - Unauthenticated SQL Injection via Paymob Callback Pixel Lookup — Paymob for WooCommerce--2026-08-14
CVE-2026-16739 Epeken All Kurir <= 2.1.2 - Unauthenticated Order Payment Confirmation Forgery — Epeken All Kurir for Woocommerce--2026-08-14
CVE-2026-14290 Embed Google Photos Album Easily <= 2.2.1 - Contributor+ Stored XSS via link Shortcode Attribute — Embed Google Photos album--2026-08-14
CVE-2026-15413 Link Factory - Backdoor — Link Factory 10.0 Critical2026-08-13
CVE-2026-14332 Ecwid by Lightspeed Ecommerce Shopping Cart < 7.0.9 - Subscriber+ Store Disconnection via 'ec_disconnect' Action — Ecwid by Lightspeed Ecommerce Shopping Cart 5.4 Medium2026-08-13
CVE-2026-18945 WP Helper Premium < 4.7.6 - Unauthenticated Order Data Disclosure and Order Manipulation via Missing Order Key Validation — WP Helper Premium--2026-08-13
CVE-2026-19088 ShopEngine < 4.9.3 - Customer PII Disclosure via Forced Authentication — ShopEngine Elementor WooCommerce Builder Addon--2026-08-13
CVE-2026-14182 Customer Email Verification for WooCommerce < 3.2.6 - Unauthenticated Account Takeover via Type-Juggling Authentication Bypass — Customer Email Verification for WooCommerce--2026-08-13
CVE-2026-14213 Amelia < 2.4.6 - Provider+ Cross-Customer Appointment Data Disclosure via IDOR — Booking for Appointments and Events Calendar--2026-08-13

This page lists every published CVE security advisory associated with Unknown. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.