Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

unknown — Vulnerabilities & Security Advisories 4139

Browse all 4139 CVE security advisories affecting unknown. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2021-4226 RSFirewall < 1.1.25 - IP Block Bypass — RSFirewall! 9.4 -2022-12-15
CVE-2022-4016 Booster for WooCommerce - Custom Role Creation/Deletion via CSRF — Booster for WooCommerce 6.5 -2022-12-12
CVE-2022-3921 Listingo < 3.2.7 - Unauthenticated Arbitrary File Upload — Listingo 9.8 -2022-12-12
CVE-2022-3900 Cooked Pro < 1.7.5.7 - Unauthenticated PHP Object Injection — Cooked Pro 9.8 -2022-12-12
CVE-2022-3989 Motors - Car Dealer, Classifieds & Listing < 1.4.4 - Arbitrary File Upload — Motors 8.8 -2022-12-12
CVE-2022-3862 Livemesh Addons for Elementor < 7.2.4 - Admin+ Stored XSS — Livemesh Addons for Elementor 4.8 -2022-12-12
CVE-2022-4000 WooCommerce Shipping - DPD baltic < 1.2.11 - Admin+ Stored XSS — WooCommerce Shipping 4.8 -2022-12-12
CVE-2022-3946 Welcart e-Commerce < 2.8.4 - Subscriber+ Arbitrary Shipping Method Creation/Update/Deletion — Welcart e-Commerce 6.5 -2022-12-12
CVE-2022-3881 WPTools < 3.43 - Subscriber+ Arbitrary Plugin Installation — WP Tools Increase Maximum Limits, Repair, Server PHP Info, Javascript errors, File Permissions, Transients, Error Log 5.7 -2022-12-12
CVE-2022-3880 AntiHacker < 4.20 - Subscriber+ Arbitrary Plugin Installation — Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan 5.7 -2022-12-12
CVE-2022-3879 Car Dealer < 3.05 - Subscriber+ Arbitrary Plugin Installation — Car Dealer (Dealership) and Vehicle sales WordPress Plugin 6.5 -2022-12-12
CVE-2022-3906 Easy Form Builder < 3.4.0 - Admin+ Stored XSS — Easy Form Builder 4.8 -2022-12-12
CVE-2022-3930 Directorist < 7.4.2.2 - Subscriber+ Arbitrary User Password Update via IDOR — Directorist 6.5 -2022-12-12
CVE-2022-4010 Image Hover Effects < 5.5 - Admin+ Stored XSS — Image Hover Effects 4.8 -2022-12-12
CVE-2022-3999 WooCommerce Shipping - DPD baltic < 1.2.57 - Subscriber+ Arbitrary Options Deletion — DPD Baltic Shipping 8.1 -2022-12-12
CVE-2022-3609 GetYourGuide Ticketing < 1.0.4 - Admin+ Stored XSS — GetYourGuide Ticketing 4.8 -2022-12-12
CVE-2022-3982 Booking Calendar < 3.2.2 - Unauthenticated Arbitrary File Upload — Booking calendar, Appointment Booking System 9.8 -2022-12-12
CVE-2022-3605 WP CSV Exporter < 1.3.7 - CSV Injection — WP CSV Exporter 7.8 -2022-12-12
CVE-2022-3853 Supra CSV <= 4.0.3 - Stored Cross-Site Scripting via CSRF — Supra CSV 6.1 -2022-12-12
CVE-2022-3981 Icegram Express < 5.5.1 - Subscriber+ SQLi — Icegram Express 8.8 -2022-12-12
CVE-2022-3915 Dokan < 3.7.6 - Unauthenticated SQLi — Dokan 9.8 -2022-12-12
CVE-2022-4004 Donation Button <= 4.0.0 - Subscriber+ Broken Access Control leading to SMS Spam — Donation Button 4.3 -2022-12-12
CVE-2022-3935 Welcart e-Commerce < 2.8.4 - Multiple Subscriber+ Stored Cross-Site Scripting — Welcart e-Commerce 5.4 -2022-12-12
CVE-2022-3919 Jetpack CRM < 5.4.3 - Admin+ Cross-Site Scripting — Jetpack CRM 4.8 -2022-12-12
CVE-2022-3934 Flat PM < 3.0.13 - Reflected Cross-Site Scripting — FlatPM 6.1 -2022-12-12
CVE-2022-3925 Buddybadges <= 1.0.0 - Admin+ SQLi — buddybadges 7.2 -2022-12-12
CVE-2022-4005 Donation Button <= 4.0.0 - Contributor+ Stored XSS — Donation Button 5.4 -2022-12-12
CVE-2022-3933 Essential Real Estate < 3.9.6 - Reflected Cross-Site-Scripting — Essential Real Estate 5.4 -2022-12-12
CVE-2022-3883 StopBadBots < 7.24 - Subscriber+ Arbitrary Plugin Installation — Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection 6.5 -2022-12-12
CVE-2022-3912 User Registration < 2.2.4.1 - Subscriber+ Arbitrary File Upload — User Registration 7.5 -2022-12-12

This page lists every published CVE security advisory associated with unknown. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.