Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

access:pre-auth — CVE vulnerabilities tagged 21982

21982 CVE security advisories tagged "access:pre-auth" with AI Chinese analysis, CVSS, references and POCs.

The tag "access:pre-auth" identifies vulnerabilities that allow unauthenticated attackers to gain unauthorized access to a system, application, or network resource before legitimate credentials are verified. This classification is critical because it represents the lowest barrier to entry for exploitation, enabling remote code execution, data exfiltration, or full system compromise without prior authentication. Typical scenarios involve flaws in authentication mechanisms, such as broken access controls, insecure direct object references, or logic errors in session management that bypass login requirements. Attackers frequently target these weaknesses via exposed APIs, administrative interfaces, or default configurations. Because no user interaction or valid credentials are needed, pre-authentication flaws are among the most severe and widely exploited security issues, often leading to immediate breach of confidentiality, integrity, and availability across affected infrastructure.

CVE IDTitleCVSSSeverityPublished
CVE-2024-11457 Feedpress Generator – External RSS Frontend Customizer <= 1.2.1 - Reflected Cross-Site Scripting — Feedpress Generator – External RSS Frontend CustomizerCWE-79 6.1 Medium2024-12-07
CVE-2024-11464 Easy Code Snippets <= 1.0.2 - Reflected Cross-Site Scripting — Easy Code SnippetsCWE-79 6.1 Medium2024-12-07
CVE-2024-12128 Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal <= 3.1.2 - Reflected Cross-Site Scripting via monthly_sales_current_year Parameter — Simple Ecommerce Shopping Cart Plugin- Sell products through PaypalCWE-79 6.1 Medium2024-12-07
CVE-2024-11367 Smoove connector for Elementor forms <= 4.1.0 - Reflected Cross-Site Scripting — Smoove connector for Elementor formsCWE-79 6.1 Medium2024-12-07
CVE-2024-12270 Beautiful Taxonomy Filters <= 2.4.3 - Unauthenticated SQL Injection — Beautiful taxonomy filtersCWE-89 7.5 High2024-12-07
CVE-2024-11374 TWChat – Send or receive messages from users <= 4.0.4 - Reflected Cross-Site Scripting — TWChat – Send or receive messages from usersCWE-79 6.1 Medium2024-12-07
CVE-2024-12253 Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal <= 3.1.2 - Missing Authorization to Authenticated (Subscriber+) Settings Update / Data Access — Simple Ecommerce Shopping Cart Plugin- Sell products through PaypalCWE-862 5.4 Medium2024-12-07
CVE-2024-12115 Poll Maker <= 5.5.4 - Cross-Site Request Forgery to Poll Duplication — Poll Maker – Versus Polls, Anonymous Polls, Image PollsCWE-352 4.3 Medium2024-12-07
CVE-2024-7894 If Menu <= 0.19.1 - Missing Authorization to License Key Update — If Menu – Visibility control for MenusCWE-862 5.3 Medium2024-12-07
CVE-2024-12165 Mollie for Contact Form 7 <= 5.0.0 - Reflected Cross-Site Scripting — Mollie for Contact Form 7CWE-79 6.1 Medium2024-12-07
CVE-2024-12167 Shortcodes Blocks Creator Ultimate <= 2.2.0 - Reflected Cross-Site Scripting via _wpnonce — Shortcodes Blocks Creator UltimateCWE-79 6.1 Medium2024-12-07
CVE-2024-12257 CardGate Payments for WooCommerce <= 3.2.1 - Reflected Cross-Site Scripting — CardGate Payments for WooCommerceCWE-79 6.1 Medium2024-12-07
CVE-2024-12166 Shortcodes Blocks Creator Ultimate <= 2.2.0 - Reflected Cross-Site Scripting via 'page' — Shortcodes Blocks Creator UltimateCWE-79 6.1 Medium2024-12-07
CVE-2024-10046 افزونه پیامک ووکامرس Persian WooCommerce SMS <= 7.0.5 - Reflected Cross-Site Scripting — افزونه پیامک ووکامرس Persian WooCommerce SMSCWE-79 6.1 Medium2024-12-07
CVE-2024-11943 워드프레스 결제 심플페이 – 우커머스 결제 플러그인 <= 5.2.2 - Reflected Cross-Site Scripting via add_query_arg Function — 워드프레스 결제 심플페이 – 우커머스 결제 플러그인CWE-79 6.1 Medium2024-12-07
CVE-2024-11436 Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! <= 1.4.19 - Reflected Cross-Site Scripting — Pie Forms — Drag & Drop Form BuilderCWE-79 6.1 Medium2024-12-07
CVE-2024-11329 Comfino Payment Gateway <= 4.1.1 - Reflected Cross-Site Scripting — Comfino Payment GatewayCWE-79 6.1 Medium2024-12-07
CVE-2024-52558 Planet Technology Planet WGS-804HPT Integer Underflow — Planet WGS-804HPTCWE-191 5.3 Medium2024-12-06
CVE-2024-52320 Planet Technology Planet WGS-804HPT Command Injection — Planet WGS-804HPTCWE-78 9.8 Critical2024-12-06
CVE-2024-48871 Planet Technology Planet WGS-804HPT Stack-based Buffer Overflow — Planet WGS-804HPTCWE-121 9.8 Critical2024-12-06
CVE-2024-10516 Swift Performance Lite <= 2.3.7.1 - Unauthenticated Local PHP File Inclusion via 'ajaxify' — Swift Performance LiteCWE-22 8.1 High2024-12-06
CVE-2024-10774 SICK InspectorP61x and SICK InspectorP62x have unauthenticated CROWN APIs — SICK InspectorP61xCWE-306 7.3 High2024-12-06
CVE-2024-11289 Soledad <= 8.5.9 - Unauthenticated Limited Local File Inclusion — SoledadCWE-98 8.1 High2024-12-06
CVE-2024-11460 Verowa Connect <= 3.0.1 - Unauthenticated SQL Injection — Verowa ConnectCWE-89 7.5 High2024-12-06
CVE-2024-11728 KiviCare – Clinic & Patient Management System (EHR) <= 3.6.4 - Unauthenticated SQL Injection — KiviCare – Clinic & Patient Management System (EHR)CWE-89 7.5 High2024-12-06
CVE-2024-11204 ForumWP – Forum & Discussion Board <= 2.1.2 - Reflected Cross-Site Scripting via url Parameter — ForumWP – Forum & Discussion BoardCWE-79 6.1 Medium2024-12-06
CVE-2024-11687 Next-Cart Store to WooCommerce Migration <= 3.9.2 - Reflected Cross-Site Scripting — Next-Cart Store to WooCommerce MigrationCWE-79 6.1 Medium2024-12-06
CVE-2024-12155 SV100 Companion <= 2.0.02 - Missing Authorization to Unuathenticated Arbitrary Options Update — SV100 CompanionCWE-862 9.8 Critical2024-12-06
CVE-2024-12028 Friends <= 3.2.1 - Missing Authorization — FriendsCWE-862 5.3 Medium2024-12-06
CVE-2024-9706 Ultimate Coming Soon & Maintenance <= 1.0.9 - Missing Authorization to Unauthenticated Template Activation — Ultimate Coming Soon & MaintenanceCWE-862 5.3 Medium2024-12-06

Vulnerabilities classified as access:pre-auth represent 21982 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.