access:pre-auth 类型相关 23083 条 CVE 漏洞,含 AI 中文分析、CVSS、参考链接与 POC。
“access:pre-auth”标签标识了无需身份验证即可触发的漏洞,涵盖18971个CVE。此类漏洞之所以关键,是因为攻击者无需凭证即可直接利用,极大降低了攻击门槛并扩大了潜在受害面。典型场景包括远程代码执行、未授权数据访问及拒绝服务攻击,常见于配置错误的API接口、默认凭证服务或存在逻辑缺陷的认证前处理模块,对系统安全性构成直接且严重的威胁。
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-61426 | Mervin Praison praisonai 信息泄露漏洞 — PraisonAICWE-200 | 8.6 | High | 2026-07-11 |
| CVE-2026-56303 | Capgo 信息泄露漏洞 — CapgoCWE-200 | 7.5 | High | 2026-07-11 |
| CVE-2026-56296 | Capgo 侧信道信息泄露漏洞 — capgoCWE-203 | 5.3 | Medium | 2026-07-11 |
| CVE-2026-57827 | RSJoomla RSFiles 任意文件上传漏洞 — rsjoomla.com RSFiles extension for JoomlaCWE-434 | 10.0 | Critical | 2026-07-11 |
| CVE-2026-9017 | webaways NEX-Forms – Ultimate Forms Plugin for WordPress 授权问题漏洞 — NEX-Forms – Ultimate Forms Plugin for WordPressCWE-862 | 5.3 | Medium | 2026-07-11 |
| CVE-2026-9282 | boldgrid W3 Total Cache 路径遍历漏洞 — W3 Total CacheCWE-22 | 7.5 | High | 2026-07-11 |
| CVE-2026-15010 | WordPress bbp style pack 跨站脚本漏洞 — bbp style packCWE-79 | 6.4 | Medium | 2026-07-11 |
| CVE-2026-6939 | WordPress CorvusPay WooCommerce Payment Gateway 跨站脚本漏洞 — CorvusPay WooCommerce Payment GatewayCWE-79 | 7.2 | High | 2026-07-11 |
| CVE-2026-4661 | WordPress WP CTA SQL注入漏洞 — WP CTA – Call Now Button, Sticky Button & Call to Action BuilderCWE-89 | 7.5 | High | 2026-07-11 |
| CVE-2026-12994 | WordPress WCFM 授权问题漏洞 — WCFM – Frontend Manager for WooCommerceCWE-862 | 5.3 | Medium | 2026-07-11 |
| CVE-2026-6801 | postmagthemes Context Blog 信息泄露漏洞 — Context BlogCWE-200 | 5.3 | Medium | 2026-07-11 |
| CVE-2026-10865 | stylemixthemes cost calculator builder 信息泄露漏洞 — Cost Calculator BuilderCWE-200 | 5.3 | Medium | 2026-07-11 |
| CVE-2026-11901 | WordPress WP Hotel Booking 输入验证错误漏洞 — WP Hotel BookingCWE-345 | 5.3 | Medium | 2026-07-11 |
| CVE-2026-13378 | WordPress Form Vibes – Save Contact Form 7 & Elementor Form Entries to Database 跨站脚本漏洞 — Form Vibes – Save Contact Form 7 & Elementor Form Entries to DatabaseCWE-79 | 7.2 | High | 2026-07-11 |
| CVE-2026-7655 | surecart 授权问题漏洞 — SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & PaymentsCWE-640 | 8.1 | High | 2026-07-11 |
| CVE-2026-6804 | WordPress AI Copilot – Content Generator 授权问题漏洞 — AI Copilot – Content GeneratorCWE-862 | 5.3 | Medium | 2026-07-11 |
| CVE-2026-15335 | masaakitanaka Booking Package SQL注入漏洞 — Booking PackageCWE-89 | 7.5 | High | 2026-07-11 |
| CVE-2026-13250 | WordPress Solace Extra 授权问题漏洞 — Solace ExtraCWE-862 | 5.3 | Medium | 2026-07-11 |
| CVE-2026-3576 | WordPress Planyo online reservation system 输入验证错误漏洞 — Planyo online reservation systemCWE-20 | 7.2 | High | 2026-07-11 |
| CVE-2026-6803 | WordPress AI Copilot – Content Generator 授权问题漏洞 — AI Copilot – Content GeneratorCWE-862 | 5.3 | Medium | 2026-07-11 |
| CVE-2026-13114 | WordPress Motors 跨站脚本漏洞 — Motors – Car Dealership & Classified Listings PluginCWE-79 | 7.2 | High | 2026-07-11 |
| CVE-2026-12426 | WordPress Members 信息泄露漏洞 — Members – Membership & User Role Editor PluginCWE-200 | 5.3 | Medium | 2026-07-11 |
| CVE-2026-10628 | WordPress Points and Rewards for WooCommerce 授权问题漏洞 — Points and Rewards for WooCommerceCWE-862 | 4.3 | Medium | 2026-07-11 |
| CVE-2026-13262 | WordPress Majestic Support SQL注入漏洞 — Majestic Support – The Leading-Edge Help Desk & Customer Support PluginCWE-89 | 6.5 | Medium | 2026-07-11 |
| CVE-2026-55883 | Tilt Dev Tilt 输入验证错误漏洞 — tiltCWE-345 | - | - | 2026-07-10 |
| CVE-2026-55882 | Tilt Dev Tilt 信息泄露漏洞 — tiltCWE-200 | - | - | 2026-07-10 |
| CVE-2026-55884 | Tilt Dev Tilt 授权问题漏洞 — tiltCWE-306 | 9.2 | Critical | 2026-07-10 |
| CVE-2026-58499 | EverMind EverOS 路径遍历漏洞 — EverOSCWE-22 | 8.2 | High | 2026-07-10 |
| CVE-2026-55879 | OpenReplay 跨站脚本漏洞 — openreplayCWE-79 | 9.3 | Critical | 2026-07-10 |
| CVE-2026-12761 | WordPress miniOrange Social Login and Register 授权问题漏洞 — miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn)CWE-287 | 9.8 | Critical | 2026-07-10 |
access:pre-auth 是常见的弱点类别,本平台收录该类弱点关联的 23083 条 CVE 漏洞。