Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

UNKNOWN — Vulnerabilities & Security Advisories 4143

Browse all 4143 CVE security advisories affecting UNKNOWN. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2023-1982 Front Editor <= 4.0.4 - Admin+ Stored XSS — Guest posting / Frontend Posting wordpress plugin 4.8 -2023-08-30
CVE-2023-3992 PostX - Gutenberg Post Grid Blocks < 3.0.6 - Reflected Cross-Site Scripting — PostX 6.1 -2023-08-30
CVE-2023-4035 Simple Blog Card < 1.31 - Contributor+ Stored XSS via Shortcode — Simple Blog Card 5.4 -2023-08-30
CVE-2023-4013 GDPR Cookie Compliance < 4.12.5 - License Update/Deactivation via CSRF — GDPR Cookie Compliance (CCPA, DSGVO, Cookie Consent) 6.5 -2023-08-30
CVE-2023-4109 Ninja Forms < 3.6.26 - Admin+ Stored HTML Injection — Ninja Forms Contact Form 6.1 -2023-08-30
CVE-2023-3501 FormCraft < 1.2.7 - Admin+ Stored XSS — FormCraft 4.8 -2023-08-30
CVE-2023-4036 Simple Blog Card < 1.32 - Subscriber+ Arbitrary Post Access — Simple Blog Card 6.5 -2023-08-30
CVE-2023-3720 Upload Media By URL < 1.0.8 - Stored XSS via CSRF — Upload Media By URL 4.3 -2023-08-30
CVE-2023-3356 Subscribers Text Counter < 1.7.1 - Settings Update via CSRF to Stored XSS — Subscribers Text Counter 6.1 -2023-08-30
CVE-2023-3604 Change WP Admin < 1.1.4 - Secret Login Page Disclosure — Change WP Admin Login 5.3 -2023-08-21
CVE-2023-3936 Blog2Social < 7.2.1 - Reflected XSS — Blog2Social: Social Media Auto Post & Scheduler 6.1 -2023-08-21
CVE-2023-3366 MultiParcels Shipping For WooCommerce < 1.15.2 - Arbitrary Shipment Deletion via CSRF — MultiParcels Shipping For WooCommerce 6.5 -2023-08-21
CVE-2023-3954 MultiParcels Shipping For WooCommerce 1.15.2-1.15.3 - Reflected XSS — MultiParcels Shipping For WooCommerce 6.1 -2023-08-21
CVE-2023-3667 Bit Assist < 1.1.9 - Admin+ Stored Cross-Site Scripting — Chat Button: WhatsApp Chat, Facebook Messenger, Telegram Chat, WeChat, Line Chat, Discord Chat for Customer Support Chat with floating Chat Widget 4.8 -2023-08-21
CVE-2023-2254 Ko-fi Button < 1.3.3 - Admin+ Stored XSS — Ko-fi Button 4.8 -2023-08-16
CVE-2023-0551 REST API TO MiniProgram <= 4.6.1 - Subscriber+ Attachment Deletion — REST API TO MiniProgram 6.5 -2023-08-16
CVE-2023-1977 Booking Manager < 2.0.29 - Subscriber+ SSRF — Booking Manager 8.5 -2023-08-16
CVE-2023-1465 WP EasyPay < 4.1 - Reflected Cross-Site Scripting — WP EasyPay 6.1 -2023-08-16
CVE-2023-0274 URL Params < 2.5 - Contributor+ Stored XSS — URL Params 5.4 -2023-08-16
CVE-2023-1110 Yellow Yard < 2.8.12 - Contributor+ Stored XSS — Yellow Yard Searchbar 5.4 -2023-08-16
CVE-2023-2225 SEO ALert <= 1.59 - Admin+ Stored XSS — SEO ALert 4.8 -2023-08-16
CVE-2023-2272 Tiempo.com <= 0.1.2 - Reflected XSS — Tiempo.com 6.1 -2023-08-16
CVE-2023-0058 Tiempo.com <= 0.1.2 - Stored XSS via CSRF — Tiempo.com 6.1 -2023-08-16
CVE-2023-2271 Tiempo.com <= 0.1.2 - Shortcode Deletion via CSRF — Tiempo.com 4.3 -2023-08-16
CVE-2023-2123 WP Inventory Manager < 2.1.0.13 - Reflected Cross-Site Scripting — WP Inventory Manager 6.1 -2023-08-16
CVE-2023-0579 YARPP - Yet Another Related Posts Plugin < 5.30.3 - Subscriber+ SQLi — YARPP 8.8 -2023-08-16
CVE-2023-2122 Image Optimizer by 10web < 1.0.27 - Reflected Cross-Site Scripting — Image Optimizer by 10web 6.1 -2023-08-16
CVE-2022-4782 ClickFunnels <= 3.1.1 - Contributor+ Stored XSS via Shortcode — ClickFunnels 5.4 -2023-08-16
CVE-2023-2606 WP Brutal AI < 2.06 - Admin+ Stored XSS — WP Brutal AI 4.8 -2023-08-14
CVE-2023-3328 Custom Field For WP Job Manager < 1.2 - Admin+ Stored XSS — Custom Field For WP Job Manager 4.8 -2023-08-14

This page lists every published CVE security advisory associated with UNKNOWN. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.