Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

UNKNOWN — Vulnerabilities & Security Advisories 4143

Browse all 4143 CVE security advisories affecting UNKNOWN. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2023-3601 Simple Author Box < 2.52 - Contributor+ Arbitrary User Information Disclosure via IDOR — Simple Author Box 4.3 -2023-08-14
CVE-2023-2802 Ultimate Addons for Contact Form 7 < 3.1.29 - Admin+ Stored XSS — Ultimate Addons for Contact Form 7 4.8 -2023-08-14
CVE-2023-3435 User Activity Log < 1.6.5 - Unauthenticated SQLi — User Activity Log 9.8 -2023-08-14
CVE-2022-4953 Elementor < 3.5.5 - Iframe Injection — Elementor Website Builder 6.1 -2023-08-14
CVE-2023-2803 Ultimate Addons for Contact Form 7 < 3.1.29 - Reflected XSS — Ultimate Addons for Contact Form 7 6.1 -2023-08-14
CVE-2023-3645 Contact Form Builder by Bit Form < 2.2.0 - Admin+ Stored XSS — Contact Form Builder by Bit Form 4.8 -2023-08-14
CVE-2023-3721 WP-EMail < 2.69.1 - Admin+ Stored Cross-Site Scripting — WP-EMail 4.8 -2023-08-14
CVE-2023-2843 MultiParcels Shipping For WooCommerce < 1.14.15 - Subscribers+ SQLi — MultiParcels Shipping For WooCommerce 8.8 -2023-08-07
CVE-2023-0604 WP Food Manager < 1.0.4 - Admin+ Stored XSS — WP Food Manager 4.8 -2023-08-07
CVE-2021-24916 Qubely < 1.8.6 - Unauthenticated Arbitrary E-mail Sending — Qubely 5.3 -2023-08-07
CVE-2023-3524 WPCode < 2.0.13.1 - Reflected XSS — WPCode 6.1 -2023-08-07
CVE-2023-3671 MultiParcels Shipping For WooCommerce < 1.15.4 - Reflected XSS — MultiParcels Shipping For WooCommerce 6.1 -2023-08-07
CVE-2023-3365 MultiParcels Shipping For WooCommerce < 1.14.14 - Subscriber+ Arbitrary Shipment Deletion — MultiParcels Shipping For WooCommerce 4.3 -2023-08-07
CVE-2023-3575 Quiz And Survey Master < 8.1.11 - Contributor+ Stored XSS — Quiz And Survey Master 5.4 -2023-08-07
CVE-2023-3492 WP Shopping Pages <= 1.14 - Stored XSS via CSRF — WP Shopping Pages 6.1 -2023-08-07
CVE-2023-3650 Bubble Menu < 3.0.5 - Admin+ Stored XSS — Bubble Menu 4.8 -2023-08-07
CVE-2023-3508 WooCommerce Pre-Orders < 2.0.3 - Unauthorised Actions via CSRF — WooCommerce Pre-Orders 4.3 -2023-07-31
CVE-2023-3507 WooCommerce Pre-Orders < 2.0.3 - Arbitrary Pre-Order Canceling via CSRF — WooCommerce Pre-Orders 4.3 -2023-07-31
CVE-2023-3345 LMS by Masteriyo < 1.6.8 - Information Exposure — LMS by Masteriyo 4.3 -2023-07-31
CVE-2023-3292 Grid Kit Premium < 2.2.0 - Multiple Reflected Cross-Site Scripting — grid-kit-premium 6.1 -2023-07-31
CVE-2023-3134 Forminator < 1.24.4 - Reflected XSS — Forminator 6.1 -2023-07-31
CVE-2023-3130 Short URL < 1.6.5 - Admin+ Cross Site Scripting — Short URL 4.8 -2023-07-31
CVE-2022-4888 Multiple Plugins from Addify - Multiple CSRF — Checkout Fields Manager 5.3 -2023-07-31
CVE-2023-0602 Twittee Text Tweet <= 1.0.8 - Reflected XSS — Twittee Text Tweet 6.1 -2023-07-31
CVE-2023-2761 User Activity Log < 1.6.3 - Admin+ SQL Injection — User Activity Log 7.2 -2023-07-24
CVE-2023-3248 All-in-one Floating Contact Form < 2.1.2 - Admin+ Stored Cross-Site Scripting — All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs 4.8 -2023-07-24
CVE-2023-3344 Auto Location for WP Job Manager via Google < 1.1 - Admin+ Cross Site Scripting — Auto Location for WP Job Manager via Google 4.8 -2023-07-24
CVE-2023-2309 wpForo Forum < 2.1.9 - Reflected Cross-Site Scripting — wpForo Forum 6.1 -2023-07-24
CVE-2023-2701 Gravity Forms < 2.7.5 - Reflected XSS — gravityforms 6.1 -2023-07-17
CVE-2023-0439 NEX-Forms < 8.4.4 - Authenticated Stored XSS — NEX-Forms 4.8 -2023-07-17

This page lists every published CVE security advisory associated with UNKNOWN. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.