Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

UNKNOWN — Vulnerabilities & Security Advisories 4165

Browse all 4165 CVE security advisories affecting UNKNOWN. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2022-3855 404 to Start <= 1.6.1 - Admin+ Stored XSS — 404 to Start 4.8 -2023-01-09
CVE-2022-4426 Mautic Integration For WooCommerce < 1.0.3 - Arbitrary Options Update via CSRF — Mautic Integration for WooCommerce 6.5 -2023-01-09
CVE-2022-4102 Royal Elementor Addons < 1.3.56 - Subscriber+ Arbitrary Post Deletion — Royal Elementor Addons (Elementor Templates, Post Grid, Mega Menu & Header Footer Builder, WooCommerce Builder, Product Grid, Slider, Parallax Image & other Free Elementor Widgets) 3.1 -2023-01-09
CVE-2022-4196 Multi Step Form < 1.7.8 - Admin+ Stored XSS — Multi Step Form 4.8 -2023-01-09
CVE-2022-4103 Royal Elementor Addons < 1.3.56 - Subscriber+ Arbitrary Post Creation — Royal Elementor Addons (Elementor Templates, Post Grid, Mega Menu & Header Footer Builder, WooCommerce Builder, Product Grid, Slider, Parallax Image & other Free Elementor Widgets) 4.3 -2023-01-09
CVE-2022-4374 Bg Bible References <= 3.8.14 - Reflected XSS — Bg Bible References 6.1 -2023-01-09
CVE-2022-4301 Sunshine Photo Cart < 2.9.15 - Reflected XSS — Sunshine Photo Cart 6.1 -2023-01-09
CVE-2022-3923 ActiveCampaign for WooCommerce < 1.9.8 - Subscriber+ Error Log Cleanup — ActiveCampaign for WooCommerce 4.3 -2023-01-09
CVE-2022-4497 Jetpack CRM < 5.5 - Contributor+ Stored XSS — Jetpack CRM 5.4 -2023-01-09
CVE-2022-4394 iPages Flipbook For WordPress <= 1.4.6 - Contributor+ Stored XSS — iPages Flipbook For WordPress 5.4 -2023-01-09
CVE-2022-4479 Table of Contents Plus < 2212 - Contributor+ Stored XSS — Table of Contents Plus 5.4 -2023-01-09
CVE-2022-4491 WP Table Reloaded <= 1.9.4 - Contributor+ Stored XSS — WP-Table Reloaded 5.4 -2023-01-09
CVE-2022-4468 WP Recipe Maker < 8.6.1 - Contributor+ Stored XSS — WP Recipe Maker 5.4 -2023-01-09
CVE-2022-3417 WPtouch < 4.3.45 - Admin+ PHP Object Injection — WPtouch 8.8 -2023-01-09
CVE-2022-4043 WP Custom Admin Interface < 7.29 - Admin+ PHP Object Injection — WP Custom Admin Interface 7.2 -2023-01-09
CVE-2022-4393 ImageLinks Interactive Image Builder for WordPress <= 1.5.3 - Contributor+ Stored XSS — ImageLinks Interactive Image Builder for WordPress 5.4 -2023-01-09
CVE-2022-4392 iPanorama 360 WordPress Virtual Tour Builder <= 1.6.29 - Contributor+ Stored XSS — iPanorama 360 WordPress Virtual Tour Builder 5.4 -2023-01-09
CVE-2022-3416 WPtouch < 4.3.45 - Admin+ Arbitrary File Upload — WPtouch 7.2 -2023-01-09
CVE-2022-3343 WPQA < 5.9.3 - Missing validation lead to functionality abuse — WPQA Builder 4.3 -2023-01-09
CVE-2022-4310 Slimstat Analytics < 4.9.3 - Unauthenticated Stored XSS — Slimstat Analytics 6.1 -2023-01-09
CVE-2022-3860 Visual Email Designer for WooCommerce < 1.7.2 - Multiple Author+ SQLi — Visual Email Designer for WooCommerce 8.8 -2023-01-02
CVE-2022-4260 WP-Ban < 1.69.1 - Admin+ Stored XSS — WP-Ban 4.8 -2023-01-02
CVE-2022-4237 Welcart e-Commerce < 2.8.6 - Subscriber+ PHAR Deserialisation — Welcart e-Commerce 8.8 -2023-01-02
CVE-2022-4372 Web Invoice <= 2.1.3 - Authenticated SQLi — Web Invoice 7.2 -2023-01-02
CVE-2022-4057 Autoptimize < 3.1.0 - Sensitive Data Disclosure — Autoptimize 5.3 -2023-01-02
CVE-2022-4329 Product list Widget for Woocommerce <= 1.0 - Reflected XSS — Product list Widget for Woocommerce 6.1 -2023-01-02
CVE-2022-3911 iubenda < 3.3.3 - Subscriber+ Privileges Escalation to Admin — iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more 8.8 -2023-01-02
CVE-2022-4256 All-in-One Addons for Elementor - WidgetKit < 2.4.4 - Admin+ Stored XSS — All-in-One Addons for Elementor 4.8 -2023-01-02
CVE-2022-4352 Qe SEO Handyman <= 1.0 - Admin+ SQLi — Qe SEO Handyman 7.2 -2023-01-02
CVE-2022-4200 Login with Cognito <= 1.4.8 - Admin+ Stored XSS — Login with Cognito 4.8 -2023-01-02

This page lists every published CVE security advisory associated with UNKNOWN. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.