Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Unknown — Vulnerabilities & Security Advisories 4484

Browse all 4484 CVE security advisories affecting Unknown. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2026-7842 Infility Global < 2.15.20 - Editor+ SQL Injection via orderby Parameter — Infility Global--2026-06-23
CVE-2026-8172 Simple Basic Contact Form <= 20250114 - Reflected XSS — Simple Basic Contact Form--2026-06-23
CVE-2026-8163 Infility Global < 2.15.19 - Subscriber+ SQL Injection via order Parameter — Infility Global--2026-06-23
CVE-2026-10530 Pie Register < 3.8.4.10 - Unauthenticated Email Verification Bypass via Predictable Token — Pie Register--2026-06-22
CVE-2026-7859 Motors Car Dealership & Classified Listings < 1.4.110 - Unauthenticated Post-Meta Write via stm_ajax_add_a_car_media — Motors--2026-06-22
CVE-2026-8157 Vitepos < 3.4.2 - Outlet Manager+ Privilege Escalation — Vitepos--2026-06-22
CVE-2026-6858 Transbank Webpay < 1.14.0 - Unauthenticated Stored XSS — Transbank Webpay--2026-06-22
CVE-2026-4259 Ultimate WooCommerce Auction Pro <= 2.4.5 - Reflected XSS via uwa_manage_auctions — ultimate-woocommerce-auction-pro--2026-06-22
CVE-2026-4110 Ultimate WooCommerce Auction Pro <= 2.4.5 - Reflected XSS via uwa_auctions_bids_list — ultimate-woocommerce-auction-pro--2026-06-22
CVE-2026-9822 WP Hotel Booking < 2.3.1 - Subscriber+ Missing Authorization in Multiple AJAX Handlers — WP Hotel Booking--2026-06-19
CVE-2026-9815 MagicForm <= 0.1.3 - Unauthenticated Arbitrary File Upload to RCE — MagicForm--2026-06-18
CVE-2026-9570 Taskbuilder < 5.0.8 - Reflected XSS via Shortcode — Taskbuilder--2026-06-17
CVE-2026-8383 LearnPress < 4.3.7 - Unauthenticated Sensitive User Information Disclosure via REST API — LearnPress--2026-06-17
CVE-2026-8089 weMail < 2.1.3 - Reflected Cross-Site Scripting — weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce--2026-06-17
CVE-2026-7850 WP Magnific Popup <= 1.0 - Author+ Stored XSS via href Attribute — WP Magnific Popup--2026-06-17
CVE-2026-9278 Form Builder CP < 1.2.47 - Editor+ Stored XSS via form_structure — Form Builder CP--2026-06-15
CVE-2026-8385 WP Go Maps < 10.0.10 - Unauthenticated Sensitive Information Disclosure via Datatables AJAX Fallback — WP Go Maps--2026-06-15
CVE-2026-8935 Advanced Google Maps < 6.1.1 - Unauthenticated Administrator Account Creation — WP MAPS PRO--2026-06-15
CVE-2026-8386 WP Go Maps < 10.0.10 - Unauthenticated Sensitive Information Disclosure via Marker ID — WP Go Maps--2026-06-15
CVE-2025-15546 Iptanus File Upload < 5.1.7 - File Overwrite via Race Condition — Iptanus File Upload--2026-06-14
CVE-2026-9062 Agile Store Locator < 1.6.9 - Admin+ Arbitrary File Read via Path Traversal — Store Locator WordPress--2026-06-13
CVE-2026-9061 Agile Store Locator < 1.6.9 - Admin+ Stored XSS via logo_name — Store Locator WordPress--2026-06-13
CVE-2026-9269 Secure Copy Content Protection and Content Locking < 5.1.5 - Admin+ Stored XSS via ays_sccp_sub_icon_image Parameter — Secure Copy Content Protection and Content Locking--2026-06-12
CVE-2026-9271 KeepInMind - Dashboard Notes < 0.8.4.2 - Contributor+ Stored XSS — KeepInMind Dashboard Notes--2026-06-12
CVE-2026-9067 Schema & Structured Data for WP & AMP < 1.60 - Unauthenticated Arbitrary Media Upload — Schema & Structured Data for WP & AMP--2026-06-10
CVE-2026-9060 Agile Store Locator < 1.6.6 - Admin+ Stored XSS via map_style — Store Locator WordPress--2026-06-10
CVE-2026-8071 Spam protection, Honeypot, Anti-Spam by CleanTalk < 6.79 - Unauthenticated Stored XSS via Comment Shortcode Bypass — Anti-Spam by CleanTalk. Spam protection--2026-06-10
CVE-2026-3326 XStore < 9.7.3 - Unauthenticated SQLi — Xstore--2026-06-10
CVE-2026-8981 Lazy Blocks < 4.3.0 - Admin+ Stored XSS via Custom Block Frontend HTML — Custom Block Builder--2026-06-09
CVE-2026-4986 WPForms Lite < 1.10.0.5 – Unauthenticated PayPal Webhook Forgery — WPForms--2026-06-09

This page lists every published CVE security advisory associated with Unknown. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.