Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Unknown — Vulnerabilities & Security Advisories 4608

Browse all 4608 CVE security advisories affecting Unknown. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2025-15672 Chama < 1.0.13 - Unauthenticated PHP Object Injection — ChamaWP--2026-08-03
CVE-2026-15254 Simply Schedule Appointments < 1.6.12.11 - Contributor+ Sensitive Data Disclosure via Admin Shortcode — Simply Schedule Appointments--2026-08-03
CVE-2026-16274 Classified Listing < 5.4.4 - Contributor+ Unpublished Post Content Disclosure via rtcl_block_css_get_posts — Classified Listing--2026-08-03
CVE-2026-16057 Contest Gallery < 30.0.7 - Author+ Arbitrary Post Deletion via post_cg_youtube_delete_from_library — Contest Gallery--2026-08-03
CVE-2026-15236 Gallery for Google Photos < 1.2.1 - Unauthenticated Google OAuth Token Disclosure — Gallery for Google Photos--2026-08-02
CVE-2026-13389 WebToffee Cookie Consent < 3.5.3 - Consent Log Disclosure/Deletion, Page Creation & License Deactivation via Unprotected REST Routes — webtoffee-cookie-consent--2026-08-02
CVE-2026-16064 Event Booking Manager for WooCommerce < 5.3.7 - Contributor+ Arbitrary Post Modification via mpwem_quick_edit_event — Event Booking Manager for WooCommerce--2026-08-02
CVE-2026-16062 Event Booking Manager for WooCommerce < 5.3.7 - Contributor+ PHP Object Injection via Event Timeline and FAQ Content — Event Booking Manager for WooCommerce--2026-08-02
CVE-2026-16063 Event Booking Manager for WooCommerce < 5.3.7 - Author+ Stored XSS via Event Timeline Content — Event Booking Manager for WooCommerce--2026-08-02
CVE-2026-16540 Simply Schedule Appointments < 1.6.12.6 - Unauthenticated Appointment Data Disclosure and Mass Deletion via purge Endpoint — Simply Schedule Appointments--2026-08-02
CVE-2025-15675 Charitable < 1.8.5.3 - Admin+ Stored XSS via Photo Field ALT Text — Charitable--2026-08-02
CVE-2026-16292 Frontend File Manager Plugin <= 23.6 - File Metadata Update via CSRF — Frontend File Manager Plugin--2026-08-02
CVE-2026-16273 Narrative Publisher <= 1.0.7 - Contributor+ Stored XSS via narrative_post_script Post Meta — Narrative Publisher--2026-08-02
CVE-2026-16261 Huge IT Login <= 1.0.4 - Unauthenticated Account Takeover — login-social--2026-08-02
CVE-2026-16291 ProfileGrid < 5.9.9.8 - Subscriber+ Arbitrary Notification Deletion via IDOR — ProfileGrid--2026-08-02
CVE-2026-16285 WooCommerce Product Attachment < 2.3.3 - Unauthenticated Arbitrary Media Download — Product Attachment for WooCommerce--2026-08-02
CVE-2026-16042 LWS Optimize < 3.4 - Subscriber+ Cache Deletion — LWS Optimize--2026-08-02
CVE-2026-11872 Clever Mega Menu for Visual Composer <= 1.0.1 - Subscriber+ Menu Item Meta Update via save_clever_menu_item — Clever Mega Menu for Visual Composer--2026-08-02
CVE-2026-14817 Element Pack Elementor Addons < 8.7.13 - Contributor+ DOM-Based Stored XSS via uikit Data Attributes — Element Pack Addons for Elementor--2026-08-02
CVE-2026-12586 Lenxel WP <= 1.0.31 - Unauthenticated Account Takeover via Arbitrary Password Reset — Lenxel WP--2026-08-02
CVE-2026-15385 RT Mega Menu < 1.5.2 - Subscriber+ Stored XSS via Menu Item CSS — RT Mega Menu--2026-08-02
CVE-2026-15241 ChatBot for eCommerce – WoowBot < 4.8.4 - Unauthenticated Gemini API Key Abuse via qcld_gemini_response — AI ChatBot for WooCommerce--2026-08-02
CVE-2026-15939 Simple Restrict < 1.2.9 - Contributor+ Restricted Content Disclosure via REST API — Simple Restrict--2026-08-02
CVE-2026-15248 Meta Box < 5.13.1 - Contributor+ Arbitrary Attachment Deletion via IDOR — Meta Box--2026-08-02
CVE-2026-16256 Pouco Import Users <= 1.0.0 - Unauthenticated Privilege Escalation — POUCO Import Users--2026-08-02
CVE-2026-15206 SMS Alert Order Notifications – WooCommerce < 3.9.8 - Unauthenticated Account Takeover via Unbound OTP Verification in Signup-with-Mobile — SMS Alert--2026-08-02
CVE-2026-15151 Five Star Restaurant Reservations < 2.7.23 - Booking Manager+ Missing Authorization via rtb_reset_notifications — Five Star Restaurant Reservations--2026-08-02
CVE-2026-14938 FluentBoards < 1.95.3 - Subscriber+ Cross-Board Task Disclosure via IDOR — FluentBoards--2026-08-02
CVE-2026-14841 King Addons for Elementor < 51.1.76 - Reflected XSS via Posts Grid Widget — King Addons for Elementor--2026-08-02
CVE-2026-14920 AcyMailing < 10.11.1 - Unauthenticated SQL Injection via subscription[] Parameter — AcyMailing--2026-08-02

This page lists every published CVE security advisory associated with Unknown. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.