CVE Analysis
2026
- CVE-2026-93897: GeoDirectory Stored XSS via a Text-type Custom Field 🐈
- CVE-2026-91092: wpForo Forum Guest Post Takeover via a Forged Ownership Cookie 🐈
- CVE-2026-89093: Better Messages Unauthenticated Information Exposure via a Spoofed AI Bot Identity 🐈
- CVE-2026-18442: WCFM Marketplace Unauthenticated SQL Injection via Checkout Distance Shipping 🐈
- CVE-2026-14311: Amelia Missing Authorization to Limited Account Takeover 🐈
- CVE-2026-18555: Better Messages Unauthenticated Reflected XSS via the Live Chat Builder Preview 🐈
- CVE-2026-18063: Job Postings Stored XSS via the position_button Field 🐈
- CVE-2026-18579: WP Photo Album Plus Unauthenticated Stored XSS via Error Log Injection 🐈
- CVE-2026-19769: Ninja Forms Stored XSS via Repeater Child Type Confusion 🐈
- CVE-2026-52810: Gogs Git HTTP Authorisation Bypass via Service Parameter Confusion 🐈
- CVE-2026-52798: Gogs Notebook Stored XSS via Post-Sanitisation Markdown Conversion 🐈
- CVE-2026-47267: Gogs Webhook SSRF via Redirect Bypass with Response Exfiltration 🐈
- CVE-2026-45308: libarchive ZIP Writer Heap Out-of-Bounds Write 🐈
- CVE-2026-11851: ASUS Router bwdpi SQL Injection Patch Bypass 🐈
- CVE-2026-18100: MetForm Stored XSS via the mf_form_id Widget Setting 🐈
- CVE-2026-11780: Quiz and Survey Master Stored XSS via question_title 🐈
- CVE-2026-18501: UsersWP Badge Widget Stored XSS via Variable Substitution 🐈
- CVE-2026-66066: KindaRails2Shell Unauthenticated RCE chain
- CVE-2026-15156: Essential Addons for Elementor Global Reading Progress Stored XSS 🐈
- CVE-2026-15155: Essential Addons for Elementor Email Header Injection to Account Takeover 🐈
- CVE-2026-9145: Contact Form Entries Arbitrary File Copy to File Read 🐈
- CVE-2026-55793: Craft CMS Stored XSS to Account Takeover 🐈
- CVE-2026-55790: Craft CMS DOM XSS via GitHub Issue Title 🐈
- HedgeDoc 2 Stored XSS via Slideshow Reveal Background Iframe 🐈
- CVE-2026-53943: Ghost CMS Unauthenticated Cache-Poisoning XSS 🐈
- CVE-2026-9829: Photo Gallery Compact Album Second-Order Blind SQL Injection 🐈
- CVE-2026-52806: Gogs RCE via Argument Injection 🐈
- CVE-2026-20182: Cisco Catalyst SD-WAN Authentication Bypass 🐈
- CVE-2026-4610: ProfileGrid Stored XSS via Private Messages 🐈
- CVE-2026-4609: ProfileGrid Arbitrary Group Joining 🐈
- CVE-2026-4608: ProfileGrid rid SQL Injection 🐈
- CVE-2026-6127: Elementor REST API Stored XSS 🐈
- CVE-2026-3612: Wavlink Command Injection
- CVE-2026-20127: Cisco Catalyst SD-WAN Authentication Bypass
- CVE-2024-4040: CrushFTP Template Injection
2025
- CVE-2025-31344: giflib Heap-based Buffer Overflow
- CVE-2025-24813: Tomcat DefaultServlet Partial PUT
- CVE-2025-54376: Hoverfly WebSocket Auth Bypass
Bold entries are vulnerabilities I discovered and reported 🐈