Vulnerability Research

Security vulnerabilities I've discovered and responsibly disclosed since 2020.

TOTAL CVES

43

CRITICAL FINDINGS

10

YEARS ACTIVE

6

CTRL + K
TRA-2025-50

Ultimate Dashboard

Medium

Exposed API Key

2025 View
TRA-2025-34

BentoML

High

SSRF Bypass

2025 View
TRA-2025-33

Feed Them Social

Medium

Exposed API Key

2025 View
TRA-2025-32

WP Social Ninja

Medium

Exposed API Key

2025 View
CVE-2025-2304

Camaleon CMS

High

Privilege Escalation

2025 View
CVE-2024-12015

Project Manager

High

SQL Injection

2024 View
CVE-2024-10859

Surecart

Critical

SQL Injection

2024 View
CVE-2024-9148

Flowise

Medium

Stored XSS

2024 View
CVE-2024-8182

Flowise

High

Denial of Service

2024 View
CVE-2024-7790

DevikaAI

Medium

Stored XSS

2024 View
CVE-2024-7297

Langflow

High

Privilege Escalation

2024 View
CVE-2024-4960

WP RSS Aggregator

Medium

Reflected XSS

2024 View
CVE-2024-4959

Solidus

Medium

Stored XSS

2024 View
CVE-2024-1063

AppWrite

Medium

Blind SSRF

2024 View
CVE-2024-1061

HTML5 Video Player

Critical

SQL Injection

2024 View
CVE-2023-6360

My Calendar

Critical

SQL Injection

2023 View
CVE-2023-4137

AYS Popup Box

Medium

Reflected XSS

2023 View
CVE-2023-28667

Lead Generated

Critical

Insecure Deserialization

2023 View
CVE-2023-28666

InPost Gallery

Medium

Reflected XSS

2023 View
CVE-2023-28665

Bulk Price Update

Medium

Reflected XSS

2023 View
CVE-2023-28664

MDTF – Meta Data Filter

Medium

Reflected XSS

2023 View
CVE-2023-28663

Formidable PRO2PDF

High

SQL Injection

2023 View
CVE-2023-28662

Gift Vouchers and Packages

Critical

SQL Injection

2023 View
CVE-2023-28661

WP Popup Banners

High

SQL Injection

2023 View
CVE-2023-28660

Events Made Easy

High

SQL Injection

2023 View
CVE-2023-28659

Waiting: One-click countdowns

High

SQL Injection

2023 View
CVE-2023-28017

CraftCMS

Medium

Stored XSS

2023 View
CVE-2023-26326

BuddyForms

Critical

Insecure Deserialization

2023 View
CVE-2023-26325

ReviewX

High

SQL Injection

2023 View
CVE-2023-23492

Login with Phone Number

Medium

Reflected XSS

2023 View
CVE-2023-23491

Quick Event Manager

Medium

Reflected XSS

2023 View
CVE-2023-23490

Survey Maker

High

SQL Injection

2023 View
CVE-2023-23489

Easy Digital Downloads

Critical

SQL Injection

2023 View
CVE-2023-23488

Paid Memberships Pro

Critical

SQL Injection

2023 View
CVE-2023-0448

WP Helper Lite

Medium

Reflected XSS

2023 View
CVE-2022-1731

Metasonic Doc WebClient

Critical

SQL Injection

2022 View
CVE-2022-38131

RStudio Connect

Medium

Open Redirect

2022 View
CVE-2021-41262

Galette

High

SQL Injection

2021 View
CVE-2021-41261

Galette

Medium

Stored XSS

2021 View
CVE-2021-41260

Galette

Medium

CSRF

2021 View
CVE-2020-25070

USVN

Medium

CSRF

2020 View
CVE-2020-25069

USVN

Critical

RCE

2020 View
CVE-2020-15081

PrestaShop

Medium

Information Disclosure

2020 View

Showing 43 of 43 results