← All credits
Colin Xu
94 vulnerability records and advisories credit this contributor.
CVE-2026-6228
Frontend Admin by DynamiApps <= 3.28.36 - Unauthenticated Privilege Escalation via Edit User Form
CVE-2025-1483
LTL Freight Quotes – GlobalTranz Edition <= 2.3.12 - Missing Authorization to Unauthenticated Settings Update
CVE-2024-9938
Bounce Handler MailPoet 3 <= 1.3.21 - Reflected Cross-Site Scripting
CVE-2024-9937
Woo Manage Fraud Orders <= 2.6.1 - Reflected Cross-Site Scripting
CVE-2024-9896
BBP Core – Expand bbPress powered forums with useful features <= 1.2.5 - Reflected Cross-Site Scripting via add_query_arg Parameter
CVE-2024-9888
ElementInvader Addons for Elementor <= 1.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVE-2024-9385
Themify Builder <= 7.6.2 - Reflected Cross-Site Scripting
CVE-2024-9384
Quantity Dynamic Pricing & Bulk Discounts for WooCommerce <= 3.8.0 - Reflected Cross-Site Scripting
CVE-2024-9378
YML for Yandex Market <= 4.7.2 - Reflected Cross-Site Scripting
CVE-2024-9377
Products, Order & Customers Export for WooCommerce <= 2.0.15 - Reflected Cross-Site Scripting