← All credits
Hackrate
6 vulnerability records and advisories credit this contributor.
CVE-2026-79987
Low-privilege RCE through element-search eager loading
CVE-2026-79989
Arbitrary user password reset leading to administrator account takeover
CVE-2026-79991
Authenticated SQL Injection via nested eager-loading criteria
CVE-2026-79990
GQL entry mutation `siteId` bypasses schema site scope, enabling cross-site content read/write/delete
CVE-2026-79988
Authenticated RCE through Twig sandbox escape
CVE-2026-78416
Authenticated RCE via `condition.config` JSON cleanse bypass