← All credits
Raphael P. Cigana
7 vulnerability records and advisories credit this contributor.
CVE-2026-97188
String Locator < 2.6.8 - Unauthenticated PHP Object Injection via Database Editor
CVE-2026-103323
Integration for Epos Now and WooCommerce 4.6.0 - 4.11.1 - Unauthenticated Action Scheduler Queue Disclosure
CVE-2026-92994
Verge3D < 4.13.1 - Unauthenticated Stored XSS via File Storage API
CVE-2026-92995
Verge3D <= 4.13.0 - Unauthenticated Product Download Disclosure via v3d_download_file
CVE-2026-96526
MCP Server for WordPress < 1.8.2 - Contributor+ Arbitrary Post Title Disclosure via workflows/run REST Route
CVE-2026-96525
MCP Server for WordPress < 1.8.2 - Contributor+ Workflow Modification and Deletion via Missing Ownership Check
CVE-2026-96524
MCP Server for WordPress < 1.8.2 - Administrator Account Creation via CSRF