← All credits
alham-rizvi
51 vulnerability records and advisories credit this contributor.
CVE-2026-90927
filebrowser through 2.63.23 Denial of Service via unbounded WebSocket message
CVE-2026-87814
SiYuan before v3.8.2 Stored XSS via Asset Preview
CVE-2026-72700
Grav before 3.9.1 Timing Attack via Non-Constant-Time Token Comparison
CVE-2026-85578
SiYuan through 3.8.1 Authorization Bypass via getFile
CVE-2026-86192
SiYuan before v3.8.2 Information Disclosure via Attribute-View
CVE-2026-85601
Grav Admin before 2.0.20 Cross-Site Scripting via marked.js
CVE-2026-74907
Grav before 2.0.15 Path Traversal via plugin-asset-map.php
CVE-2026-86191
SiYuan before v3.8.2 Private Attribute View Key Enumeration
CVE-2026-85600
Grav Admin before 2.0.21 Stored XSS via username
CVE-2026-85585
SiYuan before v3.8.2 Unbounded Memory Consumption via ControlConcurrency