← All credits
cyberkareem
12 vulnerability records and advisories credit this contributor.
CVE-2026-97219
MStore API 4.21.1 - 4.22.0 - Subscriber+ Payment Bypass via 'status' Parameter
CVE-2026-101057
utcp-mcp before 1.1.3 SSRF via unvalidated MCP server URL
CVE-2026-84906
Eventin < 4.1.24 - Unauthenticated Payment Bypass via Stripe and PayPal Cross-Order Transaction Replay
CVE-2026-85615
Openpanel before 2.3.0 Cross-Tenant IDOR via report.getLayouts
CVE-2026-85614
OpenPanel API before 2.3.0 Unauthenticated SSRF via site-checker
CVE-2026-85613
OpenPanel Unauthenticated XSS via SVG Favicon Proxy
CVE-2026-82186
WPLP Cookie Consent < 4.4.2 - Admin+ SQLi via 'offset' Parameter
CVE-2026-82182
WPvivid Backup & Migration < 0.9.133 - Admin+ SQLi via Upload Cleaner Isolation
CVE-2026-62233
grav-plugin-api < 1.0.6 Privilege Escalation via createApiKey
CVE-2026-62236
grav-plugin-login < 3.8.11 CSRF via regenerate2FASecret