0xmrma
11 exploits
Active since Mar 2026
listmonk: Active sessions remain valid after password reset and password change
Memray-generated HTML reports vulnerable to Stored XSS via unescaped command-line metadata
python-ecdsa: Denial of Service via improper DER length validation in crafted private keys
Plane: Cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in other Plane workspaces
CVSS 8.3
Docmost's Public Share Search Exposes Metadata of Restricted Children
CVSS 4.3
Docmost has cross-page attachment overwrite via flawed attachmentId overwrite validation
CVSS 5.4
yeoman-environment Vulnerable to Arbitrary Package Installation without User Confirmation
CVSS 8.6
TypeBot: SSRF Protection Bypass via DNS-Resolved Hostnames in Webhook / HTTP Request Validation
CVSS 7.6
Docmost page content has stored XSS via unsanitized attachment URLs
CVSS 5.4
NocoDB: Shared-base link access can invite arbitrary users as persistent base members
CVSS 5.8
python-ecdsa: Denial of Service via improper DER length validation in crafted private keys
CVSS 5.3