Brad Bell
10 exploits
Active since Mar 2021
Feed Me plugin 4.6.1 for Craft CMS - Denial of Service via Crafted Feed-Me Name and URL Fields
CVSS 7.5
Craft CMS 3.0.0-3.9.5 and 4.0.0-RC1-4.4.15 - Privilege Escalation
CVSS 5.4
Craft Commerce <4.10.2/5.5.3 - SQL Injection
CVSS 8.8
Craft Commerce 4.0.0-4.10.1 - Stored Cross-Site Scripting in Order Status Update
CVSS 4.8
Craft Commerce <5.5.3 - SQL Injection
CVSS 8.8
Craft CMS 3.1.31 - Stored Cross-Site Scripting via Site Settings
CVSS 5.4
CraftCMS < 3.7.68 - Stored Cross-Site Scripting via Volume Name
CVSS 6.1
Craft CMS 3.0.0-3.8.14 and 4.0.0-RC1-4.4.14 - Authenticated Remote Code Execution via Path Validation Bypass
CVSS 7.2
Craft CMS 3.0.0-3.9.5 and 4.0.0-RC1-4.4.15 - Privilege Escalation
CVSS 5.4
Craft CMS 4.0.0-RC1-4.16.5 and 5.0.0-RC1-5.8.6 - Remote Code Execution via Twig SSTI
CVSS 7.2