Jenderal92
20 exploits
Active since Feb 2023
Essential Addons for Elementor 5.4.0-5.7.1 - Unauthenticated Privilege Escalation via Arbitrary Password Reset
Super Backup & Clone - Migrate <2.3.3 - RCE
WordPress WP Time Capsule Arbitrary File Upload to RCE
JSON API User <3.9.3 - Privilege Escalation
RegistrationMagic < 6.0.2.7 - Unauthenticated Privilege Escalation via Password Reset Token Validation Bypass
Chamilo unauthenticated command injection in PowerPoint upload
Kirki 6.0.0 - 6.0.6 - Unauthenticated Privilege Escalation via 'handle_forgot_password'
CVSS 9.8
WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action
CVSS 9.8
React Server Components <19.2.0 - RCE
CVSS 10.0
Piotnet Addons for Elementor Pro <= 7.1.70 - Unauthenticated Arbitrary File Upload via Form File Upload
CVSS 9.8
Divi Form Builder <= 5.1.2 - Unauthenticated Privilege Escalation via 'role'
CVSS 9.8
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover
CVSS 9.8
Magento SessionReaper
CVSS 9.1
cPanel and WHM Authentication Bypass via Login Flow
CVSS 9.8
Opal Estate Pro - Property Management and Submission <=1.7.5 - Privilege Escalation
CVSS 9.8
WordPress Royal Elementor Addons RCE
CVSS 9.8
MStore API < 3.9.2 - Unauthenticated Authentication Bypass via Listing REST API
CVSS 9.8
PaperCut MF and NG 8.0-20.1.7 - Unauthenticated Remote Code Execution via SetupCompleted
CVSS 9.8
WooCommerce Payments < 4.8.2 and WooPayments < 5.6.2 - Unauthenticated Privilege Escalation via Request Forgery
CVSS 9.8
Joomla! 4.0.0-4.2.7 - Unauthenticated Improper Access Control in Webservice Endpoints
CVSS 5.3