Valentin Lobstein
99 exploits
Active since Nov 2013
Xorcom Completepbx < 5.2.36.1 - Path Traversal
CVSS 6.5
WordPress Ultimate Member SQL Injection (CVE-2024-1071)
CVSS 9.8
BYOB Unauthenticated RCE via Arbitrary File Write and Command Injection (CVE-2024-45256, CVE-2024-45257)
CVSS 9.8
Cyberpanel < 2.3.8 - OS Command Injection
CVSS 10.0
Splunk Enterprise <9.0.7-9.1.2 - RCE
CVSS 8.0
stamparm/maltrail <=0.54 - Command Injection
GeoServer WMS GetMap XXE Arbitrary File Read
CVSS 8.2
WordPress Photo Gallery Plugin SQL Injection (CVE-2022-0169)
CVSS 9.8
WordPress Depicter Plugin SQL Injection (CVE-2025-2011)
CVSS 7.5
Gladinet CentreStack < 16.4.10315.56368 Use of Hard-coded Key Leads to Unauthenticated RCE
CVSS 9.0
WordPress WP Time Capsule Arbitrary File Upload to RCE
CVSS 9.8
WordPress AI Engine Plugin MCP Unauthenticated Admin Creation to RCE
CVSS 9.8
Hashthemes Hash Form < 1.1.1 - Unrestricted File Upload
CVSS 9.8
User Registration & Membership <= 4.1.1 - Unauthenticated Privilege Escalation
CVSS 8.1
WordPress Royal Elementor Addons RCE
CVSS 9.8
Flowise < 3.0.1 - Missing Authorization
CVSS 9.8
Unauthenticated Remote Code Execution - Bricks <= 1.9.6
CVSS 10.0
WWBN AVideo <14.2 - RCE
CVSS 9.8
Wing FTP Server NULL-byte Authentication Bypass (CVE-2025-47812)
CVSS 10.0
AVideo <20.1 - RCE
Monstaftp Monsta FTP < 2.11 - Unrestricted File Upload
CVSS 9.8
SPIP <3.0.12 - RCE
SPIP <4.3.2-4.1.18 - Command Injection
CVSS 9.8
SPIP - RCE
CVSS 9.8
Flowise < 3.0.6 - Code Injection
CVSS 10.0