Valentin Lobstein
108 exploits
Active since Nov 2013
Rejected
OttoKit < 1.0.83 - SureTriggers allows Privilege Escalation
CVSS 9.8
WordPress Really Simple SSL Plugin Authentication Bypass to RCE
CVSS 9.8
Lissy93/web-check < 2.0.1 - OS Command Injection via Screenshot API URL Parameter
vBulletin Template Conditionals - PHP Code Execution
CVSS 9.0
Advanced Custom Fields: Extended <0.9.1.1 - RCE
CVSS 9.8
Magento SessionReaper
CVSS 9.1
WordPress Automatic Plugin <= 3.92.0 - SQL Injection
CVSS 9.9
Flowise 3.0.5 - Remote Code Execution via CustomMCP Node Configuration Parsing
CVSS 10.0
SPIP porte_plume - Unauthenticated PHP Code Execution
CVSS 9.8
SPIP <4.3.2-4.1.18 - Command Injection
CVSS 9.8
SPIP < 3.0.12 - Remote Code Execution via Security Screen Connect Parameter
Monsta FTP < 2.11 - Unauthenticated Arbitrary File Upload
CVSS 9.8
AVideo 14.3.1-20.1 - Unauthenticated Remote Code Execution via Predictable Installation Salt
Wing FTP Server NULL-byte Authentication Bypass (CVE-2025-47812)
CVSS 10.0
WWBN AVideo 12.4-14.2 - Remote Code Execution via systemRootPath Parameter
CVSS 9.8
Unauthenticated Remote Code Execution - Bricks <= 1.9.6
CVSS 10.0
Flowise < 3.0.1 - Unauthenticated Remote Code Execution via Custom MCPs Feature
CVSS 9.8
WordPress Royal Elementor Addons RCE
CVSS 9.8
User Registration & Membership <= 4.1.1 - Unauthenticated Privilege Escalation
CVSS 8.1
Hash Form - Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload via file_upload_action Function
CVSS 9.8
Invisioncommunity < 5.0.7 - Remote Code Execution
CVSS 10.0
SPIP < 4.2.1 - Remote Code Execution via Form Value Deserialization
CVSS 9.8
Gladinet CentreStack < 16.4.10315.56368 Use of Hard-coded Key Leads to Unauthenticated RCE
CVSS 9.0
MajorDoMo < 2023-11-15 - Remote Code Execution via thumb.php Shell Metacharacters
CVSS 9.8