aj2108
10 exploits
Active since May 2026
WP Ticket <= 6.0.4 - Unauthenticated SQL Injection via WordPress Search 's' Parameter
CVSS 7.5
Stored Cross-Site Scripting (XSS) in CTI Transmute Notification Panel via Malicious Convert Names
Mautic 7 - Authenticated Stored Cross-Site Scripting in Projects Component
CVSS 7.6
Mautic 7 - Authenticated Stored Cross-Site Scripting in Project Selector Component
CVSS 5.4
Tag Groups < 2.2.0 - Reflected XSS via 'tag_groups_task' Parameter
CVSS 7.1
Concrete CMS 9.5.0 and below is vulnerable to IDOR in '/ccm/frontend/conversations/get_rating'
CVSS 5.3
Concrete CMS 9.5.0 and below is vulnerable to IDOR in the`/ccm/frontend/conversations/message_detail` endpoint
CVSS 5.3
Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in Express association Reorder dialog
CVSS 4.3
Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys when sites are running concurrent public surveys and private surveys
CVSS 5.3
Concrete CMS 9.5.0 and below is vulnerable to IDOR + wrong-authorization-level in Express association Reorder dialog
CVSS 4.3