brandonkelly
68 exploits
Active since May 2021
Craft CMS 3.0.0-3.8.5 and 4.0.0-RC1-4.4.5 - Stored Cross-Site Scripting in Quick Post Validation Error Message
CVSS 3.7
Craft CMS 4.3.0-4.4.5 - Cross-Site Scripting via Malformed RSS Feed
CVSS 5.0
Craft CMS 4.0.1-4.4.6 - Cross-Site Scripting via Review Volumes
CVSS 5.5
Craft CMS < 4.4.6 - Cross-Site Scripting via Update Asset Index Utility
CVSS 5.5
Craft CMS 5.0.0-5.1.1 - Stored Cross-Site Scripting in Breadcrumb List and Title Fields
CVSS 5.5
Craft CMS 4.0.0-4.12.1 - Remote Code Execution via Twig SSTI
CVSS 7.2
Craft CMS 4.0.0-4.13.7 and 5.0.0-RC1-5.5.7 - Remote Code Execution via Compromised Security Key
CVSS 8.0
Craft CMS 4.13.8-4.16.2 and 5.5.8-5.8.3 - Remote Code Execution via /updater/restore-db Endpoint
CVSS 8.8
Craft CMS 4.0.0-RC1-4.16.5 and 5.0.0-RC1-5.8.6 - Remote Code Execution via Twig SSTI
CVSS 7.2
Craft CMS 4.0.0.1-4.16.16 and 5.0.0-RC1-5.8.20 - Authenticated Sensitive Information Exposure via User Profile Photo
CVSS 6.5
Craft CMS 4.0.0.1-4.16.16 and 5.0.0-RC1-5.8.20 - Authenticated Remote Code Execution via Twig SSTI
CVSS 8.8
Craft CMS 3.0.0-4.16.16 and 5.0.0-RC1-5.8.20 - Unauthenticated Resource Exhaustion via Database Backup Trigger
CVSS 9.1
Craft CMS 3.5.0-4.16.17 & 5.0.0-RC1-5.8.21 - Server-Side Request Forgery via GraphQL
CVSS 6.5
Craft CMS saveAsset GraphQL - Redirect-Based Server-Side Request Forgery
CVSS 6.5
Craft CMS saveAsset GraphQL - Alternative IP Server-Side Request Forgery
CVSS 6.5
Craft CMS 4.0.0-4.16.17 and 5.0.0-RC1-5.8.21 - Authenticated SQL Injection via Element Index OrderBy Parameter
CVSS 8.8
Craft CMS GraphQL API - Cross-Volume Asset Privilege Escalation
CVSS 8.8
Craft CMS 4.0.0-4.16.17 and 5.0.0-RC1-5.8.21 - Authenticated Remote Code Execution via Behavior Configuration Injection
CVSS 7.2