d3kc4rt1
5 exploits
Active since Jan 2026
IndieWeb plugin for WordPress <4.0.5 - XSS
CVSS 6.4
MyRewards for WooCommerce - Missing Authorization in Ajax Function
CVSS 6.5
Tutor LMS - IDOR
CVSS 8.1
EventPrime WordPress Plugin <4.2.8.4 - Unauthenticated File Upload
CVSS 5.3
Contact List <= 3.0.18 - Authenticated (Contributor+) Stored Cross-Site Scripting via '_cl_map_iframe' Parameter
CVSS 6.4