halilkirazkaya
45 exploits
Active since Sep 2019
Analytics Insights for Google Analytics 4 < 6.3 - Unauthenticated Open Redirect via oauth2callback.php
Travelpayouts WordPress plugin < 1.1.17 - Unauthenticated Open Redirect
WordPress Plugin <2.2.76 - Info Disclosure
Coda v.2024Q1 - Cross-Site Scripting
User Meta <= 3.0 - Exposure of Sensitive Information to an Unauthorized Actor
iboss Secure Web Gateway <10.1 - XSS
SuiteCRM <7.14.4-8.6.1 - SQL Injection
osCommerce 4 - Cross-Site Scripting via /catalog/all-products cat Parameter
PHP CGI Argument Injection Remote Code Execution
NetAlertX 24.7.18-24.10.12 - Unauthenticated Path Traversal and Arbitrary File Read via logs.php
EnvaySoft FleetCart <4.1.1 - Info Disclosure
SoftLab Radio Player <2.0.82 - SSRF
ChurchCRM < 5.13.0 - Time-Based Blind SQL Injection via EditEventTypes newCountName Parameter
WordPress AI Engine Plugin MCP Unauthenticated Admin Creation to RCE
langgenius/dify-web <1.6.0 - Info Disclosure
WPvivid Backup & Migration <0.9.123 - Unauthenticated RCE
Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload via fetch_gravatar_from_remote
Post SMTP < 3.6.0 - Unauthenticated Arbitrary Email Log Access via Missing Capability Check
Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload via fetch_gravatar_from_remote
CVSS 9.8
WPvivid Backup & Migration <0.9.123 - Unauthenticated RCE
CVSS 9.8