im-hanzou
14 exploits
Active since Oct 2021
Apache 2.4.49/2.4.50 Traversal RCE
WordPress MStore API <3.9.9 - Privilege Escalation
WooCommerce Payments < 4.8.2 and WooPayments < 5.6.2 - Unauthenticated Privilege Escalation via Request Forgery
User Post Gallery WP <2.19 - Code Injection
JobBoardWP < 1.2.2 - Unauthenticated Arbitrary File Upload
Fusion Builder < 3.6.2 - Server-Side Request Forgery via Unvalidated Form Parameter
Extensive VC Addons for WPBakery <1.9.1 - Info Disclosure
InPost Gallery <2.1.4.1 - Code Injection
WordPress Return Refund and Exchange for WooCommerce <4.0.9 - PHP File Upload
FormCraft WP <3.8.28 - Server-Side Request Forgery via URL Parameter
Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload via fetch_gravatar_from_remote
CVSS 9.8
alexusmai laravel-file-manager <3.3.1 - Authenticated RCE
CVSS 8.8
React Server Components <19.2.0 - RCE
CVSS 10.0
MongoDB Memory Disclosure (CVE-2025-14847) - Mongobleed
CVSS 7.5