lorenzocamilli
4 exploits
Active since Oct 2025
Automad Broken Access Control: unauthenticated exposure of administrator bcrypt password hashes and TOTP secrets via public API endpoint
CVSS 7.5
WP Private Content Plus <3.6.2 - Auth Bypass
CVSS 6.5
Contest Gallery <= 28.0.0 - Cross-Site Request Forgery
CVSS 4.3
WP Private Content Plus <3.6.2 - Auth Bypass
CVSS 6.5