lukasz-rybak
29 exploits
Active since Nov 2025
Dolibarr: OS Command Injection (RCE) via MAIN_ODT_AS_PDF configuration
CVSS 9.1
October CMS: Twig Sandbox Bypass via Collection Methods
CVSS 4.9
XWiki Blog Application < 9.15.7 - Stored Cross-Site Scripting via Blog Post Title
CVSS 9.0
WBCE CMS < 1.6.5 - Brute-Force Protection Bypass via X-Forwarded-For Header
CVSS 8.1
ChurchCRM < 6.5.3 - Authenticated Privilege Escalation and Stored Cross-Site Scripting via Profile Injection
CVSS 5.4
ChurchCRM < 6.4.0 - Stored Cross-Site Scripting in Group Role Names
CVSS 5.4
ChurchCRM < 6.5.3 - Authenticated SQL Injection via Legacy Reports Endpoint
CVSS 8.8
OpenSTAManager < 2.9.8 - Authenticated OS Command Injection via P7M Filename
CVSS 8.8
OpenSTAManager <= 2.9.8 - Authenticated SQL Injection via idanagrafica Parameter
CVSS 8.8
OpenSTAManager < 2.9.8 - Authenticated SQL Injection via ajax_select.php Componenti Operation
CVSS 8.8
OpenSTAManager < 2.9.8 - SQL Injection in Stampe Module
CVSS 8.8
OpenSTAManager < 2.9.8 - Authenticated SQL Injection via Scadenzario id_anagrafica Parameter
CVSS 6.5
Omega-PSIR 4.5.9-4.6.7 - Reflected Cross-Site Scripting via Lang Parameter
CVSS 6.1
REDAXO < 5.20.2 - Authenticated Path Traversal via Backup Addon EXPDIR Parameter
CVSS 6.5
WBCE CMS < 1.6.4 - Privilege Escalation via groups[] Parameter Manipulation
CVSS 8.8
Saleor 3.0.0-3.20.107 - Stored Cross-Site Scripting via Rich Text HTML Injection
CVSS 4.8
InvoicePlane <=1.6.3 - Path Traversal
CVSS 7.5
Shopware 6.7.0.0-6.7.6.0 - Remote Code Execution via PHP Closure Allow List Bypass
CVSS 7.2
Saleor <3.20.108-3.22.27 - Code Injection
CVSS 5.4
OpenSTAManager < 2.9.8 - Reflected Cross-Site Scripting via Righe GET Parameter
CVSS 6.1
OpenSTAManager <2.9.8 - SQL Injection
CVSS 6.5
OpenSTAManager <2.9.8 - SQL Injection
CVSS 6.5
OpenSTAManager <2.9.8 - SQL Injection
CVSS 6.5
OpenSTAManager <2.9.8 - SQL Injection
CVSS 6.5
FacturaScripts < 2025.81 - Authenticated SQL Injection via REST API Sort Parameter
CVSS 8.8