shinthink
28 exploits
Active since Apr 2025
CodeIgniter: Uploaded file extension validation bypass in is_image and mime_in rules
MediaTek Software Development Kit - Heap-based Buffer Overflow in WLAN AP Driver
Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing
Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0
Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2
Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12
CVSS 9.8
Remote Code Execution via Unsafe Deserialization in LogItem Import
CVSS 9.8
Blocksy Companion Pro < 2.1.47 Unauthenticated File Upload via save_attachments
CVSS 9.8
Blocksy Companion <= 2.1.46 - Unauthenticated Arbitrary File Upload via 'blc-review-images[]' Parameter
CVSS 9.8
Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1
WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
CVSS 9.8
WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query
CVSS 5.9
Super Forms <= 6.3.313 - Unauthenticated Arbitrary File Upload via 'data' Parameter (datauristring / value)
CVSS 9.8
Podlove Podcast Publisher <= 4.5.1 - Unauthenticated Arbitrary File Upload via podlove_image_cache_url Parameter
CVSS 9.8
Pix for WooCommerce <=1.5.0 - Arbitrary File Upload
CVSS 9.8
Moodle 4.5.0-4.5.2 - Unauthenticated Exposure of Sensitive User Data via API Stack Traces
CVSS 7.5
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
CVSS 9.8
Instant Appointment <= 1.2 - Unauthenticated Arbitrary File Upload
CVSS 9.8
JTL Shop < 5.7.2 Server-Side Template Injection via Smarty Renderer
CVSS 9.8
WordPress WP Maps plugin <= 4.9.1 - SQL Injection vulnerability
CVSS 9.3
Langflow < 1.8.0 - Remote Code Execution via CSV Agent Node
CVSS 9.8
Avada (Fusion) Builder <= 3.15.3 - Unauthenticated Arbitrary File Deletion via Form Entry Value
CVSS 9.1
WP User Manager <= 2.9.17 - Unauthenticated Path Traversal to Local File Inclusion via 'tab' Query Parameter
CVSS 7.5
Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15
CVSS 9.8
Joomla Extension - joomshaper.com - Unauthenticated access to Helix3 template ajax handler
CVSS 7.5