Skip to content
Noroxi

Webbernaut

6 credited records · 4 in the last 12 months · 0 in CISA KEV

Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.

Credited records

Researchers
  • Smart Slider 3 <= 3.5.1.38 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-href' Attribute in Custom HTML Block

    MediumCVSS 6.4No exploit

    nextendweb · smart slider 3Today

  • CVE-2026-0551
    35Monitor

    PPWP – Password Protect Pages <= 1.9.18 - Authenticated (Contributor+) PHP Object Injection via post_protection_roles

    HighCVSS 8.8No exploitEPSS 1%

    buildwps · ppwp – password protect pagesAug 22, 2026

  • Ultra Addons for Contact Form 7 <= 3.5.43 - Authenticated (Contributor+) Stored Cross-Site Scripting via Slider Attributes

    MediumCVSS 6.4No exploitEPSS 0%

    themefic · ultra addons for contact form 7Aug 7, 2026

  • Motors <= 1.4.112 - Unauthenticated Stored Cross-Site Scripting via Comment Content and User Biographical Info

    HighCVSS 7.2No exploitEPSS 0%

    stylemix · motors – car dealership & classified listings pluginJul 11, 2026

  • Export User Data <= 2.2.6 - Authenticated (Subscriber+) PHP Object Injection to Arbitrary File Deletion via display_name Field

    HighCVSS 8.0No exploitEPSS 1%

    qlstudio · export user dataJun 30, 2026

  • CVE-2024-5647
    25Monitor

    Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library

    MediumCVSS 6.4No exploitEPSS 0%

    blossomthemes · blossomthemes social feedJul 3, 2025

  • CVE-2023-3372
    21Monitor

    Lana Shortcodes < 1.2.0 - Contributor+ Stored XSS

    MediumCVSS 5.4No exploitEPSS 0%

    lana · lana shortcodesJan 16, 2024