Bonds (Patchstack Alliance)
17 credited records · 0 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2025-24777No exploit | WordPress Hillter theme <= 3.0.7 - PHP Object Injection Vulnerabilityawethemes · hillter · CWE-502 | High8.8 | — | 0.5% | Jul 16, 2025 |
30Monitor | CVE-2025-47627No exploit | WordPress PrivateContent - Mail Actions plugin <= 2.3.2 - Local File Inclusion vulnerabilitylcweb · privatecontent - mail actions · CWE-98 | High7.5 | — | 0.6% | Jul 4, 2025 |
28Monitor | CVE-2025-47574No exploit | WordPress School Management System Plugin <= 92.0.0 - Reflected Cross Site Scripting (XSS) vulnerabilitymojoomla · school management · CWE-79 | High7.1 | — | 0.3% | Jun 27, 2025 |
28Monitor | CVE-2025-39478No exploit | WordPress Smart Notification Plugin <= 10.3 - Reflected Cross Site Scripting (XSS) vulnerabilitysmartiolabs · smart notification · CWE-79 | High7.1 | — | 0.3% | Jun 27, 2025 |
37Monitor | CVE-2025-47573No exploit | WordPress School Management System Plugin <= 92.0.0 - SQL Injection vulnerabilitymojoomla · school management · CWE-89 | Critical9.3 | — | 0.5% | Jun 17, 2025 |
37Monitor | CVE-2025-39479No exploit | WordPress Smart Notification Plugin <= 10.3 - SQL Injection vulnerabilitysmartiolabs · smart notification · CWE-89 | Critical9.3 | — | 0.4% | Jun 17, 2025 |
32Monitor | CVE-2025-39536No exploit | WordPress JobHunt Job Alerts <= 3.6 - Arbitrary Content Deletion Vulnerabilitychimpstudio · jobhunt job alerts · CWE-862 | High8.2 | — | 0.4% | May 23, 2025 |
39Monitor | CVE-2025-39410No exploit | WordPress Smart Sections Theme Builder - WPBakery Page Builder Addon plugin <= 1.7.8 - PHP Object Injection vulnerabilitythemegusta · smart sections theme builder - wpbakery page builder addon · CWE-502 | Critical9.8 | — | 0.5% | May 19, 2025 |
28Monitor | CVE-2025-39409No exploit | WordPress WordPress Video Robot - The Ultimate Video Importer plugin <= 1.20.0 - Reflected Cross Site Scripting (XSS) vulnerabilitypressaholic · wordpress video robot - the ultimate video importer · CWE-79 | High7.1 | — | 0.2% | May 19, 2025 |
30Monitor | CVE-2025-39492No exploit | WordPress WHMpress plugin <= 6.2-revision-9 - Local File Inclusion vulnerabilitywhmpress · whmpress · CWE-35 | High7.5 | — | 0.5% | May 16, 2025 |
32Monitor | CVE-2025-39491No exploit | WordPress WHMpress plugin <= 6.2-revision-9 - Local File Inclusion vulnerabilitywhmpress · whmpress · CWE-35 | High8.1 | — | 0.4% | May 16, 2025 |
37Monitor | CVE-2025-32643No exploit | WordPress WPGYM Plugin <= 65.0 - SQL Injection vulnerabilitymojoomla · wpgym · CWE-89 | Critical9.3 | — | 0.5% | May 16, 2025 |
28Monitor | CVE-2025-22263No exploit | WordPress Global Gallery plugin <= 8.8.0 - Reflected Cross Site Scripting (XSS) vulnerabilitynotfound · global gallery · CWE-79 | High7.1 | — | 0.3% | Apr 15, 2025 |
34Monitor | CVE-2024-49333No exploit | WordPress Hero Menu plugin <= 1.16.5 - SQL Injection vulnerabilitynotfound · hero mega menu - responsive wordpress menu plugin · CWE-89 | High8.5 | — | 0.4% | Jan 21, 2025 |
34Monitor | CVE-2024-49303No exploit | WordPress Hero Menu plugin <= 1.16.5 - SQL Injection vulnerabilitynotfound · hero mega menu - responsive wordpress menu plugin · CWE-89 | High8.5 | — | 0.4% | Jan 21, 2025 |
28Monitor | CVE-2024-49300No exploit | WordPress Hero Menu plugin <= 1.16.5 - Cross Site Scripting (XSS) vulnerabilitynotfound · hero mega menu - responsive wordpress menu plugin · CWE-79 | High7.1 | — | 0.3% | Jan 21, 2025 |
39Monitor | CVE-2024-52431No exploit | WordPress WP Video Robot plugin <= 1.20.0 - SQL Injection vulnerabilitypressaholic · wordpress video robot · CWE-89 | Critical9.8 | — | 0.5% | Nov 18, 2024 |
- CVE-2025-2477735Monitor
WordPress Hillter theme <= 3.0.7 - PHP Object Injection Vulnerability
HighCVSS 8.8No exploitEPSS 0%awethemes · hillterJul 16, 2025
- CVE-2025-4762730Monitor
WordPress PrivateContent - Mail Actions plugin <= 2.3.2 - Local File Inclusion vulnerability
HighCVSS 7.5No exploitEPSS 1%lcweb · privatecontent - mail actionsJul 4, 2025
- CVE-2025-4757428Monitor
WordPress School Management System Plugin <= 92.0.0 - Reflected Cross Site Scripting (XSS) vulnerability
HighCVSS 7.1No exploitEPSS 0%mojoomla · school managementJun 27, 2025
- CVE-2025-3947828Monitor
WordPress Smart Notification Plugin <= 10.3 - Reflected Cross Site Scripting (XSS) vulnerability
HighCVSS 7.1No exploitEPSS 0%smartiolabs · smart notificationJun 27, 2025
- CVE-2025-4757337Monitor
WordPress School Management System Plugin <= 92.0.0 - SQL Injection vulnerability
CriticalCVSS 9.3No exploitEPSS 0%mojoomla · school managementJun 17, 2025
- CVE-2025-3947937Monitor
WordPress Smart Notification Plugin <= 10.3 - SQL Injection vulnerability
CriticalCVSS 9.3No exploitEPSS 0%smartiolabs · smart notificationJun 17, 2025
- CVE-2025-3953632Monitor
WordPress JobHunt Job Alerts <= 3.6 - Arbitrary Content Deletion Vulnerability
HighCVSS 8.2No exploitEPSS 0%chimpstudio · jobhunt job alertsMay 23, 2025
- CVE-2025-3941039Monitor
WordPress Smart Sections Theme Builder - WPBakery Page Builder Addon plugin <= 1.7.8 - PHP Object Injection vulnerability
CriticalCVSS 9.8No exploitEPSS 0%themegusta · smart sections theme builder - wpbakery page builder addonMay 19, 2025
- CVE-2025-3940928Monitor
WordPress WordPress Video Robot - The Ultimate Video Importer plugin <= 1.20.0 - Reflected Cross Site Scripting (XSS) vulnerability
HighCVSS 7.1No exploitEPSS 0%pressaholic · wordpress video robot - the ultimate video importerMay 19, 2025
- CVE-2025-3949230Monitor
WordPress WHMpress plugin <= 6.2-revision-9 - Local File Inclusion vulnerability
HighCVSS 7.5No exploitEPSS 0%whmpress · whmpressMay 16, 2025
- CVE-2025-3949132Monitor
WordPress WHMpress plugin <= 6.2-revision-9 - Local File Inclusion vulnerability
HighCVSS 8.1No exploitEPSS 0%whmpress · whmpressMay 16, 2025
- CVE-2025-3264337Monitor
WordPress WPGYM Plugin <= 65.0 - SQL Injection vulnerability
CriticalCVSS 9.3No exploitEPSS 0%mojoomla · wpgymMay 16, 2025
- CVE-2025-2226328Monitor
WordPress Global Gallery plugin <= 8.8.0 - Reflected Cross Site Scripting (XSS) vulnerability
HighCVSS 7.1No exploitEPSS 0%notfound · global galleryApr 15, 2025
- CVE-2024-4933334Monitor
WordPress Hero Menu plugin <= 1.16.5 - SQL Injection vulnerability
HighCVSS 8.5No exploitEPSS 0%notfound · hero mega menu - responsive wordpress menu pluginJan 21, 2025
- CVE-2024-4930334Monitor
WordPress Hero Menu plugin <= 1.16.5 - SQL Injection vulnerability
HighCVSS 8.5No exploitEPSS 0%notfound · hero mega menu - responsive wordpress menu pluginJan 21, 2025
- CVE-2024-4930028Monitor
WordPress Hero Menu plugin <= 1.16.5 - Cross Site Scripting (XSS) vulnerability
HighCVSS 7.1No exploitEPSS 0%notfound · hero mega menu - responsive wordpress menu pluginJan 21, 2025
- CVE-2024-5243139Monitor
WordPress WP Video Robot plugin <= 1.20.0 - SQL Injection vulnerability
CriticalCVSS 9.8No exploitEPSS 0%pressaholic · wordpress video robotNov 18, 2024