Skip to content
Noroxi

Bonds (Patchstack Alliance)

17 credited records · 0 in the last 12 months · 0 in CISA KEV

Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.

Credited records

Researchers
  • WordPress Hillter theme <= 3.0.7 - PHP Object Injection Vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    awethemes · hillterJul 16, 2025

  • WordPress PrivateContent - Mail Actions plugin <= 2.3.2 - Local File Inclusion vulnerability

    HighCVSS 7.5No exploitEPSS 1%

    lcweb · privatecontent - mail actionsJul 4, 2025

  • WordPress School Management System Plugin <= 92.0.0 - Reflected Cross Site Scripting (XSS) vulnerability

    HighCVSS 7.1No exploitEPSS 0%

    mojoomla · school managementJun 27, 2025

  • WordPress Smart Notification Plugin <= 10.3 - Reflected Cross Site Scripting (XSS) vulnerability

    HighCVSS 7.1No exploitEPSS 0%

    smartiolabs · smart notificationJun 27, 2025

  • WordPress School Management System Plugin <= 92.0.0 - SQL Injection vulnerability

    CriticalCVSS 9.3No exploitEPSS 0%

    mojoomla · school managementJun 17, 2025

  • WordPress Smart Notification Plugin <= 10.3 - SQL Injection vulnerability

    CriticalCVSS 9.3No exploitEPSS 0%

    smartiolabs · smart notificationJun 17, 2025

  • WordPress JobHunt Job Alerts <= 3.6 - Arbitrary Content Deletion Vulnerability

    HighCVSS 8.2No exploitEPSS 0%

    chimpstudio · jobhunt job alertsMay 23, 2025

  • WordPress Smart Sections Theme Builder - WPBakery Page Builder Addon plugin <= 1.7.8 - PHP Object Injection vulnerability

    CriticalCVSS 9.8No exploitEPSS 0%

    themegusta · smart sections theme builder - wpbakery page builder addonMay 19, 2025

  • WordPress WordPress Video Robot - The Ultimate Video Importer plugin <= 1.20.0 - Reflected Cross Site Scripting (XSS) vulnerability

    HighCVSS 7.1No exploitEPSS 0%

    pressaholic · wordpress video robot - the ultimate video importerMay 19, 2025

  • WordPress WHMpress plugin <= 6.2-revision-9 - Local File Inclusion vulnerability

    HighCVSS 7.5No exploitEPSS 0%

    whmpress · whmpressMay 16, 2025

  • WordPress WHMpress plugin <= 6.2-revision-9 - Local File Inclusion vulnerability

    HighCVSS 8.1No exploitEPSS 0%

    whmpress · whmpressMay 16, 2025

  • WordPress WPGYM Plugin <= 65.0 - SQL Injection vulnerability

    CriticalCVSS 9.3No exploitEPSS 0%

    mojoomla · wpgymMay 16, 2025

  • WordPress Global Gallery plugin <= 8.8.0 - Reflected Cross Site Scripting (XSS) vulnerability

    HighCVSS 7.1No exploitEPSS 0%

    notfound · global galleryApr 15, 2025

  • WordPress Hero Menu plugin <= 1.16.5 - SQL Injection vulnerability

    HighCVSS 8.5No exploitEPSS 0%

    notfound · hero mega menu - responsive wordpress menu pluginJan 21, 2025

  • WordPress Hero Menu plugin <= 1.16.5 - SQL Injection vulnerability

    HighCVSS 8.5No exploitEPSS 0%

    notfound · hero mega menu - responsive wordpress menu pluginJan 21, 2025

  • WordPress Hero Menu plugin <= 1.16.5 - Cross Site Scripting (XSS) vulnerability

    HighCVSS 7.1No exploitEPSS 0%

    notfound · hero mega menu - responsive wordpress menu pluginJan 21, 2025

  • WordPress WP Video Robot plugin <= 1.20.0 - SQL Injection vulnerability

    CriticalCVSS 9.8No exploitEPSS 0%

    pressaholic · wordpress video robotNov 18, 2024