crow
3 credited records · 3 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
30Monitor | CVE-2026-89294No exploit | Simply Schedule Appointments <= 1.6.12.27 - Authenticated (Subscriber+) Local File Inclusion via 'ssa_locale' Parametercroixhaug · simply schedule appointments · CWE-98 | High7.5 | — | — | Today |
21Monitor | CVE-2026-92799No exploit | Online Scheduling and Appointment Booking System <= 28.2 - Unauthenticated Authorization Bypass via PHP Type Juggling via 'verification_code' Parameter Type Jugladela · online scheduling and appointment booking system – bookly · CWE-285 | Medium5.3 | — | 0.3% | 5 days ago |
32Monitor | CVE-2026-92969No exploit | HUSKY <= 1.4.4 - Unauthenticated Local File Inclusion via 'custom_tpl' Shortcode Attribute via 'woof_draw_products' AJAXrealmag777 · husky – products filter for woocommerce professional · CWE-98 | High8.1 | — | 0.7% | Sep 22, 2026 |
24Monitor | CVE-2026-89330No exploit | EmbedPress <= 4.6.5 - Reflected Cross-Site Scripting via 'hash' and 'unique' Parameterswpdevteam · embedpress – pdf embedder, 3d pdf flipbook, google reviews, youtube videos, upload & embed pdf documents · CWE-79 | Medium6.1 | — | 0.4% | Sep 18, 2026 |
- CVE-2026-8929430Monitor
Simply Schedule Appointments <= 1.6.12.27 - Authenticated (Subscriber+) Local File Inclusion via 'ssa_locale' Parameter
HighCVSS 7.5No exploitcroixhaug · simply schedule appointmentsToday
- CVE-2026-9279921Monitor
Online Scheduling and Appointment Booking System <= 28.2 - Unauthenticated Authorization Bypass via PHP Type Juggling via 'verification_code' Parameter Type Jug
MediumCVSS 5.3No exploitEPSS 0%ladela · online scheduling and appointment booking system – bookly5 days ago
- CVE-2026-9296932Monitor
HUSKY <= 1.4.4 - Unauthenticated Local File Inclusion via 'custom_tpl' Shortcode Attribute via 'woof_draw_products' AJAX
HighCVSS 8.1No exploitEPSS 1%realmag777 · husky – products filter for woocommerce professionalSep 22, 2026
- CVE-2026-8933024Monitor
EmbedPress <= 4.6.5 - Reflected Cross-Site Scripting via 'hash' and 'unique' Parameters
MediumCVSS 6.1No exploitEPSS 0%wpdevteam · embedpress – pdf embedder, 3d pdf flipbook, google reviews, youtube videos, upload & embed pdf documentsSep 18, 2026