Skip to content
Noroxi

devploit

Patchstack Bug Bounty Program

3 credited records · 3 in the last 12 months · 0 in CISA KEV

Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.

Credited records

Researchers
  • PixMagix <= 1.7.2 - Authenticated (Author+) Path Traversal in 'layers[].id' Parameter

    MediumCVSS 6.5No exploitEPSS 1%

    andrasweb · pixmagix – wordpress image editorJun 30, 2026

  • WordPress Simply Schedule Appointments plugin <= 1.6.10.6 - Cross Site Scripting (XSS) vulnerability

    HighCVSS 7.1No exploitEPSS 0%

    nsquared · simply schedule appointmentsJun 15, 2026

  • WordPress Checkout Files Upload for WooCommerce plugin <= 2.2.5 - Insecure Direct Object References (IDOR) vulnerability

    MediumCVSS 6.5No exploitEPSS 0%

    wp wham · checkout files upload for woocommerceMay 27, 2026