devploit
Patchstack Bug Bounty Program
3 credited records · 3 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
26Monitor | CVE-2026-11367No exploit | PixMagix <= 1.7.2 - Authenticated (Author+) Path Traversal in 'layers[].id' Parameterandrasweb · pixmagix – wordpress image editor · CWE-22 | Medium6.5 | — | 0.8% | Jun 30, 2026 |
28Monitor | CVE-2026-39447No exploit | WordPress Simply Schedule Appointments plugin <= 1.6.10.6 - Cross Site Scripting (XSS) vulnerabilitynsquared · simply schedule appointments · CWE-79 | High7.1 | — | 0.3% | Jun 15, 2026 |
26Monitor | CVE-2026-42725No exploit | WordPress Checkout Files Upload for WooCommerce plugin <= 2.2.5 - Insecure Direct Object References (IDOR) vulnerabilitywp wham · checkout files upload for woocommerce · CWE-639 | Medium6.5 | — | 0.4% | May 27, 2026 |
- CVE-2026-1136726Monitor
PixMagix <= 1.7.2 - Authenticated (Author+) Path Traversal in 'layers[].id' Parameter
MediumCVSS 6.5No exploitEPSS 1%andrasweb · pixmagix – wordpress image editorJun 30, 2026
- CVE-2026-3944728Monitor
WordPress Simply Schedule Appointments plugin <= 1.6.10.6 - Cross Site Scripting (XSS) vulnerability
HighCVSS 7.1No exploitEPSS 0%nsquared · simply schedule appointmentsJun 15, 2026
- CVE-2026-4272526Monitor
WordPress Checkout Files Upload for WooCommerce plugin <= 2.2.5 - Insecure Direct Object References (IDOR) vulnerability
MediumCVSS 6.5No exploitEPSS 0%wp wham · checkout files upload for woocommerceMay 27, 2026