Fraudless
Patchstack Bug Bounty Program
2 credited records · 2 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
28Monitor | CVE-2026-16636No exploit | FluentSMTP <= 2.2.95 - Unauthenticated Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logswpmanageninja · fluentsmtp – wp smtp plugin with amazon ses, sendgrid, mailgun, postmark, cloudflare, tosend, gmail and any smtp · CWE-79 | High7.2 | — | 0.5% | Aug 6, 2026 |
26Monitor | CVE-2026-57316No exploit | WordPress GetGenie plugin <= 4.4.2 - Sensitive Data Exposure vulnerabilityroxnor · getgenie · CWE-497 | Medium6.5 | — | 0.4% | Jun 26, 2026 |
- CVE-2026-1663628Monitor
FluentSMTP <= 2.2.95 - Unauthenticated Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logs
HighCVSS 7.2No exploitEPSS 1%wpmanageninja · fluentsmtp – wp smtp plugin with amazon ses, sendgrid, mailgun, postmark, cloudflare, tosend, gmail and any smtpAug 6, 2026
- CVE-2026-5731626Monitor
WordPress GetGenie plugin <= 4.4.2 - Sensitive Data Exposure vulnerability
MediumCVSS 6.5No exploitEPSS 0%roxnor · getgenieJun 26, 2026