Hackrate
6 credited records · 6 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
34Monitor | CVE-2026-79987No exploit | Low-privilege RCE through element-search eager loadingcraftcms · cms · CWE-470 | High8.7 | — | 0.6% | Sep 10, 2026 |
28Monitor | CVE-2026-79991No exploit | Authenticated SQL Injection via nested eager-loading criteriacraftcms · cms · CWE-89 | High7.1 | — | 0.5% | Sep 2, 2026 |
34Monitor | CVE-2026-79990No exploit | GQL entry mutation `siteId` bypasses schema site scope, enabling cross-site content read/write/deletecraftcms · cms · CWE-639 | High8.7 | — | 0.4% | Sep 2, 2026 |
34Monitor | CVE-2026-79989No exploit | Arbitrary user password reset leading to administrator account takeovercraftcms · cms · CWE-285 | High8.7 | — | 0.4% | Sep 2, 2026 |
34Monitor | CVE-2026-79988No exploit | Authenticated RCE through Twig sandbox escapecraftcms · cms · CWE-693 | High8.7 | — | 0.5% | Aug 27, 2026 |
34Monitor | CVE-2026-78416No exploit | Authenticated RCE via `condition.config` JSON cleanse bypasscraftcms · cms · CWE-915 | High8.7 | — | 1.0% | Aug 24, 2026 |
- CVE-2026-7998734Monitor
Low-privilege RCE through element-search eager loading
HighCVSS 8.7No exploitEPSS 1%craftcms · cmsSep 10, 2026
- CVE-2026-7999128Monitor
Authenticated SQL Injection via nested eager-loading criteria
HighCVSS 7.1No exploitEPSS 1%craftcms · cmsSep 2, 2026
- CVE-2026-7999034Monitor
GQL entry mutation `siteId` bypasses schema site scope, enabling cross-site content read/write/delete
HighCVSS 8.7No exploitEPSS 0%craftcms · cmsSep 2, 2026
- CVE-2026-7998934Monitor
Arbitrary user password reset leading to administrator account takeover
HighCVSS 8.7No exploitEPSS 0%craftcms · cmsSep 2, 2026
- CVE-2026-7998834Monitor
Authenticated RCE through Twig sandbox escape
HighCVSS 8.7No exploitEPSS 0%craftcms · cmsAug 27, 2026
- CVE-2026-7841634Monitor
Authenticated RCE via `condition.config` JSON cleanse bypass
HighCVSS 8.7No exploitEPSS 1%craftcms · cmsAug 24, 2026