Skip to content
Noroxi

Hackrate

6 credited records · 6 in the last 12 months · 0 in CISA KEV

Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.

Credited records

Researchers
  • Low-privilege RCE through element-search eager loading

    HighCVSS 8.7No exploitEPSS 1%

    craftcms · cmsSep 10, 2026

  • Authenticated SQL Injection via nested eager-loading criteria

    HighCVSS 7.1No exploitEPSS 1%

    craftcms · cmsSep 2, 2026

  • GQL entry mutation `siteId` bypasses schema site scope, enabling cross-site content read/write/delete

    HighCVSS 8.7No exploitEPSS 0%

    craftcms · cmsSep 2, 2026

  • Arbitrary user password reset leading to administrator account takeover

    HighCVSS 8.7No exploitEPSS 0%

    craftcms · cmsSep 2, 2026

  • Authenticated RCE through Twig sandbox escape

    HighCVSS 8.7No exploitEPSS 0%

    craftcms · cmsAug 27, 2026

  • Authenticated RCE via `condition.config` JSON cleanse bypass

    HighCVSS 8.7No exploitEPSS 1%

    craftcms · cmsAug 24, 2026