Skip to content
Noroxi

ifoundbug

16 credited records · 12 in the last 12 months · 0 in CISA KEV

Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.

Credited records

Researchers
  • CVE-2026-2144
    32Monitor

    Magic Login Mail or QR Code <= 2.05 - Unauthenticated Privilege Escalation via Insecure QR Code File Storage

    HighCVSS 8.1No exploitEPSS 0%

    katsushi-kawamori · magic login mail or qr codeFeb 14, 2026

  • ShareThis Dashboard for Google Analytics <= 3.2.4 - Unauthenticated Google Analytics Data Exposure

    MediumCVSS 4.7No exploitEPSS 0%

    sharethis · sharethis dashboard for google analyticsJan 7, 2026

  • URL Shortener Plugin For WordPress <= 3.0.7 - Unauthenticated SQL Injection

    CriticalCVSS 9.8No exploitEPSS 0%

    rupok98 · url shortener plugin for wordpressDec 13, 2025

  • ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Unauthenticated Arbitrary File Upload

    CriticalCVSS 9.8No exploitEPSS 1%

    elula · wsdeskNov 21, 2025

  • File Manager for Google Drive – Integrate Google Drive with WordPress <= 1.5.3 - Unauthenticated Sensitive Information Exposure

    HighCVSS 7.5Proof of conceptEPSS 2%

    princeahmed · file manager for google drive – integrate google driveNov 5, 2025

  • Community Events <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting

    HighCVSS 7.2No exploitEPSS 0%

    jackdewey · community eventsNov 1, 2025

  • URL Shortener Plugin For WordPress <= 3.0.7 - Missing Authorization to Authenticated (Subscriber+) Link Manipulation

    MediumCVSS 6.3No exploitEPSS 0%

    rupok98 · url shortener plugin for wordpressOct 24, 2025

  • DocoDoco Store Locator <= 1.0.1 - Authenticated (Editor+) Arbitrary File Upload

    HighCVSS 7.2No exploitEPSS 1%

    geolocationtechnology · docodoco store locatorOct 15, 2025

  • Find And Replace content for WordPress <= 1.1 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting

    HighCVSS 7.2No exploitEPSS 0%

    jankimoradiya · find and replace content for wordpressOct 15, 2025

  • Community Events <= 1.5.1 - Unauthenticated SQL Injection

    CriticalCVSS 9.8No exploitEPSS 1%

    jackdewey · community eventsOct 8, 2025

  • RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.6.2 - Authenticated (Administrator+) SQL Injection

    HighCVSS 7.2No exploitEPSS 0%

    metagauss · registrationmagic – custom registration forms, user registration, payment, and user loginOct 8, 2025

  • Community Events <= 1.5.1 - Unauthenticated SQL Injection

    CriticalCVSS 9.8No exploitEPSS 0%

    jackdewey · community eventsOct 8, 2025

  • CVE-2025-9985
    25Monitor

    Featured Image from URL (FIFU) <= 5.2.7 - Unauthenticated Information Exposure via Log File

    MediumCVSS 5.3Proof of conceptEPSS 12%

    marceljm · featured image from url (fifu)Sep 26, 2025

  • CVE-2025-9984
    21Monitor

    Featured Image from URL (FIFU) <= 5.2.7 - Missing Authorization to Password Protected Post Disclosure

    MediumCVSS 5.3No exploitEPSS 0%

    marceljm · featured image from url (fifu)Sep 26, 2025

  • Featured Image from URL (FIFU) <= 5.2.7 - Authenticated (Admin+) SQL Injection

    MediumCVSS 4.9No exploitEPSS 0%

    marceljm · featured image from url (fifu)Sep 26, 2025

  • Featured Image from URL (FIFU) <= 5.2.7 - Authenticated (Admin+) SQL Injection

    MediumCVSS 4.9No exploitEPSS 0%

    marceljm · featured image from url (fifu)Sep 26, 2025