ifoundbug
16 credited records · 12 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
32Monitor | CVE-2026-2144No exploit | Magic Login Mail or QR Code <= 2.05 - Unauthenticated Privilege Escalation via Insecure QR Code File Storagekatsushi-kawamori · magic login mail or qr code · CWE-269 | High8.1 | — | 0.5% | Feb 14, 2026 |
18Monitor | CVE-2025-12540No exploit | ShareThis Dashboard for Google Analytics <= 3.2.4 - Unauthenticated Google Analytics Data Exposuresharethis · sharethis dashboard for google analytics · CWE-200 | Medium4.7 | — | 0.3% | Jan 7, 2026 |
39Monitor | CVE-2025-10738No exploit | URL Shortener Plugin For WordPress <= 3.0.7 - Unauthenticated SQL Injectionrupok98 · url shortener plugin for wordpress · CWE-89 | Critical9.8 | — | 0.4% | Dec 13, 2025 |
39Monitor | CVE-2025-11456No exploit | ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Unauthenticated Arbitrary File Uploadelula · wsdesk · CWE-434 | Critical9.8 | — | 0.7% | Nov 21, 2025 |
31Monitor | CVE-2025-12139Proof of concept | File Manager for Google Drive – Integrate Google Drive with WordPress <= 1.5.3 - Unauthenticated Sensitive Information Exposureprinceahmed · file manager for google drive – integrate google drive · CWE-200 | High7.5 | — | 2.3% | Nov 5, 2025 |
28Monitor | CVE-2025-11995No exploit | Community Events <= 1.5.2 - Unauthenticated Stored Cross-Site Scriptingjackdewey · community events · CWE-79 | High7.2 | — | 0.3% | Nov 1, 2025 |
25Monitor | CVE-2025-10740No exploit | URL Shortener Plugin For WordPress <= 3.0.7 - Missing Authorization to Authenticated (Subscriber+) Link Manipulationrupok98 · url shortener plugin for wordpress · CWE-89 | Medium6.3 | — | 0.3% | Oct 24, 2025 |
28Monitor | CVE-2025-10754No exploit | DocoDoco Store Locator <= 1.0.1 - Authenticated (Editor+) Arbitrary File Uploadgeolocationtechnology · docodoco store locator · CWE-434 | High7.2 | — | 0.7% | Oct 15, 2025 |
28Monitor | CVE-2025-10313No exploit | Find And Replace content for WordPress <= 1.1 - Missing Authorization to Unauthenticated Stored Cross-Site Scriptingjankimoradiya · find and replace content for wordpress · CWE-862 | High7.2 | — | 0.3% | Oct 15, 2025 |
39Monitor | CVE-2025-10586No exploit | Community Events <= 1.5.1 - Unauthenticated SQL Injectionjackdewey · community events · CWE-89 | Critical9.8 | — | 0.5% | Oct 8, 2025 |
28Monitor | CVE-2025-11204No exploit | RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.6.2 - Authenticated (Administrator+) SQL Injectionmetagauss · registrationmagic – custom registration forms, user registration, payment, and user login · CWE-89 | High7.2 | — | 0.4% | Oct 8, 2025 |
39Monitor | CVE-2025-10587No exploit | Community Events <= 1.5.1 - Unauthenticated SQL Injectionjackdewey · community events · CWE-89 | Critical9.8 | — | 0.4% | Oct 8, 2025 |
25Monitor | CVE-2025-9985Proof of concept | Featured Image from URL (FIFU) <= 5.2.7 - Unauthenticated Information Exposure via Log Filemarceljm · featured image from url (fifu) · CWE-532 | Medium5.3 | — | 11.7% | Sep 26, 2025 |
21Monitor | CVE-2025-9984No exploit | Featured Image from URL (FIFU) <= 5.2.7 - Missing Authorization to Password Protected Post Disclosuremarceljm · featured image from url (fifu) · CWE-862 | Medium5.3 | — | 0.3% | Sep 26, 2025 |
19Monitor | CVE-2025-10037No exploit | Featured Image from URL (FIFU) <= 5.2.7 - Authenticated (Admin+) SQL Injectionmarceljm · featured image from url (fifu) · CWE-89 | Medium4.9 | — | 0.3% | Sep 26, 2025 |
19Monitor | CVE-2025-10036No exploit | Featured Image from URL (FIFU) <= 5.2.7 - Authenticated (Admin+) SQL Injectionmarceljm · featured image from url (fifu) · CWE-89 | Medium4.9 | — | 0.3% | Sep 26, 2025 |
- CVE-2026-214432Monitor
Magic Login Mail or QR Code <= 2.05 - Unauthenticated Privilege Escalation via Insecure QR Code File Storage
HighCVSS 8.1No exploitEPSS 0%katsushi-kawamori · magic login mail or qr codeFeb 14, 2026
- CVE-2025-1254018Monitor
ShareThis Dashboard for Google Analytics <= 3.2.4 - Unauthenticated Google Analytics Data Exposure
MediumCVSS 4.7No exploitEPSS 0%sharethis · sharethis dashboard for google analyticsJan 7, 2026
- CVE-2025-1073839Monitor
URL Shortener Plugin For WordPress <= 3.0.7 - Unauthenticated SQL Injection
CriticalCVSS 9.8No exploitEPSS 0%rupok98 · url shortener plugin for wordpressDec 13, 2025
- CVE-2025-1145639Monitor
ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Unauthenticated Arbitrary File Upload
CriticalCVSS 9.8No exploitEPSS 1%elula · wsdeskNov 21, 2025
- CVE-2025-1213931Monitor
File Manager for Google Drive – Integrate Google Drive with WordPress <= 1.5.3 - Unauthenticated Sensitive Information Exposure
HighCVSS 7.5Proof of conceptEPSS 2%princeahmed · file manager for google drive – integrate google driveNov 5, 2025
- CVE-2025-1199528Monitor
Community Events <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting
HighCVSS 7.2No exploitEPSS 0%jackdewey · community eventsNov 1, 2025
- CVE-2025-1074025Monitor
URL Shortener Plugin For WordPress <= 3.0.7 - Missing Authorization to Authenticated (Subscriber+) Link Manipulation
MediumCVSS 6.3No exploitEPSS 0%rupok98 · url shortener plugin for wordpressOct 24, 2025
- CVE-2025-1075428Monitor
DocoDoco Store Locator <= 1.0.1 - Authenticated (Editor+) Arbitrary File Upload
HighCVSS 7.2No exploitEPSS 1%geolocationtechnology · docodoco store locatorOct 15, 2025
- CVE-2025-1031328Monitor
Find And Replace content for WordPress <= 1.1 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting
HighCVSS 7.2No exploitEPSS 0%jankimoradiya · find and replace content for wordpressOct 15, 2025
- CVE-2025-1058639Monitor
Community Events <= 1.5.1 - Unauthenticated SQL Injection
CriticalCVSS 9.8No exploitEPSS 1%jackdewey · community eventsOct 8, 2025
- CVE-2025-1120428Monitor
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.6.2 - Authenticated (Administrator+) SQL Injection
HighCVSS 7.2No exploitEPSS 0%metagauss · registrationmagic – custom registration forms, user registration, payment, and user loginOct 8, 2025
- CVE-2025-1058739Monitor
Community Events <= 1.5.1 - Unauthenticated SQL Injection
CriticalCVSS 9.8No exploitEPSS 0%jackdewey · community eventsOct 8, 2025
- CVE-2025-998525Monitor
Featured Image from URL (FIFU) <= 5.2.7 - Unauthenticated Information Exposure via Log File
MediumCVSS 5.3Proof of conceptEPSS 12%marceljm · featured image from url (fifu)Sep 26, 2025
- CVE-2025-998421Monitor
Featured Image from URL (FIFU) <= 5.2.7 - Missing Authorization to Password Protected Post Disclosure
MediumCVSS 5.3No exploitEPSS 0%marceljm · featured image from url (fifu)Sep 26, 2025
- CVE-2025-1003719Monitor
Featured Image from URL (FIFU) <= 5.2.7 - Authenticated (Admin+) SQL Injection
MediumCVSS 4.9No exploitEPSS 0%marceljm · featured image from url (fifu)Sep 26, 2025
- CVE-2025-1003619Monitor
Featured Image from URL (FIFU) <= 5.2.7 - Authenticated (Admin+) SQL Injection
MediumCVSS 4.9No exploitEPSS 0%marceljm · featured image from url (fifu)Sep 26, 2025