LevinityCyber
Patchstack Bug Bounty Program
5 credited records · 5 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
17Monitor | CVE-2026-84027No exploit | Directorist 8.9.1 - 8.9.4 - Subscriber+ Paid Order and Payment Record Forgery via REST Orders Endpointunknown · directorist: ai-powered business directory, listings & classified ads · CWE-862 | Medium4.3 | — | 0.2% | Sep 23, 2026 |
26Monitor | CVE-2026-62110No exploit | WordPress Bold Page Builder plugin <= 5.9.9 - Cross Site Scripting (XSS) vulnerabilityboldthemes · bold page builder · CWE-79 | Medium6.5 | — | 0.2% | Sep 11, 2026 |
30Monitor | CVE-2026-78268No exploit | WordPress Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads plugin <= 1.2.0 - Sensitive Data Exposure vulnerabilextend themes · lead generation contact widget & ai chatbot: chat button, phone call, telegram, email – siteleads · CWE-497 | High7.5 | — | 0.4% | Aug 24, 2026 |
28Monitor | CVE-2026-65565No exploit | WordPress Survey Maker plugin <= 5.2.3.3 - Cross Site Scripting (XSS) vulnerabilityays pro · survey maker · CWE-79 | High7.1 | — | 0.3% | Aug 6, 2026 |
21Monitor | CVE-2026-15252No exploit | Search Atlas SEO < 2.6.12 - Subscriber+ Google Indexing API Accessunknown · search atlas seo · CWE-862 | Medium5.4 | — | 0.3% | Jul 30, 2026 |
- CVE-2026-8402717Monitor
Directorist 8.9.1 - 8.9.4 - Subscriber+ Paid Order and Payment Record Forgery via REST Orders Endpoint
MediumCVSS 4.3No exploitEPSS 0%unknown · directorist: ai-powered business directory, listings & classified adsSep 23, 2026
- CVE-2026-6211026Monitor
WordPress Bold Page Builder plugin <= 5.9.9 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 6.5No exploitEPSS 0%boldthemes · bold page builderSep 11, 2026
- CVE-2026-7826830Monitor
WordPress Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads plugin <= 1.2.0 - Sensitive Data Exposure vulnerabil
HighCVSS 7.5No exploitEPSS 0%extend themes · lead generation contact widget & ai chatbot: chat button, phone call, telegram, email – siteleadsAug 24, 2026
- CVE-2026-6556528Monitor
WordPress Survey Maker plugin <= 5.2.3.3 - Cross Site Scripting (XSS) vulnerability
HighCVSS 7.1No exploitEPSS 0%ays pro · survey makerAug 6, 2026
- CVE-2026-1525221Monitor
Search Atlas SEO < 2.6.12 - Subscriber+ Google Indexing API Access
MediumCVSS 5.4No exploitEPSS 0%unknown · search atlas seoJul 30, 2026