Pascal SUN
4 credited records · 4 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
26Monitor | CVE-2026-6453No exploit | CubeWP Framework <= 1.1.30 - Authenticated (Subscriber+) SQL Injection via 'relation_id' Parametercubewp1211 · cubewp framework · CWE-89 | Medium6.5 | — | 0.5% | Aug 1, 2026 |
19Monitor | CVE-2026-10039No exploit | Frontend Admin by DynamiApps <= 3.28.28 - Authenticated (Administrator+) SQL Injection via 'order' Parametershabti · frontend admin by dynamiapps · CWE-89 | Medium4.9 | — | 0.3% | May 29, 2026 |
32Monitor | CVE-2026-6455No exploit | WP Contact Form 7 DB Handler <= 3.0 - Cross-Site Request Forgery to Arbitrary File Deletion via 'contact_form' Parameteryudiz · wp contact form 7 db handler · CWE-352 | High8.1 | — | 0.4% | May 28, 2026 |
24Monitor | CVE-2026-6203Proof of concept | User Registration & Membership <= 5.1.4 - Unauthenticated Open Redirect via 'redirect_to_on_logout' Parameterwpeverest · user registration & membership – free & paid memberships, subscriptions, content restriction, user profile, custom user registration & login builder · CWE-601 | Medium6.1 | — | 0.6% | Apr 13, 2026 |
- CVE-2026-645326Monitor
CubeWP Framework <= 1.1.30 - Authenticated (Subscriber+) SQL Injection via 'relation_id' Parameter
MediumCVSS 6.5No exploitEPSS 0%cubewp1211 · cubewp frameworkAug 1, 2026
- CVE-2026-1003919Monitor
Frontend Admin by DynamiApps <= 3.28.28 - Authenticated (Administrator+) SQL Injection via 'order' Parameter
MediumCVSS 4.9No exploitEPSS 0%shabti · frontend admin by dynamiappsMay 29, 2026
- CVE-2026-645532Monitor
WP Contact Form 7 DB Handler <= 3.0 - Cross-Site Request Forgery to Arbitrary File Deletion via 'contact_form' Parameter
HighCVSS 8.1No exploitEPSS 0%yudiz · wp contact form 7 db handlerMay 28, 2026
- CVE-2026-620324Monitor
User Registration & Membership <= 5.1.4 - Unauthenticated Open Redirect via 'redirect_to_on_logout' Parameter
MediumCVSS 6.1Proof of conceptEPSS 1%wpeverest · user registration & membership – free & paid memberships, subscriptions, content restriction, user profile, custom user registration & login builderApr 13, 2026