Skip to content
Noroxi

skeletonsec

20 credited records · 20 in the last 12 months · 0 in CISA KEV

Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.

Credited records

Researchers
  • Froxlor before 2.3.12 Arbitrary File Deletion via Symlink

    HighCVSS 8.5No exploitEPSS 0%

    froxlor · froxlor4 days ago

  • froxlor before 2.3.12 Authentication Bypass via Session Persistence

    HighCVSS 8.7No exploitEPSS 0%

    froxlor · froxlor4 days ago

  • Froxlor before 2.3.12 Privilege Escalation via Symlink

    CriticalCVSS 9.4No exploitEPSS 0%

    froxlor · froxlor4 days ago

  • Froxlor before 2.3.12 Command Injection via letsencryptchallengepath

    CriticalCVSS 9.4No exploitEPSS 1%

    froxlor · froxlor4 days ago

  • Froxlor before 2.3.12 Privilege Escalation via SSH Key Sync

    HighCVSS 7.1No exploitEPSS 0%

    froxlor · froxlor4 days ago

  • froxlor before 2.3.12 Two-Factor Authentication Bypass via CSRF

    HighCVSS 7.1No exploitEPSS 0%

    froxlor · froxlor4 days ago

  • Grav before 2.0.20 Cross-Site Scripting via Assets Sandbox

    MediumCVSS 5.1No exploitEPSS 0%

    getgrav · gravSep 5, 2026

  • phpMyFAQ before 4.1.8 Authentication Bypass via Unverified Password Change

    HighCVSS 7.1No exploitEPSS 1%

    thorsten · phpmyfaqSep 4, 2026

  • phpMyFAQ before 4.1.8 Authentication Bypass via Two-Factor Disable

    HighCVSS 7.1No exploitEPSS 1%

    thorsten · phpmyfaqSep 4, 2026

  • phpMyFAQ before 4.2.0-alpha.2 Missing Authorization via Dashboard API

    MediumCVSS 5.3No exploitEPSS 0%

    thorsten · phpmyfaqSep 4, 2026

  • phpMyFAQ before 4.1.8 TOTP Secret Exposure via Data Export

    MediumCVSS 5.3No exploitEPSS 1%

    thorsten · phpmyfaqSep 4, 2026

  • phpMyFAQ before 4.1.8 Incorrect Authorization via Admin Pages

    MediumCVSS 5.3No exploitEPSS 0%

    thorsten · phpmyfaqSep 4, 2026

  • phpMyFAQ before 4.1.8 CAPTCHA Bypass via store parameter

    MediumCVSS 6.9No exploitEPSS 0%

    thorsten · phpmyfaqSep 4, 2026

  • WWBN AVideo through 30.0 Information Disclosure via MobileManager

    MediumCVSS 6.9No exploitEPSS 0%

    wwbn · avideoSep 1, 2026

  • filebrowser 2.24.0 Race Condition via TUS concurrent PATCH uploads

    LowCVSS 2.3No exploitEPSS 0%

    filebrowser · filebrowserAug 28, 2026

  • File Browser 2.63.6 through 2.63.23 Share Link Exposure via File Deletion

    LowCVSS 2.3No exploitEPSS 0%

    filebrowser · filebrowserAug 28, 2026

  • filebrowser through 2.63.23 Stale Share Link via File Rename

    LowCVSS 2.3No exploitEPSS 0%

    filebrowser · filebrowserAug 28, 2026

  • filebrowser through 2.63.23 Denial of Service via named pipes

    HighCVSS 8.2No exploitEPSS 1%

    filebrowser · filebrowserAug 28, 2026

  • WWBN AVideo through 30.0 CSRF via myLiveControls.save.json.php

    MediumCVSS 5.1No exploitEPSS 0%

    wwbn · avideoAug 28, 2026

  • WWBN AVideo through 30.0 Information Disclosure via report4.json.php

    MediumCVSS 6.9No exploitEPSS 1%

    wwbn · avideoAug 28, 2026