SECURITY RESEARCH ARCHIVE

Vulnerability Research & Analysis

Source-to-sink root cause analyses, CVE disclosures, deserialization gadget chains, and exploit mechanics.

Showing 15 publication(s)Clear filter ✕
CVE-2026-40478critical
2026-06-046 min read

CVE-2026-40478 Thymeleaf Template Injection: From Sandbox Bypass to Unauthenticated RCE

# CVE-2026-40478 Thymeleaf Template Injection: From Sandbox Bypass to Unauthenticated RCE ![image](https://hackmd.io/uploads/BkLrCXJZzg.png) ## Overview ...

CVE-2026-3359critical
2026-05-166 min read

CVE-2026-3359 WordPress Form Maker by 10Web Plugin <= 1.15.42 is vulnerable to a high priority SQL Injection

# Critical SQL Injection (CVE-2026-3359) in WordPress Form Maker by 10Web ![image](https://hackmd.io/uploads/rJC0RXuRbg.png) ## Overview Published: ...

CVE-2026-2628critical
2026-05-038 min read

CVE-2026-2628 WordPress All-in-One Microsoft 365 &amp; Entra ID / Azure AD SSO Login Plugin <= 2.2.5 is vulnerable to a high priority Bypass Vulnerability

# WordPress All-in-One Microsoft 365 &amp; Entra ID / Azure AD SSO Login Plugin <= 2.2.5 is vulnerable to a high priority Bypass Vulnerability ![image](https...

CVE-2026-2942critical
2026-04-126 min read

CVE-2026-2942 WordPress ProSolution WP Client Plugin <= 1.9.9 is vulnerable to a high priority Arbitrary File Upload

## CVE-2026-2942 WordPress ProSolution WP Client Plugin <= 1.9.9 is vulnerable to a high priority Arbitrary File Upload ![image](https://hackmd.io/uploads/H1...

CVE-2026-3658high
2026-04-127 min read

CVE-2026-3658 WordPress Simply Schedule Appointments Plugin <= 1.6.10.0 is vulnerable to a high priority SQL Injection

## CVE-2026-3658 WordPress Simply Schedule Appointments Plugin <= 1.6.10.0 is vulnerable to a high priority SQL Injection ![image](https://hackmd.io/uploads/...

CVE-2026-1581high
2025-12-306 min read

CVE-2026-1581 WordPress wpForo Forum Plugin is vulnerable to a high priority SQL Injection

# CVE-2026-1581 WordPress wpForo Forum Plugin is vulnerable to a high priority SQL Injection ![image](https://hackmd.io/uploads/BJipTiSdbe.png) ## Overvie...

CVE-2026-0702high
2025-12-296 min read

CVE-2026-0702 WordPress VidShop Plugin <= 1.1.4 is vulnerable to a high priority SQL Injection

# CVE-2026-0702 WordPress VidShop Plugin <= 1.1.4 is vulnerable to a high priority SQL Injection ![image](https://hackmd.io/uploads/rkhOvm9vWg.png) # VidS...

CVE-2026-23550critical
2025-12-289 min read

CVE-2026-23550 WordPress Modular DS Plugin <= 2.5.1 is vulnerable to a high priority Privilege Escalation

# CVE-2026-23550 WordPress Modular DS Plugin <= 2.5.1 is vulnerable to a high priority Privilege Escalation ![image](https://hackmd.io/uploads/HyLArhXPZg.png...

CVE-2026-3459high
2025-12-279 min read

CVE-2026-3459 WordPress Drag and Drop Multiple File Upload – Contact Form 7 Plugin <= 1.3.9.5 is vulnerable to a high priority Arbitrary File Upload

## CVE-2026-3459 WordPress Drag and Drop Multiple File Upload – Contact Form 7 Plugin <= 1.3.9.5 is vulnerable to a high priority Arbitrary File Upload ![ima...

CVE-2026-2511high
2025-12-265 min read

CVE-2026-2511 WordPress JS Help Desk Plugin <= 3.0.4 is vulnerable to a high priority SQL Injection

# CVE-2026-2511 JS Help Desk – AI-Powered Support & Ticketing System <= 3.0.4 - Unauthenticated SQL Injection via 'multiformid' Parameter ![image](https://ha...

CVE-2026-2232
2025-12-256 min read

CVE-2026-2232 Product Table and List Builder for WooCommerce Lite Vulnerable To Unauthenticated Time-Based SQL Injection

# CVE-2026-2232 Product Table and List Builder for WooCommerce Lite Vulnerable To Unauthenticated Time-Based SQL Injection via 'search' Parameter ![image](ht...

CVE-2025-7340critical
2025-12-249 min read

WordPress HT Contact Form 7 Plugin <= 2.2.1 is vulnerable to a high priority Arbitrary File Upload

# WordPress HT Contact Form 7 Plugin <= 2.2.1 is vulnerable to a high priority Arbitrary File Upload ![image](https://hackmd.io/uploads/HJ5TohCu-g.png) ##...

CVE-2025-13329
2025-12-236 min read

CVE-2025-13329 File Uploader for WooCommerce

# CVE-2025-13329 File Uploader for WooCommerce <= 1.0.3 - Unauthenticated Arbitrary File Upload via add-image-data ![image](https://hackmd.io/uploads/SJGvzVA...

CVE-2025-68519
2025-12-225 min read

CVE-2025-68519 WordPress Brands for WooCommerce Plugin

# CVE-2025-68519 WordPress Brands for WooCommerce Plugin <= 3.8.6.3 is vulnerable to SQL Injection ![image](https://hackmd.io/uploads/ByI6-ltIbg.png) # Wo...

CVE-2025-14770
2025-12-2110 min read

CVE-2025-14770 – Unauthenticated SQL Injection via “city” Parameter

![image](https://hackmd.io/uploads/r1isJ3HLZl.png) # WordPress Shipping Rate By Cities Plugin ## Overview - CVE ID: CVE-2025-14770 - Affected Plugin: ...

Phat Mai — Security Researcher & Pentester