Disclosures

CVEs

8 identifiers assigned to vulnerabilities I reported, the highest scoring 10.0. Each one went to the vendor or a national CERT first and stayed private until a fix shipped.

  1. CVE-2026-34156

    NocoBase VM Sandbox Escape to RCE

    CVSS 10.0

    NocoBase v2.0.26

    VM sandbox escape through console prototype chain in Workflow Script Node. Authenticated attacker achieves RCE as root inside Docker containers: database credential theft, arbitrary file access, reverse shell.

  2. CVE-2026-9558

    Mautic SSTI via Twig Themes to RCE

    CVSS 9.9

    Mautic 5.2.10

    Server-side template injection through theme upload. Low-privilege Designer user with core:themes:create achieves remote code execution via unsandboxed Twig rendering.

  3. CVE-2025-60507

    Reflected & Stored XSS via PDF Upload

    CVSS 8.9

    Moodle GeniAI Plugin 2.3.6

    Teacher uploads PDF with embedded JavaScript. The assistant outputs an unsanitized HTML link, so the payload executes for any user who clicks it.

  4. CVE-2025-57520

    Stored XSS in Decap CMS

    CVSS 6.1

    Decap CMS 3.8.3 and earlier

    Contributor or editor injects payloads into title, tags, description and body fields. Fires when an admin opens the content preview, allowing session hijacking and arbitrary JS execution.

  5. CVE-2025-60506

    Stored XSS in Moodle PDF Annotator

    CVSS 5.4

    Moodle PDF Annotator v1.5r9

    Student-level attacker injects JavaScript via Public Comments. Payload fires when any user views the annotated PDF, which allows session hijacking and credential theft.

  6. CVE-2025-60511

    IDOR in Moodle OpenAI Chat Block

    CVSS 4.3

    Moodle OpenAI Chat Block 3.0.1

    Authenticated student impersonates another user (admin, teacher) and sends OpenAI queries using their configuration. API misuse and admin-data exposure.

  7. CVE-2026-3251

    Stored XSS

    High

    Stored cross-site scripting vulnerability. Reported through T.C. Siber Güvenlik Başkanlığı.

  8. CVE-2025-10228

    Session Fixation

    High

    Session fixation vulnerability. Reported through USOM.

Scores are NVD CVSS 3.1 base scores, not my own ratings. Entries without a number are still awaiting NVD analysis and carry the reporting CERT's severity instead.