Disclosures
CVEs
8 identifiers assigned to vulnerabilities I reported, the highest scoring 10.0. Each one went to the vendor or a national CERT first and stayed private until a fix shipped.
- CVE-2026-34156CVSS 10.0
NocoBase VM Sandbox Escape to RCE
NocoBase v2.0.26
VM sandbox escape through console prototype chain in Workflow Script Node. Authenticated attacker achieves RCE as root inside Docker containers: database credential theft, arbitrary file access, reverse shell.
- CVE-2026-9558CVSS 9.9
Mautic SSTI via Twig Themes to RCE
Mautic 5.2.10
Server-side template injection through theme upload. Low-privilege Designer user with core:themes:create achieves remote code execution via unsandboxed Twig rendering.
- CVE-2025-60507CVSS 8.9
Reflected & Stored XSS via PDF Upload
Moodle GeniAI Plugin 2.3.6
Teacher uploads PDF with embedded JavaScript. The assistant outputs an unsanitized HTML link, so the payload executes for any user who clicks it.
- CVE-2025-57520CVSS 6.1
Stored XSS in Decap CMS
Decap CMS 3.8.3 and earlier
Contributor or editor injects payloads into title, tags, description and body fields. Fires when an admin opens the content preview, allowing session hijacking and arbitrary JS execution.
- CVE-2025-60506CVSS 5.4
Stored XSS in Moodle PDF Annotator
Moodle PDF Annotator v1.5r9
Student-level attacker injects JavaScript via Public Comments. Payload fires when any user views the annotated PDF, which allows session hijacking and credential theft.
- CVE-2025-60511CVSS 4.3
IDOR in Moodle OpenAI Chat Block
Moodle OpenAI Chat Block 3.0.1
Authenticated student impersonates another user (admin, teacher) and sends OpenAI queries using their configuration. API misuse and admin-data exposure.
- CVE-2026-3251High
Stored XSS
Stored cross-site scripting vulnerability. Reported through T.C. Siber Güvenlik Başkanlığı.
- CVE-2025-10228High
Session Fixation
Session fixation vulnerability. Reported through USOM.
Scores are NVD CVSS 3.1 base scores, not my own ratings. Entries without a number are still awaiting NVD analysis and carry the reporting CERT's severity instead.