
CVE-2026-31283
Documentation of CVE-2026-31283: an email bombing vulnerability in Totara LMS's forgot password API due to missing rate limiting, allowing…

Documentation of CVE-2026-31283: an email bombing vulnerability in Totara LMS's forgot password API due to missing rate limiting, allowing…
Python exploit for CVE-2026-89012, a Dolibarr SQL filter denylist bypass that uses a blind-boolean oracle to extract password hashes and API keys via…

unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)

NebulousAD automated credential auditing tool.

This vulnerability allows unauthenticated attackers who know a valid administrator username to impersonate that admin during REST API requests by…

PHP 8.4+ security library (mirror)

A WordPress plugin exposing an MCP server over the REST API, with the security model as the point -- closes the CVE-2026-15015 OAuth-bypass shape by…