Security research

Vulnerabilities explained with public proof.

Read selected case studies or search the complete advisory ledger. Public claims link to vendor, CNA, CVE Program, or project sources. Unpublished technical details remain private.

Complete research ledger

Find a CVE, product, or weakness.

Includes 26 assigned CVEs and 4 additional Finder credits. Each public entry links to its supporting record.

30 records in the public ledger · 8 additional records shown
  1. CVECVE-2026-48130

    Tekton Pipeline

    A CVE ID is assigned to Tekton Pipeline. Technical details remain withheld until the vendor advisory and CVE Program record are public.

    Publication pending
    Disclosure pending · AssignedRemediation details withheld until publication
    Open project page opens in a new tab
    CVE-2026-48130: Facts and sources
    Published
    Vendor publication pending
    Status
    CVE assigned; public advisory and CVE Program record pending
    Scoring
    Pending vendor publication
    Credit
    Public credit pending publication
    Remediation
    Remediation details withheld until publication
  2. CVECVE-2026-73556

    vLLM

    vLLM's lm-format-enforcer structured-output backend compiled an attacker-supplied regex with no timeout, so one catastrophic pattern pegged a CPU core and stalled the engine worker.

    Injection & untrusted executionRequest, file & parser boundaries
    Medium · 5.3Fixed in 0.26.0
    Read case study
    CVE-2026-73556: Facts and sources
    Published
    25 Jul 2026
    Status
    GitHub Security Advisory published; CVE Program record published
    Scoring
    CVSS 3.1
    Credit
    Finder
    Remediation
    Fixed in 0.26.0
  3. CVECVE-2026-66696

    Kadence Blocks WordPress plugin

    A contributor-controlled library URL could receive the site's stored Kadence license key and email from a server-side request.

    Authentication & session integrityRequest, file & parser boundaries
    Medium · 4.3Fixed in 3.7.8.1
    Read case study
    CVE-2026-66696: Facts and sources
    Published
    29 Jul 2026
    Status
    Patchstack verified; CVE Program published
    Scoring
    CVSS 3.1
    Credit
    Finder
    Remediation
    Fixed in 3.7.8.1
  4. CVECVE-2026-66690

    GiveWP WordPress plugin

    An unauthenticated donation phone value was stored without neutralization and rendered unescaped in the privileged donation-detail view.

    Injection & untrusted execution
    High · 7.1Fixed in 4.16.5.1
    Read case study
    CVE-2026-66690: Facts and sources
    Published
    31 Jul 2026
    Status
    Patchstack verified; CVE Program published
    Scoring
    CVSS 3.1
    Credit
    Finder
    Remediation
    Fixed in 4.16.5.1
  5. CVECVE-2026-65523

    Formidable Forms Signature Online Contract Automation

    An unauthenticated entry ID could be resolved to a private e-signature invite URL without an ownership or signer check.

    Authorization & tenant isolationAuthentication & session integrity
    High · 7.5Fixed in 2.0.2
    Read case study
    CVE-2026-65523: Facts and sources
    Published
    28 Jul 2026
    Status
    Patchstack verified; CVE Program published
    Scoring
    CVSS 3.1
    Credit
    Finder
    Remediation
    Fixed in 2.0.2
  6. CVECVE-2026-28145

    MasterStudy LMS WordPress plugin

    The PayPal IPN handler accepted a VERIFIED postback without binding its amount, receiver, status, or currency to the pending LMS order.

    Request, file & parser boundaries
    Medium · 5.3Fixed in 3.7.40
    Read case study
    CVE-2026-28145: Facts and sources
    Published
    31 Jul 2026
    Status
    Patchstack verified; CVE Program published
    Scoring
    CVSS 3.1
    Credit
    Finder
    Remediation
    Fixed in 3.7.40
  7. CVECVE-2026-16613

    GDPR Cookie Compliance WordPress plugin

    A public cookie-clearing action lacked an origin check, allowing a cross-site top-level request to expire a logged-in user's cookies.

    Authentication & session integrity
    Medium · 4.3Fixed in 5.1.0
    Read case study
    CVE-2026-16613: Facts and sources
    Published
    27 Jul 2026
    Status
    WPScan verified; CVE Program published
    Scoring
    CVSS 3.1
    Credit
    Finder
    Remediation
    Fixed in 5.1.0
  8. CVECVE-2026-16573

    Bit Form WordPress plugin

    A public signature field could store an unsanitized SVG in the uploads directory, where script executed when the file was opened.

    Injection & untrusted executionRequest, file & parser boundaries
    High · 7.5Fixed in 3.2.0
    Read case study
    CVE-2026-16573: Facts and sources
    Published
    27 Jul 2026
    Status
    WPScan verified; CVE Program published
    Scoring
    CVSS 3.1
    Credit
    Finder
    Remediation
    Fixed in 3.2.0

29 records have public primary sources. One record may cover more than one vulnerability class. Reviewed 9 Aug 2026; 1 record is awaiting coordinated publication.

Responsible disclosure

Report a security issue privately.

Start with a channel request. Do not send unpatched technical details through a public service.