Proof/CVEs & advisories

§ Public research record

Twenty-one findings. Every identifier, every write-up.

Each entry links to the independent public advisory record and, where the write-up is cleared for publication, to the full proof-first analysis. Six cases are listed with identifier and status only, because their coordinators still withhold the technical detail.

21
Distinct findings
A paired CVE and GHSA counts once here.
14
CVE records
Published identifiers with public advisory records.
12
Repository advisories
Maintainer-published GHSAs; 5 also carry a CVE.
15
Full public write-ups
6 remain at advisory level pending release.

Public records rechecked 5 September 2026. Every identifier below is independently verifiable through the linked advisory.

IdentifierProjectFindingSeveritySecHiveSource
CVE-2026-73343WP CompressWordPressUnauthenticated remote code execution — technical detail withheld pending coordinator releaseCritical · CVSS 10.0Advisory
CVE-2026-15054Bit FormWordPressInactive or unpublished forms remained reachable through public submission handlersLow · CVSS 3.7Write-up Advisory
CVE-2026-16534Import and export users and customersWordPressCSV import crossed WordPress user-management authorization boundariesHigh · CVSS 7.2Write-up Advisory
CVE-2026-64606Apache ForyJavaClass-registration bypass through an auto-admitted SerializedLambda capture interfaceCritical · CVSS 9.8 (CISA ADP)Write-up Advisory
CVE-2026-75796AI EngineWordPressMultisite privilege escalation through MCP user tools — technical detail withheld pending coordinator releaseHigh · CVSS 7.2Advisory
CVE-2026-77789Stripe Payment Forms by WP Full PayWordPressCross-customer subscription modification through an IDOR — technical detail withheld pending coordinator releaseMedium · CVSS 4.3Advisory
CVE-2026-77356
GHSA-976x-prgx-qv35
TypeBoxnpmGenerated validation-code injection through schema-controlled stringsHigh · CVSS 7.8Write-up Advisory
CVE-2026-77355
GHSA-6fxm-h49m-4fg3
isomorphic-gitnpmNTFS .git::$INDEX_ALLOCATION alias writes into the active gitdirHigh · CVSS 8.8Write-up Advisory
CVE-2026-47698
GHSA-cfcw-xp6x-25gj
vm2npmSandbox breakout using dangerous host prototype mutatorsCritical · CVSS 9.8Write-up Advisory
CVE-2026-73569
GHSA-8r6m-32jq-jx6q
fast-xml-parsernpmRepeated DOCTYPE declarations reset entity-expansion limitsHigh · CVSS 8.7Write-up Advisory
CVE-2026-81766Really Simple SecurityWordPressMultisite subsite Administrator arbitrary plugin installation — technical detail withheld pending coordinator releaseMedium · CVSS 6.6Advisory
CVE-2026-17563WP User FrontendWordPressUnauthenticated post creation through a subscription-gated form — technical detail withheld pending coordinator releaseNot displayed on the public record at audit timeAdvisory
CVE-2026-77793RegistrationMagicWordPressPaid-registration bypass through an omitted price field — technical detail withheld pending coordinator releaseNot displayed on the public record at audit timeAdvisory
CVE-2026-84451
GHSA-hh47-fhqr-cj2r
libheifC / C++Incomplete fix left the no-icef full-item range check vulnerable to integer wrap and an out-of-bounds readModerate · CVSS 6.5Write-up Advisory
GHSA-5jx8-p6q2-455gDynamicExpresso.CoreNuGetLateBindObject bypasses reflection restrictions and reaches host command executionHigh · CVSS 8.8Write-up Advisory
GHSA-hphq-wq62-4mj3OpenEXRC / C++HTJ2K planar decode row-endpoint wrap causes CPU-bound denial of serviceModerate · CVSS 5.5Write-up Advisory
GHSA-v3qq-3xvg-m77gpython-statemachinePyPIRestricted write-side dunder traversal corrupts shared model stateCritical · CVSS 9.1Write-up Advisory
GHSA-fj3w-533r-fvf6python-statemachinePyPIUntrusted SCXML external sources permitted arbitrary local-file readsHigh · CVSS 7.1Write-up Advisory
GHSA-g3jj-5cmm-3hxxfast-jwtnpmRaw public JWK JSON accepted as an HMAC secret, enabling HS256 token forgeryHigh · CVSS 7.4Write-up Advisory
GHSA-qhwx-74w5-xhxqvm2npmNodeVM builtin allowlist bypass through node:test.run() execArgvCritical · CVSS 9.9Write-up Advisory
GHSA-9v3x-mhg4-wwv2Exiv2C / C++Out-of-bounds write in http.cppLowWrite-up Advisory
Counting convention. A finding that carries both a CVE and a repository GitHub Security Advisory is counted once under distinct cases, and once in each applicable identifier count. Five public cases carry both identifiers, so the identifier totals overlap and must not be added together. The 7 advisory-only entries above carry no separate CVE record. Identifier totals are never summed into a vulnerability count: the defensible unique total is 21.
Publication boundary. Write-ups cover published advisories, CVE records, public repositories and commits, and already-public proof material. Where a proof of concept is public with the advisory, the write-up explains it without duplicating a reusable payload. Embargoed mechanics, private correspondence and unpublished PoCs are excluded — three assigned CVEs above carry no technical detail for exactly that reason.
§ Also published

Four accepted Linux mainline fixes.

Upstream kernel contributions are tracked separately from the CVE and advisory record, with patch authorship and reporter credit recorded exactly as the mainline commits state them.