Proof/CVEs & advisories
§ Public research record
Twenty-one findings. Every identifier, every write-up.
Each entry links to the independent public advisory record and, where the write-up is cleared for publication, to the full proof-first analysis. Six cases are listed with identifier and status only, because their coordinators still withhold the technical detail.
21
Distinct findings
A paired CVE and GHSA counts once here.
14
CVE records
Published identifiers with public advisory records.
12
Repository advisories
Maintainer-published GHSAs; 5 also carry a CVE.
15
Full public write-ups
6 remain at advisory level pending release.
Public records rechecked 5 September 2026. Every identifier below is independently verifiable through the linked advisory.
| Identifier | Project | Finding | Severity | SecHive | Source |
|---|---|---|---|---|---|
| CVE-2026-73343 | WP CompressWordPress | Unauthenticated remote code execution — technical detail withheld pending coordinator release | Critical · CVSS 10.0 | — | Advisory |
| CVE-2026-15054 | Bit FormWordPress | Inactive or unpublished forms remained reachable through public submission handlers | Low · CVSS 3.7 | Write-up → | Advisory |
| CVE-2026-16534 | Import and export users and customersWordPress | CSV import crossed WordPress user-management authorization boundaries | High · CVSS 7.2 | Write-up → | Advisory |
| CVE-2026-64606 | Apache ForyJava | Class-registration bypass through an auto-admitted SerializedLambda capture interface | Critical · CVSS 9.8 (CISA ADP) | Write-up → | Advisory |
| CVE-2026-75796 | AI EngineWordPress | Multisite privilege escalation through MCP user tools — technical detail withheld pending coordinator release | High · CVSS 7.2 | — | Advisory |
| CVE-2026-77789 | Stripe Payment Forms by WP Full PayWordPress | Cross-customer subscription modification through an IDOR — technical detail withheld pending coordinator release | Medium · CVSS 4.3 | — | Advisory |
| CVE-2026-77356 GHSA-976x-prgx-qv35 | TypeBoxnpm | Generated validation-code injection through schema-controlled strings | High · CVSS 7.8 | Write-up → | Advisory |
| CVE-2026-77355 GHSA-6fxm-h49m-4fg3 | isomorphic-gitnpm | NTFS .git::$INDEX_ALLOCATION alias writes into the active gitdir | High · CVSS 8.8 | Write-up → | Advisory |
| CVE-2026-47698 GHSA-cfcw-xp6x-25gj | vm2npm | Sandbox breakout using dangerous host prototype mutators | Critical · CVSS 9.8 | Write-up → | Advisory |
| CVE-2026-73569 GHSA-8r6m-32jq-jx6q | fast-xml-parsernpm | Repeated DOCTYPE declarations reset entity-expansion limits | High · CVSS 8.7 | Write-up → | Advisory |
| CVE-2026-81766 | Really Simple SecurityWordPress | Multisite subsite Administrator arbitrary plugin installation — technical detail withheld pending coordinator release | Medium · CVSS 6.6 | — | Advisory |
| CVE-2026-17563 | WP User FrontendWordPress | Unauthenticated post creation through a subscription-gated form — technical detail withheld pending coordinator release | Not displayed on the public record at audit time | — | Advisory |
| CVE-2026-77793 | RegistrationMagicWordPress | Paid-registration bypass through an omitted price field — technical detail withheld pending coordinator release | Not displayed on the public record at audit time | — | Advisory |
| CVE-2026-84451 GHSA-hh47-fhqr-cj2r | libheifC / C++ | Incomplete fix left the no-icef full-item range check vulnerable to integer wrap and an out-of-bounds read | Moderate · CVSS 6.5 | Write-up → | Advisory |
| GHSA-5jx8-p6q2-455g | DynamicExpresso.CoreNuGet | LateBindObject bypasses reflection restrictions and reaches host command execution | High · CVSS 8.8 | Write-up → | Advisory |
| GHSA-hphq-wq62-4mj3 | OpenEXRC / C++ | HTJ2K planar decode row-endpoint wrap causes CPU-bound denial of service | Moderate · CVSS 5.5 | Write-up → | Advisory |
| GHSA-v3qq-3xvg-m77g | python-statemachinePyPI | Restricted write-side dunder traversal corrupts shared model state | Critical · CVSS 9.1 | Write-up → | Advisory |
| GHSA-fj3w-533r-fvf6 | python-statemachinePyPI | Untrusted SCXML external sources permitted arbitrary local-file reads | High · CVSS 7.1 | Write-up → | Advisory |
| GHSA-g3jj-5cmm-3hxx | fast-jwtnpm | Raw public JWK JSON accepted as an HMAC secret, enabling HS256 token forgery | High · CVSS 7.4 | Write-up → | Advisory |
| GHSA-qhwx-74w5-xhxq | vm2npm | NodeVM builtin allowlist bypass through node:test.run() execArgv | Critical · CVSS 9.9 | Write-up → | Advisory |
| GHSA-9v3x-mhg4-wwv2 | Exiv2C / C++ | Out-of-bounds write in http.cpp | Low | Write-up → | Advisory |
Counting convention. A finding that carries both a CVE and a repository GitHub Security Advisory is counted once under distinct cases, and once in each applicable identifier count. Five public cases carry both identifiers, so the identifier totals overlap and must not be added together. The 7 advisory-only entries above carry no separate CVE record. Identifier totals are never summed into a vulnerability count: the defensible unique total is 21.
Publication boundary. Write-ups cover published advisories, CVE records, public repositories and commits, and already-public proof material. Where a proof of concept is public with the advisory, the write-up explains it without duplicating a reusable payload. Embargoed mechanics, private correspondence and unpublished PoCs are excluded — three assigned CVEs above carry no technical detail for exactly that reason.
§ Also published
Four accepted Linux mainline fixes.
Upstream kernel contributions are tracked separately from the CVE and advisory record, with patch authorship and reporter credit recorded exactly as the mainline commits state them.