┌──(root㉿0xbassia)-[~]
└─# cat profile.txt
[+] Name........: Mohamed Bassia
[+] Role........: Security Researcher / Vulnerability Hunter
[+] Specialties.: Source-code auditing, 0-day discovery, web exploitation
[+] Bug classes.: Account takeover, RCE, SSRF, prototype pollution, access control
[+] Credits.....: 13 published CVEs (7 GitHub-reviewed + 6 WPScan)
[+] Advisories..: 4 additional GHSA credits without CVE assignment
[+] Ecosystems..: npm, Go, WordPress, Joomla
[+] Status......: Reading code others trust, finding what they missed13 published CVEs · peak severity 9.8 Critical · npm, Go & WordPress · sorted by severity
| CVE | Target | Severity | Vulnerability Class | Published |
|---|---|---|---|---|
| CVE‑2026‑14561 | Authora - Easy Login with Mobile Number (< 1.7.7) |
🟣 Critical 9.8 |
Unauthenticated account takeover via OTP disclosure | 2026‑07‑20 |
| CVE‑2026‑46510 | form-data-objectizer |
🔴 High 8.2 |
Prototype pollution via bracket-notation form keys | 2026‑05‑18 |
| CVE‑2026‑45325 | @tmlmobilidade/utils |
🔴 High 8.2 |
Prototype pollution in setValueAtPath |
2026‑05‑18 |
| CVE‑2026‑45302 | parse-nested-form-data |
🔴 High 8.2 |
Prototype pollution via __proto__ in form fields |
2026‑05‑18 |
| CVE‑2026‑46509 | @ranfdev/deepobj |
🔴 High 8.2 |
Prototype pollution | 2026‑05‑14 |
| CVE‑2026‑44483 | @rvf/set-get |
🔴 High 8.2 |
Prototype pollution reachable via @rvf/core preprocessFormData |
2026‑05‑11 |
| CVE‑2026‑12516 | Fediverse Embeds (< 1.5.8) |
🔴 High 7.5 |
Unauthenticated SSRF via media proxy, full read + open proxy | 2026‑06‑18 |
| CVE‑2026‑17533 | All-in-One WP Migration and Backup (< 7.108) |
🔴 High 7.2 |
Network-wide PHP code execution from a multisite subsite admin | 2026‑08‑14 |
| CVE‑2026‑9815 | MagicForm (<= 0.1.3) |
🔴 High | Unauthenticated arbitrary file upload to RCE | 2026‑05‑28 |
| CVE‑2026‑9067 | Schema & Structured Data for WP & AMP (< 1.60) |
🔴 High | Unauthenticated arbitrary media upload | 2026‑05‑20 |
| CVE‑2026‑12517 | Fediverse Embeds (< 1.5.8) |
🟠 Medium 5.3 |
Unauthenticated SSRF via site-info endpoint | 2026‑06‑18 |
| CVE‑2026‑47378 | nocodb |
🟠 Medium | Hidden column exposure in public shared views | 2026‑06‑05 |
| CVE‑2026‑55671 | zitadel/zitadel (Go) |
🟢 Low | SSRF and denylist bypass in outgoing HTTP components | 2026‑06‑18 |
🟣 Critical · 🔴 High · 🟠 Medium · 🟢 Low · CVSS v3.1 base score shown where assigned
7 GitHub-reviewed CVEs (6 npm + 1 Go) credited via the GitHub Advisory Database · 6 WordPress CVEs disclosed through WPScan
4 published GitHub Security Advisories · credited as reporter, no CVE assigned
| Advisory | Target | Severity | Vulnerability Class | Published |
|---|---|---|---|---|
| GHSA‑mrf2‑rxph‑r28h | Kunena Forum (<= 7.0.4) |
🔴 High 8.2 |
Unauthenticated attachment privacy modification, missing CSRF and authorization | 2026‑05‑18 |
| GHSA‑wfph‑gf24‑pjqg | Kunena Forum (<= 7.0.4) |
🟠 Medium 4.3 |
Missing CSRF token check on the topic rating endpoint | 2026‑05‑18 |
| GHSA‑px35‑hwj4‑wqrh | Kunena Forum (<= 7.0.4) |
🟢 Low 3.5 |
Arbitrary-user avatar overwrite via missing CSRF check | 2026‑05‑18 |
| GHSA‑354h‑gmhv‑mr9c | TryGhost/Ghost (< 6.27.0) |
🟢 Low 2.7 |
SSRF in webhook trigger (CWE-918) | 2026‑08‑11 |
Research: 🛡️ 13 published CVEs · 📜 4 GHSA advisory credits · 🎯 peak 9.8 Critical
GitHub: 🦈 Pull Shark ×2 · ⚡ Quickdraw · 👥 Pair Extraordinaire · 🧊 Arctic Code Vault