Skip to content
View 0xBassia's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report 0xBassia

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
0xBassia/README.md

> whoami

┌──(root㉿0xbassia)-[~]
└─# cat profile.txt

[+] Name........: Mohamed Bassia
[+] Role........: Security Researcher / Vulnerability Hunter
[+] Specialties.: Source-code auditing, 0-day discovery, web exploitation
[+] Bug classes.: Account takeover, RCE, SSRF, prototype pollution, SQLi, XSS, IDOR
[+] Credits.....: 21 published CVEs (7 GitHub-reviewed + 14 WPScan)
[+] Advisories..: 4 additional GHSA credits without CVE assignment
[+] Peak........: CVE-2026-14560, CVSS 10.0
[+] Ecosystems..: npm, Go, WordPress, Joomla
[+] Status......: Reading code others trust, finding what they missed

> CVEs --published

21 published CVEs  ·  peak severity 10.0 Critical  ·  npm, Go & WordPress  ·  sorted by CVSS

CVE Target Severity Vulnerability Class Published
CVE‑2026‑14560 Teddy Bear Customize Addon (<= 1.0.5) 🟣 Critical 10.0 Unauthenticated arbitrary file upload to RCE 2026‑09‑09
CVE‑2026‑14559 Teddy Bear Customize Addon (<= 1.0.5) 🟣 Critical 9.8 Unauthenticated account takeover, password never verified 2026‑09‑09
CVE‑2026‑14561 Authora - Easy Login with Mobile Number (< 1.7.7) 🟣 Critical 9.8 Unauthenticated account takeover via OTP disclosure 2026‑07‑20
CVE‑2026‑46510 form-data-objectizer 🔴 High 8.2 Prototype pollution via bracket-notation form keys 2026‑05‑18
CVE‑2026‑45325 @tmlmobilidade/utils 🔴 High 8.2 Prototype pollution in setValueAtPath 2026‑05‑18
CVE‑2026‑45302 parse-nested-form-data 🔴 High 8.2 Prototype pollution via __proto__ in form fields 2026‑05‑18
CVE‑2026‑46509 @ranfdev/deepobj 🔴 High 8.2 Prototype pollution 2026‑05‑14
CVE‑2026‑44483 @rvf/set-get 🔴 High 8.2 Prototype pollution reachable via @rvf/core preprocessFormData 2026‑05‑11
CVE‑2026‑14565 Advanced Customized Prompts (<= 1.0.1) 🔴 High 8.0 Subscriber+ stored XSS via product popup configuration 2026‑09‑09
CVE‑2026‑12516 Fediverse Embeds (< 1.5.8) 🔴 High 7.5 Unauthenticated SSRF via media proxy, full read + open proxy 2026‑06‑18
CVE‑2026‑17533 All-in-One WP Migration and Backup (< 7.108) 🔴 High 7.2 Network-wide PHP code execution from a multisite subsite admin 2026‑08‑14
CVE‑2026‑9815 MagicForm (<= 0.1.3) 🔴 High Unauthenticated arbitrary file upload to RCE 2026‑05‑28
CVE‑2026‑9067 Schema & Structured Data for WP & AMP (< 1.60) 🔴 High Unauthenticated arbitrary media upload 2026‑05‑20
CVE‑2026‑91024 Booking Manager (< 2.1.21) 🟠 Medium 6.8 Author+ SQL injection via imported iCalendar feed UID 2026‑09‑21
CVE‑2026‑91074 BSK PDF Manager (<= 3.8.1) 🟠 Medium 6.8 Contributor+ SQL injection exposing admin password hashes 2026‑10‑07
CVE‑2026‑12517 Fediverse Embeds (< 1.5.8) 🟠 Medium 5.3 Unauthenticated SSRF via site-info endpoint 2026‑06‑18
CVE‑2026‑14562 Teddy Bear Customize Addon (<= 1.0.5) 🟠 Medium 5.3 Unauthenticated order and attachment data disclosure 2026‑09‑09
CVE‑2026‑47378 nocodb 🟠 Medium Hidden column exposure in public shared views 2026‑06‑05
CVE‑2026‑55671 zitadel/zitadel (Go) 🟢 Low SSRF and denylist bypass in outgoing HTTP components 2026‑06‑18
CVE‑2026‑14563 Advanced Customized Prompts (<= 1.0.1) ⚪ Unrated Unauthenticated account takeover, password never verified 2026‑09‑09
CVE‑2026‑14566 Advanced Customized Prompts (<= 1.0.1) ⚪ Unrated Subscriber+ WooCommerce order metadata tampering (IDOR) 2026‑09‑09

🟣 Critical  ·  🔴 High  ·  🟠 Medium  ·  🟢 Low  ·  ⚪ Unrated, no CVSS published by the advisory source

7 GitHub-reviewed CVEs (6 npm + 1 Go) credited via the GitHub Advisory Database  ·  14 WordPress CVEs disclosed through WPScan

11 GitHub advisories credit me in total: the 7 above that carry a CVE, plus the 4 below that never had one assigned

> advisories --credited

4 published GitHub Security Advisories  ·  credited as reporter, no CVE assigned

These do not appear under credit:0xBassia because the global Advisory Database only indexes advisories that receive a CVE

Advisory Target Severity Vulnerability Class Published
GHSA‑mrf2‑rxph‑r28h Kunena Forum (<= 7.0.4) 🔴 High 8.2 Unauthenticated attachment privacy modification, missing CSRF and authorization 2026‑05‑18
GHSA‑wfph‑gf24‑pjqg Kunena Forum (<= 7.0.4) 🟠 Medium 4.3 Missing CSRF token check on the topic rating endpoint 2026‑05‑18
GHSA‑px35‑hwj4‑wqrh Kunena Forum (<= 7.0.4) 🟢 Low 3.5 Arbitrary-user avatar overwrite via missing CSRF check 2026‑05‑18
GHSA‑354h‑gmhv‑mr9c TryGhost/Ghost (< 6.27.0) 🟢 Low 2.7 SSRF in webhook trigger (CWE-918) 2026‑08‑11

> arsenal --list

Source-Code Auditing & SAST

CodeQL Semgrep CodeChecker Manual Review

Vulnerability Research & Exploitation

Burp Suite pwntools Ghidra Frida

Fuzzing & Supply-Chain

AFL++ libFuzzer OSV Dependency Audit

Languages

Python JavaScript TypeScript Go PHP C Bash

> stats --github

> achievements --unlock

Research:   🛡️ 21 published CVEs  ·  📜 4 GHSA advisory credits  ·  🎯 peak 10.0 Critical

GitHub:   🦈 Pull Shark ×2  ·  ⚡ Quickdraw  ·  👥 Pair Extraordinaire  ·  🧊 Arctic Code Vault

> contact --secure

root@0xbassia:~# echo "Hack the planet, responsibly." █

Pinned Loading

  1. security-research security-research Public

    Vulnerability disclosures and root-cause analysis. 21 published CVEs across npm, Go and WordPress, peak CVSS 10.0: account takeover, unauthenticated upload to RCE, privilege escalation, SQL injecti…