┌──(root㉿0xbassia)-[~]
└─# cat profile.txt
[+] Name........: Mohamed Bassia
[+] Role........: Security Researcher / Vulnerability Hunter
[+] Specialties.: Source-code auditing, 0-day discovery, web exploitation
[+] Bug classes.: Account takeover, RCE, SSRF, prototype pollution, SQLi, XSS, IDOR
[+] Credits.....: 21 published CVEs (7 GitHub-reviewed + 14 WPScan)
[+] Advisories..: 4 additional GHSA credits without CVE assignment
[+] Peak........: CVE-2026-14560, CVSS 10.0
[+] Ecosystems..: npm, Go, WordPress, Joomla
[+] Status......: Reading code others trust, finding what they missed21 published CVEs · peak severity 10.0 Critical · npm, Go & WordPress · sorted by CVSS
| CVE | Target | Severity | Vulnerability Class | Published |
|---|---|---|---|---|
| CVE‑2026‑14560 | Teddy Bear Customize Addon (<= 1.0.5) |
🟣 Critical 10.0 |
Unauthenticated arbitrary file upload to RCE | 2026‑09‑09 |
| CVE‑2026‑14559 | Teddy Bear Customize Addon (<= 1.0.5) |
🟣 Critical 9.8 |
Unauthenticated account takeover, password never verified | 2026‑09‑09 |
| CVE‑2026‑14561 | Authora - Easy Login with Mobile Number (< 1.7.7) |
🟣 Critical 9.8 |
Unauthenticated account takeover via OTP disclosure | 2026‑07‑20 |
| CVE‑2026‑46510 | form-data-objectizer |
🔴 High 8.2 |
Prototype pollution via bracket-notation form keys | 2026‑05‑18 |
| CVE‑2026‑45325 | @tmlmobilidade/utils |
🔴 High 8.2 |
Prototype pollution in setValueAtPath |
2026‑05‑18 |
| CVE‑2026‑45302 | parse-nested-form-data |
🔴 High 8.2 |
Prototype pollution via __proto__ in form fields |
2026‑05‑18 |
| CVE‑2026‑46509 | @ranfdev/deepobj |
🔴 High 8.2 |
Prototype pollution | 2026‑05‑14 |
| CVE‑2026‑44483 | @rvf/set-get |
🔴 High 8.2 |
Prototype pollution reachable via @rvf/core preprocessFormData |
2026‑05‑11 |
| CVE‑2026‑14565 | Advanced Customized Prompts (<= 1.0.1) |
🔴 High 8.0 |
Subscriber+ stored XSS via product popup configuration | 2026‑09‑09 |
| CVE‑2026‑12516 | Fediverse Embeds (< 1.5.8) |
🔴 High 7.5 |
Unauthenticated SSRF via media proxy, full read + open proxy | 2026‑06‑18 |
| CVE‑2026‑17533 | All-in-One WP Migration and Backup (< 7.108) |
🔴 High 7.2 |
Network-wide PHP code execution from a multisite subsite admin | 2026‑08‑14 |
| CVE‑2026‑9815 | MagicForm (<= 0.1.3) |
🔴 High | Unauthenticated arbitrary file upload to RCE | 2026‑05‑28 |
| CVE‑2026‑9067 | Schema & Structured Data for WP & AMP (< 1.60) |
🔴 High | Unauthenticated arbitrary media upload | 2026‑05‑20 |
| CVE‑2026‑91024 | Booking Manager (< 2.1.21) |
🟠 Medium 6.8 |
Author+ SQL injection via imported iCalendar feed UID | 2026‑09‑21 |
| CVE‑2026‑91074 | BSK PDF Manager (<= 3.8.1) |
🟠 Medium 6.8 |
Contributor+ SQL injection exposing admin password hashes | 2026‑10‑07 |
| CVE‑2026‑12517 | Fediverse Embeds (< 1.5.8) |
🟠 Medium 5.3 |
Unauthenticated SSRF via site-info endpoint | 2026‑06‑18 |
| CVE‑2026‑14562 | Teddy Bear Customize Addon (<= 1.0.5) |
🟠 Medium 5.3 |
Unauthenticated order and attachment data disclosure | 2026‑09‑09 |
| CVE‑2026‑47378 | nocodb |
🟠 Medium | Hidden column exposure in public shared views | 2026‑06‑05 |
| CVE‑2026‑55671 | zitadel/zitadel (Go) |
🟢 Low | SSRF and denylist bypass in outgoing HTTP components | 2026‑06‑18 |
| CVE‑2026‑14563 | Advanced Customized Prompts (<= 1.0.1) |
⚪ Unrated | Unauthenticated account takeover, password never verified | 2026‑09‑09 |
| CVE‑2026‑14566 | Advanced Customized Prompts (<= 1.0.1) |
⚪ Unrated | Subscriber+ WooCommerce order metadata tampering (IDOR) | 2026‑09‑09 |
🟣 Critical · 🔴 High · 🟠 Medium · 🟢 Low · ⚪ Unrated, no CVSS published by the advisory source
7 GitHub-reviewed CVEs (6 npm + 1 Go) credited via the GitHub Advisory Database · 14 WordPress CVEs disclosed through WPScan
11 GitHub advisories credit me in total: the 7 above that carry a CVE, plus the 4 below that never had one assigned
4 published GitHub Security Advisories · credited as reporter, no CVE assigned
These do not appear under credit:0xBassia because the global Advisory Database only indexes advisories that receive a CVE
| Advisory | Target | Severity | Vulnerability Class | Published |
|---|---|---|---|---|
| GHSA‑mrf2‑rxph‑r28h | Kunena Forum (<= 7.0.4) |
🔴 High 8.2 |
Unauthenticated attachment privacy modification, missing CSRF and authorization | 2026‑05‑18 |
| GHSA‑wfph‑gf24‑pjqg | Kunena Forum (<= 7.0.4) |
🟠 Medium 4.3 |
Missing CSRF token check on the topic rating endpoint | 2026‑05‑18 |
| GHSA‑px35‑hwj4‑wqrh | Kunena Forum (<= 7.0.4) |
🟢 Low 3.5 |
Arbitrary-user avatar overwrite via missing CSRF check | 2026‑05‑18 |
| GHSA‑354h‑gmhv‑mr9c | TryGhost/Ghost (< 6.27.0) |
🟢 Low 2.7 |
SSRF in webhook trigger (CWE-918) | 2026‑08‑11 |
Research: 🛡️ 21 published CVEs · 📜 4 GHSA advisory credits · 🎯 peak 10.0 Critical
GitHub: 🦈 Pull Shark ×2 · ⚡ Quickdraw · 👥 Pair Extraordinaire · 🧊 Arctic Code Vault