Skip to content

zast-ai/vulnerability-reports

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

305 Commits
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

ZAST.AI Security Vulnerability Reports

A Collection of Security Vulnerability Reports Discovered and Disclosed by ZAST.AI

πŸ“ Introduction

This repository contains detailed analysis reports of security vulnerabilities discovered by the ZAST.AI. We are committed to responsible disclosure of these vulnerabilities and collaboration with the open-source community to enhance software security.

🎯 Objectives

  • Transparent sharing of discovered security vulnerabilities
  • Helping developers understand and fix common security issues
  • Promoting security awareness in the open-source community
  • Establishing best practices for responsible vulnerability disclosure

πŸ“Š Vulnerability Report List

2026

Project & Affected Version Vulnerability Type Report Disclosure Popularity
WP HTML in Category Descriptions<=1.2.4 Stored-XSS Report CVE-2026-0693 -
WP Slider Future <= 1.0.5 RCE (Arbitrary File Upload) Report CVE-2026-1405 -
WP Easy PHP Settings <= 1.0.4 Code Injection Report CVE-2026-3352 -
WP Content Visibility for Divi Builder<=4.01 Code Injection Report CVE-2026-1829 -
Prime <=0.4.0 Sensitive Info Disclosure Report CVE-2026-1170 Stars
Prime <=0.4.0 GraphQL Field Duplication Report CVE-2026-1171 Stars
Prime <=0.4.0 GraphQL Directive Overloading Report CVE-2026-1172 Stars
Prime <=0.4.0 GraphQL Array Based Query Batching Report CVE-2026-1173 Stars
Prime <=0.4.0 GraphQL Aliases Overloading Report CVE-2026-1174 Stars
Prime <=0.4.0 Directive Information Disclosure Report CVE-2026-1175 Stars
Prime <=0.4.0 CSRF Report CVE-2026-1169 Stars
Digital-Infrastructure<=9.6.7 SQL injection Report CVE-2026-1050 Stars
pycel <=1.0b30 Arbitrary Code Execution Report CVE-XXX Downloads
Apache Commons Digester<=2.1&3.2 SSRF Report Rejected? #36 Config Lib
changedetection.io <= 0.52.6 SSRF Report CVE-XXX Stars
busy <=2.5.5 Open Redirect Report CVE-2026-2709 Stars
worldquant-miner <=1.0.9 SSRF Report CVE-2026-2711 Stars
ByteDance verl<=0.7.0 RCE Report BugBounty Stars
ByteDance vchart<=2.0.15 Arbitrary File Read Report BugBounty Stars
ByteDance Depth-Anything-V2<=1.0 Open Redirect Report GotBounty Stars
ByteDance Depth-Anything-V2<=1.0 Open Redirect Report Merged Stars
xxl-job <=3.3.2 SSRF Report CVE-2026-3733 Stars
Locker <=0.1.0 Reflected XSS Report CVE-2026-3951 Stars
elecV2P <=3.8.3 Remote Code Execution Report CVE-2026-3955 Stars
weimai-wetapp <=1.0.0 SQL Injection Report CVE-2026-3956 Stars
weimai-wetapp <=1.0.0 SQL Injection Report CVE-2026-3957 Stars
Bytedesk <=1.3.9 Insecure File Upload Report CVE-2026-3748 Stars
Bytedesk <=1.3.9 Insecure File Upload Report CVE-2026-3749 Stars
Bytedesk <=1.3.9 SSRF Report CVE-2026-3788 Stars
Bytedesk <=1.3.9 SSRF Report CVE-2026-3789 Stars
list-sync <=0.6.6 SSRF Report CVE-2026-3958 Stars
OneUptime <=10.0.9 SSRF Report CVE-XXX Stars
manga-image-translator <=beta-0.3 SSRF Report CVE-2026-3961 Stars
manga-image-translator <=beta-0.3 SSRF Report Merged-2026-3961 Stars
manga-image-translator <=beta-0.3 SSRF Report Merged-2026-3961 Stars
manga-image-translator <=beta-0.3 SSRF Report Merged-2026-3961 Stars
manga-image-translator <=beta-0.3 SSRF Report Merged-2026-3961 Stars
manga-image-translator <=beta-0.3 SSRF Report Merged-2026-3961 Stars
manga-image-translator <=beta-0.3 SSRF Report Merged-2026-3961 Stars
Machine-Learning-Web-Apps <=1.0.0 Reflected XSS Report CVE-2026-3962 Stars
dinero.js <= v2.0.0-alpha.17 ReDoS Report Rejected Stars
pdf-lib <= v1.17.1 ReDoS Report Rejected Stars
VictoriaMetrics <=1.137.0 Brute Force Report CVE-XXX Stars
Gitea <=1.25.4 Account Takeover ExpChain Report CVE-XXX Stars
Gogs <=0.14.2 Brute Force Report CVE-XXX Stars
Gogs <=0.14.2 Auth Bypass Report CVE-XXX Stars
Gogs <=0.14.2 Insufficient Session Expiration Report CVE-XXX Stars
Gogs <=0.14.2 Insufficient Session Expiration Report CVE-XXX Stars
Gogs <=0.14.2 Batch registration Report CVE-XXX Stars
Apache FOP <= 2.11 RCE Report CVE-XXX #Top 1625
Minio <=2025-10-15T17-29-55Z Ldap BruteForce Report CVE-XXX Stars
elecV2P <=3.8.3 RCE Report CVE-XXX Stars
elecV2P <=3.8.3 RCE Report CVE-XXX Stars
elecV2P <=3.8.3 Path Traversal Report CVE-XXX Stars
elecV2P <=3.8.3 Path Traversal Report CVE-XXX Stars
elecV2P <=3.8.3 Reflected XSS Report CVE-XXX Stars
elecV2P <=3.8.3 SSRF Report CVE-XXX Stars

2025

Project & Affected Version Vulnerability Type Report Disclosure Popularity
Microsoft Azure SDK XXE Report ACK-12/31/2025 Stars
Alibaba Nacos-spring-context XXE Report GotBounty Stars
node-formidable <=3.5.2 Insecure File Upload & Filename Prediction Report CVE-2025-46653 npm
Apache Commons Configuration <=1.10.x Remote Code Execution Report Reported #3 Config Lib
Apache Commons Configuration2 <=2.12.x Remote Code Execution Report Reported #3 Config Lib
Apache Struts2 <=6.0.3 XXE Report CVE-2025-68493 #8 Web FWK
Koa <=3.0.0 cb22d8d Open Redirect Report CVE-2025-8129 Stars
langfuse <=3.88.0 SSRF Report CVE-2025-9799 Stars
CodiMD low version Insecure File Upload & CSP bypass Report CVE-2025-46654 Stars
CodiMD high version Insecure File Upload & CSP bypass Report CVE-2025-46655 Stars
mall <=1.0.3 7a1ca5d DOM XSS Report CVE-2025-8191 Stars
mall <=1.0.3 7a1ca5d JWT secret hardcoded Report duplicate Stars
JeeSite <=5.12.0 b522b3f SSRF Report CVE-2025-7759 Stars
JeeSite <=5.12.0 b522b3f Open Redirection Report CVE-2025-7763 Stars
JeeSite <=5.12.0 b522b3f Open Redirection Report CVE-2025-7785 Stars
JeeSite <=5.12.0 b522b3f Open Redirection Report CVE-2025-7863 Stars
JeeSite <=5.12.0 b522b3f Insecure File Upload Report CVE-2025-7864 Stars
JeeSite <=5.12.0 b522b3f XSS filter bypass Report CVE-2025-7865 Stars
JeeSite <=5.12.1 release XSS filter bypass Report CVE-2025-9796 Stars
GnuBoard v6 Stored XSS Report CVE-2025-7786 Stars
GnuBoard v6 Open Redirect Report duplicate Stars
xxl-job <=3.1.1 SSRF Report CVE-2025-7787 Stars
xxl-job <=3.1.1 OS command injection Report CVE-2025-7788 Stars
xxl-job <=3.1.1 Insecure Cryptographic Algorithm Report CVE-2025-7789 Stars
stirling-pdf <=1.0.2 SSRF Report CVE-2025-55150 Stars
stirling-pdf <=1.0.2 SSRF Report CVE-2025-55151 Stars
stirling-pdf <=1.0.2 SSRF Report CVE-2025-55161 Stars
ruoyi v4.8.1 70194ae DOM XSS Report CVE-2025-7901 Stars
ruoyi v4.8.1 70194ae Stored XSS Report CVE-2025-7902 Stars
ruoyi v4.8.1 70194ae Frame Injection Report CVE-2025-7903 Stars
ruoyi v4.8.1 70194ae Insecure File Upload Report CVE-2025-7906 Stars
ruoyi v4.8.1 70194ae Druid Credential Hardcoded Report CVE-2025-7907 Stars
platform 1.0.0 ca9acef SQL injection Report CVE-2025-7936 Stars
platform 1.0.0 ca9acef SQL injection Report CVE-2025-7935 Stars
platform 1.0.0 ca9acef SQL injection Report CVE-2025-7934 Stars
jshERP <=3.5 IDOR change password Report CVE-2025-7948 Stars
jshERP <=3.5 IDOR delete account Report CVE-2025-7947 Stars
PublicCMS V5.202506.a Open Redirect Report CVE-2025-7949 Stars
PublicCMS V5.202506.a Open Redirect Report CVE-2025-7953 Stars
PublicCMS V5.202506.a SSRF Report duplicate Stars
PublicCMS V5.202506.a Insecure File Upload Report rejected Stars
PublicCMS V5.202506.a Insecure File Upload Report rejected Stars
PublicCMS V5.202506.a Insecure File Upload Report rejected Stars
PublicCMS V5.202506.a Insecure File Upload Report rejected Stars
PublicCMS V5.202506.a Insecure File Upload Report rejected Stars
PublicCMS V5.202506.a Insecure File Upload Report rejected Stars
deer-wms-2 525b6cf Insecure Deserialization Report rejected Stars
deer-wms-2 525b6cf Insecure Deserialization Report rejected Stars
deer-wms-2 525b6cf Shiro-550 Report rejected Stars
deer-wms-2 525b6cf SQL injection Report CVE-2025-8123 Stars
deer-wms-2 525b6cf SQL injection Report CVE-2025-8124 Stars
deer-wms-2 525b6cf SQL injection Report CVE-2025-8125 Stars
deer-wms-2 525b6cf SQL injection Report CVE-2025-8126 Stars
deer-wms-2 525b6cf SQL injection Report CVE-2025-8127 Stars
deer-wms-2 525b6cf SQL injection Report CVE-2025-8161 Stars
deer-wms-2 525b6cf SQL injection Report CVE-2025-8162 Stars
deer-wms-2 525b6cf SQL injection Report CVE-2025-8163 Stars
letao 7d8df03 Arbitrarily File Upload Report CVE-2025-8128 Stars
ChanCMS <3.1.3 Arbitrary File Deletion Report CVE-2025-8132 Stars
ChanCMS <3.1.3 SSRF Report CVE-2025-8133 Stars
ChanCMS <3.1.3 SSRF Report CVE-2025-8228 Stars
ChanCMS <3.1.3 RCE Report CVE-2025-8266 Stars
ChanCMS <3.1.3 RCE Report CVE-2025-8227 Stars
ChanCMS <3.1.3 Information Disclosure Report CVE-2025-8226 Stars
eladmin <=2.7 Druid Credential Hardcoded Report CVE-2025-8530 Stars
favorites-web <=1.3.0 SSRF Report CVE-2025-8529 Stars
xboot <=3.3.4 Sensitive Info is included in Cookies Report CVE-2025-8528 Stars
xboot <=3.3.4 SSRF Report CVE-2025-8527 Stars
xboot <=3.3.4 Arbitrarily File Upload Report CVE-2025-8526 Stars
xboot <=3.3.4 Info Disclosure Report CVE-2025-8525 Stars
PyBBS <=6.0.0 CAPTCHA reuse Vulnerability Report CVE-2025-8546 Stars
PyBBS <=6.0.0 Registration email is not verified Report CVE-2025-8547 Stars
PyBBS <=6.0.0 No password security policy Report CVE-2025-8549 Stars
PyBBS <=6.0.0 Enumerate registered emails Report CVE-2025-8548 Stars
PyBBS <=6.0.0 Reflected XSS - /admin/topic/list Report CVE-2025-8550 Stars
PyBBS <=6.0.0 Reflected XSS - /admin/comment/list Report CVE-2025-8551 Stars
PyBBS <=6.0.0 Reflected XSS - /admin/tag/list Report CVE-2025-8552 Stars
PyBBS <=6.0.0 Reflected XSS - /admin/sensitive_word/list Report CVE-2025-8553 Stars
PyBBS <=6.0.0 Reflected XSS - /admin/user/list Report CVE-2025-8554 Stars
PyBBS <=6.0.0 Reflected XSS - /search Report CVE-2025-8555 Stars
PyBBS <=6.0.0 Stored XSS Report CVE-2025-8812 Stars
PyBBS <=6.0.0 Open Redirect Report CVE-2025-8813 Stars
PyBBS <=6.0.0 CSRF - modify user info Report CVE-2025-8814 Stars
PyBBS <=6.0.0 CSRF - delete account Report Submission Merged Stars
microservices-platform <=6.0.0 Insecure File Upload Report CVE-2025-8841 Stars
microservices-platform <=6.0.0 Open Redirect Report CVE-2025-8737 Stars
microservices-platform <=6.0.0 Information Disclosure Report CVE-2025-8738 Stars
My-Blog <=1.0.0 CSRF Report CVE-2025-8739 Stars
My-Blog <=1.0.0 Stored XSS Report CVE-2025-8740 Stars
My-Blog <=1.0.0 Stored XSS Report CVE-2025-9101 Stars
My-Blog <=1.0.0 Stored XSS Report duplicate Stars
My-Blog <=1.0.0 CAPTCHA reuse vulerability Report CVE-2025-9100 Stars
litemall <=1.8.0 Insecure File Upload Report CVE-2025-8965 Stars
litemall <=1.8.0 Logic vulerability Report CVE-2025-8991 Stars
mblog <=3.5.0 No CSRF protection Report CVE-2025-8992 Stars
mblog <=3.5.0 Username & Password Enum Report duplicate Stars
mblog <=3.5.0 Password Enum Report CVE-2025-9004 Stars
mblog <=3.5.0 Usename Enum & Batch registration Report CVE-2025-9005 Stars
mblog <=3.5.0 Email Enumeration Report CVE-2025-8927 Stars
mblog <=3.5.0 Stored XSS Report CVE-2025-9407 Stars
mblog <=3.5.0 Stored XSS Report CVE-2025-9429 Stars
mblog <=3.5.0 Stored XSS Report Merged-2025-9429 Stars
mblog <=3.5.0 Stored XSS Report CVE-2025-9430 Stars
mblog <=3.5.0 Reflected XSS Report CVE-2025-9431 Stars
mblog <=3.5.0 Reflected XSS Report CVE-2025-9432 Stars
mblog <=3.5.0 Reflected XSS Report CVE-2025-9433 Stars
mblog <=3.5.0 Reflected XSS Report CVE-2025-9647 Stars
mblog <=3.5.0 SSTI Report duplicate Stars
tianti <=2.3.0 Insecure File Upload (guest) Report rejected Stars
tianti <=2.3.0 Insecure File Upload Report CVE-2025-9795 Stars
tianti <=2.3.0 SSRF Report rejected Stars
expressCart <=1.0.0 Frame Injection Report CVE-2025-9797 Stars
sim <=1.0.0 Insecure File Upload Report CVE-2025-9800 Stars
sim <=1.0.0 Arbitrary File Deletion Report CVE-2025-9801 Stars
sim <=1.0.0 SSRF Report CVE-2025-10096 Stars
sim <=1.0.0 RCE Report CVE-2025-10097 Stars
PowerJob <=5.1.2 SSRF Report CVE-2025-14518 Stars
AIAS <=1.0.0 SSRF Report duplicate Stars
AIAS <=1.0.0 SSRF Report duplicate Stars
FlyCms <=1.0.0 XSS Report CVE-2025-15093 Stars
FlyCms <=1.0.0 XSS Report CVE-2025-15094 Stars
HttpBin <=0.6.1 XSS Report CVE-2025-15095 Stars
-- <=0.6.1 Insecure Deserialization Report rejected Stars
CacheCloud <=3.2.0 Reflected XSS Report CVE-2025-15145 Stars
CacheCloud <=3.2.0 Reflected XSS Report CVE-2025-15146 Stars
CacheCloud <=3.2.0 Reflected XSS Report CVE-2025-15171 Stars
CacheCloud <=3.2.0 Reflected XSS Report CVE-2025-15172 Stars
CacheCloud <=3.2.0 Reflected XSS Report CVE-2025-15173 Stars
CacheCloud <=3.2.0 Reflected XSS Report CVE-2025-15174 Stars
CacheCloud <=3.2.0 Reflected XSS Report CVE-2025-15175 Stars
CacheCloud <=3.2.0 Reflected XSS Report CVE-2025-15200 Stars
CacheCloud <=3.2.0 Reflected XSS Report CVE-2025-15201 Stars
CacheCloud <=3.2.0 Reflected XSS Report CVE-2025-15202 Stars
CacheCloud <=3.2.0 Reflected XSS Report CVE-2025-15203 Stars
CacheCloud <=3.2.0 Reflected XSS Report CVE-2025-15204 Stars
CacheCloud <=3.2.0 Reflected XSS Report CVE-2025-15219 Stars
CacheCloud <=3.2.0 Reflected XSS Report Merged-2025-15219 Stars
CacheCloud <=3.2.0 Reflected XSS Report CVE-2025-15220 Stars
CacheCloud <=3.2.0 Reflected XSS Report CVE-2025-15221 Stars
CacheCloud <=3.2.0 Reflected XSS Report Merged-2025-151757 Stars
CacheCloud <=3.2.0 Reflected XSS Report Merged-2025-152000 Stars
CacheCloud <=3.2.0 Reflected XSS Report Merged-2025-152000 Stars
WP Plugin WP Enable WebP <= 1.0 RCE Report CVE-2025-15158 -
WP Link Hopper <= 2.5 Stored-XSS Report CVE-2025-15483 -
WP Kunze Law <= 2.1 Stored-XSS Report CVE-2025-15486 -
WP Plugin Double the Donation <=2.0.0 Stored XSS Report CVE-2025-12020 -
WP Plugin YouTube Subscribe <=3.0.0 Stored XSS Report CVE-2025-12025 -
WP Plugin Featured Image <=2.1 Stored XSS Report CVE-2025-12019 -
WP Plugin MembershipWorks <=6.14 Stored XSS Report CVE-2025-12018 -
WP Plugin Custom Html Bodyhead <=0.51 Stored XSS Report duplicate -
WP Plugin Terms of Service & Privacy Policy Generator <=1.0 Stored XSS Report duplicate -
WP Plugin Sirvoy Booking Engine <= 5.0 Stored XSS Report rejected -
WordPress Core <= 6.8.2 Stored XSS Report rejected -

πŸ“– Report Structure

Each vulnerability report typically includes the following sections:

  • Vulnerability Overview
  • Technical Details
  • Impact Assessment
  • Reproduction Steps

πŸ” How to Use

  1. Browse the Vulnerability Report List to find reports of interest
  2. Each report is located in its own directory with complete analysis documentation
  3. Related PoC code and remediation guidelines can be found in the report directory

🀝 Contributing Guidelines

We welcome community contributions:

  • Report errors or provide additional information
  • Improve documentation quality
  • Share experiences with similar vulnerabilities
  • Suggest additional mitigation measures

Please submit your contributions through Issues or Pull Requests.

⚠️ Disclaimer

  • All vulnerability information is provided for educational and defensive purposes only
  • Ensure you have proper authorization before using any PoC code
  • We are not responsible for any damages resulting from misuse of this information

πŸ“¬ Contact Us


Maintained by ZAST.AI Team

Dedicated to Building a More Secure Open Source Ecosystem.

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors