Pricing
Case studies
Login
Start trial
Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity)
19,132.66
XP
949
Reports
0
Reports, last 90 days
#73
3 Sep, 2026
🇻🇳
Lvl 12
5
4
2
17
Website
X
GitHub
Sort by
Priority
Severity
Exploited
Search
Clear
Affected software | Vulnerability
CVE
AXP
Severity
Reported
Jawn
<= 1.4.2
Privilege Escalation
44.1
9.8
15/01/2026
Tonda Core
< 2.6
Local File Inclusion
32.4
8.1
14/01/2026
Tonda
< 2.6
Local File Inclusion
32.4
8.1
14/01/2026
MÃ¥ne
<= 1.7
Local File Inclusion
24.3
8.1
02/02/2026
Verdure Core
<= 1.2
Local File Inclusion
24.3
8.1
02/02/2026
Capella
<= 2.5.5
Privilege Escalation
N/A
9.8
05/01/2026
Capella
<= 2.5.5
SQL Injection
37.2
9.3
05/01/2026
Homlisti
<= 3.1.2
Broken Access Control
6.5
6.5
14/01/2026
DSK
<= 2.1
Cross Site Scripting (XSS)
14.2
7.1
29/03/2025
Valen - Sport, Fashion WooCommerce WordPress Theme
<= 2.4
Cross Site Scripting (XSS)
14.2
7.1
29/03/2025
MBStore - Digital WooCommerce WordPress Theme
<= 2.3
Cross Site Scripting (XSS)
14.2
7.1
29/03/2025
BodyCenter - Gym, Fitness WooCommerce WordPress Theme
<= 2.3
Cross Site Scripting (XSS)
14.2
7.1
29/03/2025
Altair
<= 5.2.2
Broken Access Control
13
6.5
05/01/2026
Total Donations
<= 2.0.5
SQL Injection
37.2
9.3
06/02/2026
Total Donations
<= 2.0.5
Privilege Escalation
N/A
9.8
06/02/2026
Nikstore Core
<= 1.5
SQL Injection
18.6
9.3
05/02/2026
Sidebar & Widget Manager for WordPress
<= 4.7
Cross Site Scripting (XSS)
14.2
7.1
21/04/2025
Portfolio Manager Pro
<= 3.8
Cross Site Scripting (XSS)
14.2
7.1
21/04/2025
Buttons Mega Pack Pro
<= 2.5
Cross Site Scripting (XSS)
14.2
7.1
21/04/2025
Samex - Clean, Minimal Shop WooCommerce WordPress Theme
<= 2.5
Cross Site Scripting (XSS)
14.2
7.1
29/03/2025
M.Anh
<= 1.7
Cross Site Scripting (XSS)
N/A
7.1
27/03/2025
Barista
<= 2.5.1
Local File Inclusion
32.4
8.1
02/02/2026
Foton Core
<= 1.1.1
Local File Inclusion
32.4
8.1
02/02/2026
Biagiotti Core
<= 2.1.1
Local File Inclusion
32.4
8.1
02/02/2026
PIMP - Creative MultiPurpose
<= 1.7
Cross Site Scripting (XSS)
14.2
7.1
31/03/2025
Wigi
<= 2.0.1
Cross Site Scripting (XSS)
N/A
7.1
20/03/2025
Blogfolio
<=3.0.5
Cross Site Scripting (XSS)
N/A
7.1
20/03/2025
Agrion
<= 1.0.0
Cross Site Scripting (XSS)
7.1
7.1
29/01/2026
Blogfolio
<= 3.0.5
Arbitrary File Upload
N/A
9.9
20/03/2025
Civi Framework
<= 2.2.0
Broken Access Control
10.6
5.3
09/02/2026
HTML5 Video Player
<= 5.3.4.0
SQL Injection
12.75
8.5
02/06/2025
Image&Video FullScreen Background
<= 1.6.8
SQL Injection
9.56
8.5
02/06/2025
Logos Showcase
<= 2.5
SQL Injection
9.56
8.5
02/06/2025
PIMP - Creative MultiPurpose
<= 1.7
Cross Site Request Forgery (CSRF)
N/A
4.3
31/03/2025
Grand Photography
<= 5.7.8
Cross Site Scripting (XSS)
14.2
7.1
02/01/2026
Grand Photography
<= 5.7.8
PHP Object Injection
N/A
9.8
02/01/2026
Upking - Hiking Club WordPress Theme
<= 1.4
Broken Access Control
N/A
5.3
31/03/2025
The Restaurant
<= 1.4.1
Broken Access Control
N/A
5.3
29/03/2025
PressGrid - Frontend Publish Reaction & Multimedia Theme
<= 1.3.1
Broken Access Control
N/A
5.3
31/03/2025
Jina - Celebration Agency Theme
<= 1.6
Broken Access Control
N/A
5.3
31/03/2025
Audrey
<= 1.5
Local File Inclusion
24.3
8.1
02/02/2026
Lighthouse
<= 1.2.12
Local File Inclusion
40.5
8.1
24/07/2025
Zegen
<= 1.1.9
Arbitrary File Upload
29.7
9.9
28/10/2025
NanoMag
<= 1.8
Cross Site Scripting (XSS)
14.2
7.1
11/03/2026
Italian Restaurant
<= 3.0.2
Cross Site Scripting (XSS)
7.1
7.1
11/07/2025
CF7 Auto Responder Addon
< 2.5
Broken Access Control
N/A
5.3
02/06/2025
LBG Zoominoutslider
<= 5.4.4
SQL Injection
12.75
8.5
02/06/2025
WP eMember
< v10.9.4
SQL Injection
27.9
9.3
14/09/2025
Potisen
<= 1.2.7
Local File Inclusion
16.2
8.1
24/07/2025
WP eMember
<= v10.2.2
Sensitive Data Exposure
10.6
5.3
12/09/2025
Car Zone
<= 3.7
Arbitrary File Deletion
25.8
8.6
28/10/2025
Wanium
<= 1.9.8
Local File Inclusion
32.4
8.1
28/10/2025
Plumbing
<= 1.6
PHP Object Injection
39.2
9.8
15/10/2025
SeaFood Company
<= 1.4
PHP Object Injection
29.4
9.8
15/10/2025
Reisen
<= 1.4.1
PHP Object Injection
29.4
9.8
15/10/2025
Hot Coffee
<= 1.7
PHP Object Injection
29.4
9.8
15/10/2025
Qreatix
<= 1.9.4
Cross Site Scripting (XSS)
7.1
7.1
15/10/2025
Genemy
<= 1.6.6
Privilege Escalation
19.8
8.8
28/10/2025
Genemy
<= 1.6.6
Broken Access Control
4.88
6.5
28/10/2025
CopyPress
<= 1.4.5
Local File Inclusion
24.3
8.1
15/10/2025
Corbesier
<= 1.15.0
Local File Inclusion
16.2
8.1
15/10/2025
Dazzle
<= 1.0.0
Local File Inclusion
16.2
8.1
15/10/2025
Deliciosa
<= 1.10.0
Local File Inclusion
16.2
8.1
15/10/2025
Snow Club
<= 1.1
Local File Inclusion
16.2
8.1
15/10/2025
Especio
<= 1.0
Local File Inclusion
16.2
8.1
15/10/2025
Food Drop
<= 1.3
Local File Inclusion
16.2
8.1
15/10/2025
Fortius
<= 2.3.0
Local File Inclusion
16.2
8.1
15/10/2025
Raider Spirit
<= 1.1.4
Local File Inclusion
24.3
8.1
15/10/2025
AirSupply
<= 2.0.0
Local File Inclusion
32.4
8.1
15/10/2025
Planty
<= 1.14.0
Local File Inclusion
16.2
8.1
15/10/2025
Nexio
<= 1.10.0
Local File Inclusion
16.2
8.1
15/10/2025
MaxiNet
<= 1.2.10
Local File Inclusion
24.3
8.1
15/10/2025
LuxMed | Medicine & Healthcare Doctor WordPress Theme
<= 1.2.2
Local File Inclusion
16.2
8.1
15/10/2025
Iona
<= 1.0.8
Local File Inclusion
16.2
8.1
15/10/2025
Ingenioso
<= 1.14.0
Local File Inclusion
16.2
8.1
15/10/2025
Modernee
<= 1.6.0
Local File Inclusion
16.2
8.1
15/10/2025
Imba
<= 1.5.0
Local File Inclusion
16.2
8.1
15/10/2025
Rosaleen
<= 2.8
Local File Inclusion
24.3
8.1
15/10/2025
Fermentio
<= 1.5.0
Local File Inclusion
40.5
8.1
24/07/2025
AI Lab
< 5.4.2
PHP Object Injection
29.4
9.8
02/03/2026
Kapee
< 1.7.1
Cross Site Scripting (XSS)
14.2
7.1
02/03/2026
Hitek
< 1.8.3
Local File Inclusion
24.3
8.1
10/02/2026
Solene Core
<= 2.3.2
Local File Inclusion
32.4
8.1
02/02/2026
Solene
<= 3.4
Local File Inclusion
32.4
8.1
02/02/2026
Mr. SEO
<= 2.0
Local File Inclusion
24.3
8.1
02/02/2026
Malmö
<= 2.2
Local File Inclusion
32.4
8.1
02/02/2026
Aperitif
<= 1.5
Local File Inclusion
32.4
8.1
02/02/2026
Sanzo
< 2.4.3
Cross Site Scripting (XSS)
3.25
6.5
15/01/2026
Meloo
< 2.8.2
PHP Object Injection
13.2
8.8
15/01/2026
Jaroti
< 1.4.8
Cross Site Scripting (XSS)
14.2
7.1
15/01/2026
Loobek
< 1.5.2
Cross Site Scripting (XSS)
14.2
7.1
15/01/2026
Miti
< 1.5.3
Cross Site Scripting (XSS)
7.1
7.1
15/01/2026
MyMedi
< 1.7.7
Cross Site Scripting (XSS)
14.2
7.1
15/01/2026
Yobazar
< 1.6.7
Cross Site Scripting (XSS)
14.2
7.1
15/01/2026
Reebox
< 1.4.8
Cross Site Scripting (XSS)
10.65
7.1
15/01/2026
Nooni
< 1.5.1
Cross Site Scripting (XSS)
14.2
7.1
15/01/2026
MyDecor
< 1.5.9
Cross Site Scripting (XSS)
14.2
7.1
15/01/2026
Riode
< 1.6.29
Cross Site Scripting (XSS)
14.2
7.1
29/01/2026
Pendulum
< 3.1.5
PHP Object Injection
17.6
8.8
15/01/2026
Vex
< 1.2.9
PHP Object Injection
8.8
8.8
15/01/2026
1
2
3
4
5
...
9
Report vulnerabilities to earn bounties and rewards!
Read more
Include pending
Back to top