Below is a list of all the CVEs that I have discovered..
| CVE ID | Type | PoC |
|---|---|---|
| CVE-2026-11518 | Stored XSS | → |
| CVE-2026-11344 | Remote Code Exection | → |
| CVE-2026-10290 | SQL Injection | → |
| CVE-2026-10289 | Stored XSS | → |
| CVE-2026-10288 | Authentication Bypass | → |
| CVE-2026-10243 | Authentication Bypass | → |
| CVE-2026-10170 | Remote Code Execution | → |
| CVE-2026-10110 | SQL Injection | → |
| CVE-2026-7401 | Stored XSS | → |
| CVE-2026-7394 | SQL Injection | → |
| CVE-2026-7393 | Remote Code Execution | → |
| CVE-2026-7229 | SQL Injection | → |
| CVE-2026-7222 | Stored XSS | → |
| CVE-2026-7089 | Cross-Site Scripting | → |
| CVE-2026-7071 | Broken Access Control | → |
| CVE-2026-7028 | SQL Injection | → |
| CVE-2026-6201 | IDOR | → |
| CVE-2026-6184 | XSS | → |
| CVE-2026-6183 | SQL Injection | → |
| CVE-2026-6182 | SQL Injection (Auth) | → |