Sign in

CryptoCat

@cryptocat.me
518 followers 86 following 175 posts

Security Researcher @rapid7.com 😈 Hacking Content @ yt.cryptocat.me 💜

PostsRepliesMedia
CryptoCat @cryptocat.me · 13h
On a wpForo forum with guest editing enabled, an attacker could take over someone else's guest post just by knowing their email. The ownership check trusted an unsigned WordPress comment cookie 🍪 cryptocat.me/blog/researc...
cryptocat.me
wpForo Forum Guest Post Takeover via a Forged Ownership Cookie | CVE-2026-91092 | CryptoCat's Blog
How wpForo let anyone who knew a guest author's email rewrite that author's forum post by forging the WordPress comment author cookie, and what the 3.1.6 fix changed.
001
CryptoCat @cryptocat.me · 25/09/2026
Never seen a con upload talks as fast as BruCON 🔥 I was super nervous for this ngl. Planning to record a better run at some stage, but for now if you wanna check out the live one - here it is! 💌 youtu.be/NkM4UT2z0wc
youtu.be
BruCON 0x12 Jonah Burgess
YouTube video by BruCON Security Conference
000
CryptoCat @cryptocat.me · 21/09/2026
To read private chat rooms in Better Messages, just tell it you're the AI bot. Identity was an IP-prefix check, and the IP came from a request header 🤖 cryptocat.me/blog/researc...
cryptocat.me
Better Messages Unauthenticated Information Exposure via a Spoofed AI Bot Identity | CVE-2026-89093 | CryptoCat's Blog
Root cause analysis of CVE-2026-89093 in Better Messages, where an unauthenticated guest sets a request header to impersonate the plugin's AI chat bot, passing every chat room permission check to read...
012
CryptoCat @cryptocat.me · 19/09/2026
Found an SQL injection in WCFM Marketplace, the WooCommerce multivendor plugin. A guest's checkout coordinates flow straight into a store-distance query, enough to read WordPress password hashes. CVE-2026-18442, fixed in 3.8.2, $134 bounty. cryptocat.me/blog/researc...
cryptocat.me
WCFM Marketplace Unauthenticated SQL Injection via Checkout Distance Shipping | CVE-2026-18442 | CryptoCat's Blog
Root cause analysis of CVE-2026-18442 in WCFM Marketplace, where unauthenticated checkout delivery coordinates reached a store-distance SQL query and allowed a blind read of WordPress password hashes.
000
CryptoCat @cryptocat.me · 18/09/2026
I can't believe it's not XSS! 😱 cryptocat.me/blog/researc...
cryptocat.me
Amelia Missing Authorization to Limited Account Takeover | CVE-2026-14311 | CryptoCat's Blog
Root cause analysis of CVE-2026-14311 in Amelia, where a customer endpoint authenticated the provider token but never checked which customer the provider owned, letting any Employee read, edit, and re...
000
CryptoCat @cryptocat.me · 16/09/2026
Got something different for y'all today! j/k, it's more XSS 😅 cryptocat.me/blog/researc...
cryptocat.me
Better Messages Unauthenticated Reflected XSS in the Live Chat Builder Preview | CVE-2026-18555 | CryptoCat's Blog
Root cause analysis of CVE-2026-18555 in Better Messages, where the Live Chat Builder preview rendered an SVG icon from a GET parameter through a regex sanitiser that a browser could parse back into a...
000
CryptoCat @cryptocat.me · 15/09/2026
Another day, another XSS. Got $5 for this one! 🤑 cryptocat.me/blog/researc...
cryptocat.me
Job Postings Contributor Stored XSS via the position_button Field | CVE-2026-18063 | CryptoCat's Blog
Root cause analysis of CVE-2026-18063 in the Job Postings WordPress plugin, where a 2.8.1 escaping change left the position_button field unescaped and gave a Contributor stored XSS that fires in an ad...
000
CryptoCat @cryptocat.me · 11/09/2026
An unauth stored XSS I found was disclosed yesterday. TLDR: X-Forwarded-For header gets logged as your IP without ever being checked, then runs in the admin's browser when they open the error log 😈 cryptocat.me/blog/researc...
cryptocat.me
WP Photo Album Plus Unauthenticated Stored XSS via Error Log Injection | CVE-2026-18579 | CryptoCat's Blog
Root cause analysis of CVE-2026-18579 in WP Photo Album Plus, where an unauthenticated X-Forwarded-For header became the acting user in the error log and ran as script when an administrator opened the...
030
CryptoCat @cryptocat.me · 07/09/2026
An XSS I reported in Ninja Forms was publicly disclosed recently 🐱‍👤 cryptocat.me/blog/researc...
cryptocat.me
Ninja Forms Unauthenticated Stored XSS via Repeater Child Type Confusion | CVE-2026-19769 | CryptoCat's Blog
How a gap in Ninja Forms repeater validation let anonymous visitors create a script-bearing HTML file on the site's own origin when File Uploads was active.
010
CryptoCat @cryptocat.me · 03/09/2026
Writeup coming soon 😼
unauth rce
000
CryptoCat @cryptocat.me · 31/08/2026
Having fun on @hacker0x01.bsky.social lately 👀
h1 grind
010
CryptoCat @cryptocat.me · 30/08/2026
Long name make ZIP go brrrr cryptocat.me/blog/researc...
cryptocat.me
libarchive ZIP Writer Heap Out-of-Bounds Write via Oversized Pathname | CVE-2026-45308 | CryptoCat's Blog
Root cause analysis of CVE-2026-45308 in libarchive, where the ZIP writer copies an oversized entry pathname into a fixed 64 KiB central-directory buffer and writes past the end of it.
011
CryptoCat @cryptocat.me · 28/08/2026
First bounty on @yeswehack.bsky.social! 💜 Found an info disclosure vuln that leaked 50k+ users details, incl name/DOB/phone/address/passport etc 😎
ywh bountyplz
010
CryptoCat @cryptocat.me · 27/08/2026
So nice to catch up with my good friend Max on the latest episode of the @rapid7.com podcast 💜 Tune in if you wanna hear all about his awesome WhatsApp research, presented at the last TWO (!!!) @defcon.bsky.social's 🔥 youtu.be/7sQyReuwZOo
youtu.be
Hacktics & Telemetry, E13: Courtroom Prompt Injections and WhatsApp's Blind Spots (ft. Max Günther)
YouTube video by Rapid7
000
CryptoCat @cryptocat.me · 27/08/2026
Last year, I tried to analyse a new CVE in ASUS routers. In the process, I found a patch bypass for another CVE. It's quite a long [tutorial-y] writeup from what feels like a distant time away, before I ever touched claude/codex etc 😅 cryptocat.me/blog/researc...
cryptocat.me
ASUS Router bwdpi SQL Injection Patch Bypass | CVE-2026-11851 | CryptoCat's Blog
Root cause analysis of CVE-2026-11851 in ASUS router firmware, where existing input validation failed to prevent an authenticated bwdpi SQL injection.
010
CryptoCat @cryptocat.me · 25/08/2026
A stored XSS I reported in MetForm (600k+ active installs) was disclosed yesterday! 🙏 cryptocat.me/blog/researc...
cryptocat.me
MetForm Contributor Stored XSS via the mf_form_id Widget Setting | CVE-2026-18100 | CryptoCat's Blog
Root cause analysis of CVE-2026-18100 in MetForm, where a non-numeric mf_form_id widget setting is echoed into a JavaScript template that the plugin compiles in the browser, giving a Contributor store...
000
CryptoCat @cryptocat.me · 17/08/2026
Write-up for a (out of scope 😕) stored XSS [A]I found in the Quiz and Survey Master plugin 😼 cryptocat.me/blog/researc...
cryptocat.me
Quiz and Survey Master Stored XSS via question_title | CVE-2026-11780 | CryptoCat's Blog
Root cause analysis of CVE-2026-11780 in Quiz and Survey Master, where the REST question-create endpoint stored an unsanitised question_title that the Question Bank rendered as raw HTML for administra...
000
CryptoCat @cryptocat.me · 13/08/2026
Bonus episode of the @rapid7.com podcast this week! @stephenfewer.bsky.social joins @fulmetalpackets.bsky.social and myself to talk about all things #Pwn2Own 😎 I also show off a P2O inspired CTF challenge I made for @hackinghub.bsky.social, you can still play today! youtu.be/Dnx9yDwXCiE
youtu.be
Hacktics & Telemetry, E12: Pwn2Own, AI in Exploit Chains & Brother Printer Hacks (ft. Stephen Fewer)
YouTube video by Rapid7
010
CryptoCat @cryptocat.me · 10/08/2026
Write-up for a stored XSS [A]I found in the UsersWP plugin 👇 cryptocat.me/blog/researc...
cryptocat.me
UsersWP Stored XSS via Badge Variable Substitution | CVE-2026-18501 | CryptoCat's Blog
Root cause analysis of CVE-2026-18501 in UsersWP, where the badge renderer decodes an entity-encoded Subscriber profile value and outputs it as unescaped HTML.
000
Reposted by CryptoCat
Jorian @jorianwoltjer.com · 09/08/2026
What started with a simple question on Discord, ended in *reviving an old XS-Leak technique* for probing status codes in background requests! Unravel the mystery with me in the latest @ctbbpodcast.bsky.social blog post: lab.ctbb.show/research/sol...
https://lab.ctbb.show/research/solving-an-orb-mystery
022
CryptoCat @cryptocat.me · 03/08/2026
Last week I posted about the KindaRails2Shell (CVE-2026-66066) @metasploit-r7.bsky.social module I put together. Here's a @rapid7.com technical analysis to go with it! 💜 www.rapid7.com/blog/post/ra...
rapid7.com
Rapid7
Rapid7 analyzes KindaRails2Shell (CVE-2026-66066), a Ruby on Rails Active Storage vulnerability that can allow attackers to abuse libvips and crafted MAT/HDF5 uploads to read arbitrary files from the ...
000
CryptoCat @cryptocat.me · 31/07/2026
💎 🚄 2️⃣ 🐚 🔜 @metasploit-r7.bsky.social
101
CryptoCat @cryptocat.me · 23/07/2026
WP2Shell coming soon to @metasploit-r7.bsky.social 👀
033
CryptoCat @cryptocat.me · 22/07/2026
Another Essential Addons bug.. with a much smaller bounty! 😁 A Contributor could poison the site-wide Reading Progress bar with JavaScript. Once their post was published, moving over the bar on an unrelated page ran the payload in the visitor's session. cryptocat.me/blog/researc...
cryptocat.me
Essential Addons for Elementor Global Reading Progress Stored XSS | CVE-2026-15156 | CryptoCat's Blog
Root cause analysis of CVE-2026-15156 in Essential Addons for Elementor Lite, where a Contributor-controlled Reading Progress colour is stored globally and rendered without escaping, causing stored XS...
011
CryptoCat @cryptocat.me · 18/07/2026
It might not be RCE in core, but I was awarded an $859 bounty for this bug 🙏 When entering a victim email into a password reset field, you can inject a newline and [silenty] BCC the attacker on the password reset email 😼 cryptocat.me/blog/researc...
cryptocat.me
Essential Addons for Elementor Email Header Injection to Admin Account Takeover | CVE-2026-15155 | CryptoCat's Blog
Root cause analysis of CVE-2026-15155 in Essential Addons for Elementor Lite, where a Contributor-controlled Login/Register widget setting injects a Bcc header into the administrator password reset em...
011
CryptoCat @cryptocat.me · 14/07/2026
Another day, another WP plugin writeup 🫡 cryptocat.me/blog/researc...
cryptocat.me
Contact Form Entries Unauthenticated Arbitrary File Copy to File Read | CVE-2026-9145 | CryptoCat's Blog
Root cause analysis of CVE-2026-9145 in Contact Form Entries, where the 1.5.1 rewrite of create_entry_el() fed an Elementor upload field's raw POST value into PHP copy(), letting an unauthenticated at...
000
CryptoCat @cryptocat.me · 11/07/2026
It took a while, but the third (and final) vulnerability I reported in ProfileGrid has been published 💥 cryptocat.me/blog/researc...
cryptocat.me
ProfileGrid Stored XSS to Admin Account Takeover via Private Messages | CVE-2026-4610 | CryptoCat's Blog
Root cause analysis of CVE-2026-4610 in ProfileGrid, where any Subscriber can store an invisible onclick overlay in another user's private message inbox and turn an admin's next click into a new admin...
021
CryptoCat @cryptocat.me · 15/06/2026
I found a stored XSS in the slideshow feature of Hedgedoc. It was the preview release, so no CVE (or patch), but here's the writeup anyway! 🦔 cryptocat.me/blog/researc...
cryptocat.me
HedgeDoc 2 Stored XSS via Slideshow Reveal Background Iframe | CryptoCat's Blog
Root cause analysis of a stored XSS in HedgeDoc 2's slideshow renderer, where a Reveal data-background-iframe attribute carrying a javascript: URL survives DOMPurify and is later loaded as an iframe s...
020
CryptoCat @cryptocat.me · 12/06/2026
Here's the writeup for CVE-2026-53943, a cache poisoning -> XSS vuln I found in Ghost CMS 👻 cryptocat.me/blog/researc...
cryptocat.me
Ghost CMS Unauthenticated Cache-Poisoning XSS to Account Takeover via x-ghost-preview | CVE-2026-53943 | CryptoCat's Blog
Root cause analysis of CVE-2026-53943 in Ghost CMS, an unauthenticated cache-poisoning XSS where one anonymous request poisons any caching layer in front of Ghost with attacker-controlled JavaScript t...
011
CryptoCat @cryptocat.me · 06/06/2026
An SQLi I found in Photo Gallery by 10Web was disclosed this week! cryptocat.me/blog/researc...
cryptocat.me
Photo Gallery by 10Web Compact Album Second-Order Blind SQL Injection | CVE-2026-9829 | CryptoCat's Blog
Root cause analysis of CVE-2026-9829 in Photo Gallery by 10Web, where compact album shortcode sort direction was stored then later reached an album ORDER BY clause and allowed Contributor+ time-based ...
020
CryptoCat @cryptocat.me · 02/06/2026
Writeup coming 🔜 github.com/TryGhost/Gho...
github.com
Cache-poisoning XSS in Ghost frontend via x-ghost-preview header
### Impact When Ghost is behind a shared caching layer that results in cached content being shared between different visitors (e.g., Fastly, Cloudflare, nginx proxy_cache, and others), an unauth...
000
CryptoCat @cryptocat.me · 30/05/2026
New video about the argument injection bug I found in Gogs! youtu.be/wt6l_5VB91A
youtu.be
Rebase Before Merging? More Like RCE Before Merging (Gogs Zero Day)
YouTube video by CryptoCat
000
CryptoCat @cryptocat.me · 28/05/2026
Found an unpatched RCE in Gogs 👀 Any authenticated user can get code execution on the server through argument injection into git rebase. Full @rapid7.com writeup + #Metasploit module available now! 🔗 www.rapid7.com/blog/post/ve...
RCE via argument injection in Gogs
000
CryptoCat @cryptocat.me · 22/05/2026
New episode of the @rapid7.com podcast! 👀 @stephenfewer.bsky.social joins @fulmetalpackets.bsky.social and myself to talk about the latest SD-WAN auth bypass - available now in the Metasploit framework 😎 www.youtube.com/watch?v=tg4T...
youtube.com
Hacktics and Telemetry, E6: Cisco SD-WAN Zero-Days, Mythos AI Evaluations, and Pwn2Own Drama
YouTube video by Rapid7
011
Reposted by CryptoCat
TrendAI Zero Day Initiative @thezdi.bsky.social · 16/05/2026
That's a wrap on Pwn2Own Berlin 2026! 🏆 $1,298,250 awarded. 47 unique 0-days. 3 days of absolute chaos. And talk about main character energy - congrats to DEVCORE for claiming Master of Pwn with 50.5 points and $505,000 - they never slowed down. See you next year! #Pwn2Own #P2OBerlin
082
CryptoCat @cryptocat.me · 16/05/2026
Quick video about the new SD-WAN Auth bypass (CVE-2026-20182) discovered by @rapid7.com Labs 👀 I say quick, because @stephenfewer.bsky.social will be joining @fulmetalpackets.bsky.social and myself to talk all about it (and more) in the next podcast - dropping Thursday 🔥 youtu.be/_AxRbX_GLiA
youtu.be
Authenticate? No Thanks, I'll Skip It! (CVE-2026-20182)
YouTube video by CryptoCat
000
CryptoCat @cryptocat.me · 15/05/2026
Another bug I found in ProfileGrid was disclosed this week. Broken access control! cryptocat.me/blog/researc...
cryptocat.me
ProfileGrid Missing Authorization Allows Subscriber+ Arbitrary Group Joining | CVE-2026-4609 | CryptoCat's Blog
Root cause analysis of CVE-2026-4609 in ProfileGrid, where a nonce-only AJAX invite flow lets Subscriber-level users add themselves or other registered users to closed and paid groups.
000
Reposted by CryptoCat
TrendAI Zero Day Initiative @thezdi.bsky.social · 14/05/2026
Recapping Day One of #Pwn2Own Berlin 2026! It was an amazing day of research on display with more than $500,000 awarded. Tomorrow looks to be even better. youtu.be/yb29BkA8uO4
youtu.be
Recapping Day One of Pwn2Own Berlin 2026
YouTube video by TrendAI Zero Day Initiative
043
CryptoCat @cryptocat.me · 14/05/2026
Wake up babe, new SD-WAN auth bypass dropped 😼 Stay tuned for the @metasploit-r7.bsky.social module 👀 www.rapid7.com/blog/post/ve...
rapid7.com
CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED)
While researching a critical authentication bypass vulnerability, CVE-2026-20127, which was exploited in-the-wild, Rapid7 Labs discovered a new authentication bypass vulnerability affecting Cisco Cata...
000
CryptoCat @cryptocat.me · 14/05/2026
An SQLi I found in ProfileGrid was disclosed this week. Here's the full writeup and patch review! cryptocat.me/blog/researc...
cryptocat.me
ProfileGrid Subscriber+ SQL Injection via rid Parameter | CVE-2026-4608 | CryptoCat's Blog
Root cause analysis of CVE-2026-4608 in ProfileGrid, where the messaging profile view trusted the rid parameter inside a raw SQL fragment and exposed authenticated SQL injection to Subscriber-level us...
001
CryptoCat @cryptocat.me · 08/05/2026
Did you catch @jorianwoltjer.com's cool XSS chain on RoundCube mail? 👀 If not, you can hear (and see) all about it in the latest episode of the @rapid7.com podcast! youtu.be/A05dD51mLyo
youtu.be
Hacktics and Telemetry, E5: A Masterclass in XSS, The Copyfail Exploit and Metasploit MCP
YouTube video by Rapid7
011
CryptoCat @cryptocat.me · 01/05/2026
An XSS I found in Elementor was disclosed yesterday, here's the writeup! cryptocat.me/blog/researc...
cryptocat.me
Elementor REST API Form-Encoded Stored XSS via _elementor_data | CVE-2026-6127 | CryptoCat's Blog
Root cause analysis of CVE-2026-6127 in Elementor Website Builder, where form-encoded REST API requests bypass _elementor_data sanitisation and lead to Contributor+ stored XSS.
000
CryptoCat @cryptocat.me · 28/04/2026
My writeup for the "Bucket Vault" challenge by @pwnii.bsky.social (@yeswehack.bsky.social) 💜 cryptocat.me/blog/ctf/mon...
cryptocat.me
Signed Directory Traversal via Filename Sanitisation | YesWeHack Dojo: Bucket Vault | CryptoCat's Blog
YesWeHack Dojo #50 writeup: the app checks the original filename, then signs a cleaned-up version of it, letting us turn a public path into directory traversal
001
Reposted by CryptoCat
James Kettle @jameskettle.com · 27/04/2026
We've launched a new free Web Security Academy topic on exploiting AI-powered security scanners! Learn how to use indirect prompt injection to steal data, cause damage & trigger exploit chains! Dive in here: portswigger.net/web-security...
portswigger.net
AI-powered scanner vulnerabilities | Web Security Academy
Application security teams often deploy AI-powered scanners that use Large Language Models (LLMs) to scan web applications for vulnerabilities. While ...
1159
Reposted by CryptoCat
xarkes @xark.es · 23/04/2026
Mozilla says Mythos helped identify 271 vulnerabilities in Firefox 150. I went through the commits, CVEs, and bug links to see what that number really means. My takeaway: relax folks. xark.es/b/mythos-fir...
xark.es
A quick look at Mythos run on Firefox: too much hype?
A closer look at Mozilla's Firefox 150
199
CryptoCat @cryptocat.me · 20/04/2026
My first YT video of 2026! 😳 We'll review @rapid7.com's analysis of CVE-2026-20127 - written by me! 😊 youtu.be/6vgpwr37nR0
youtu.be
This Bug Lets You Skip Cisco SD-WAN Authentication
YouTube video by CryptoCat
000
Reposted by CryptoCat
Rapid7 @rapid7.com · 26/03/2026
▶️ Now Playing: Telecom Sleeper Cells, SD-WAN Bypasses, & LLM Bug Bounties. In Episode 2 of Hacktics and Telemetry, Douglas McKee & @cryptocat.me continue to bring you the latest in cybersecurity news, vuln research, and actionable defensive strategies: r-7.co/4sTbDu5
021
CryptoCat @cryptocat.me · 23/03/2026
My writeup for the "Secret Manager" challenge by zerodaygym (@yeswehack.bsky.social) 🤫 cryptocat.me/blog/ctf/mon...
cryptocat.me
Argument Injection via Wildcard Expansion | YesWeHack Dojo 49: Secret Manager | CryptoCat's Blog
YesWeHack Dojo #49 writeup: exploiting wildcard argument injection in shell cp and grep commands to access internal secrets
001
CryptoCat @cryptocat.me · 17/03/2026
Happy St Patrick's day ☘
☘😺☘
031
Reposted by CryptoCat
Rapid7 @rapid7.com · 12/03/2026
🎤👾 Introducing Hacktics and Telemetry, a bi-weekly video and audio podcast out of Rapid7 Labs, starring Rapid7's Doug McKee (fulmetalpackets) & Jonah Burgess (@cryptocat.me)! 🧵 Find episode 1's companion blog here: r-7.co/4di8tuH ▶️ Or dive right into the full vid on YouTube: r-7.co/3NiQfP2
022