Security Research

Security research, vulnerability analysis, technical experiments, and responsible disclosure work documented from hands-on learning.

An unauthenticated arbitrary file upload vulnerability in the SP Page Builder extension for Joomla versions prior to 6.6.2. The vulnerability allows remote attackers to upload and execute arbitrary PHP files without authentication. CVSS score: 10.0.

Joomla File Upload Python
Details

A critical unauthenticated arbitrary file upload vulnerability in the Forminator Forms plugin for WordPress versions up to and including 1.56.1. Insufficient file type validation in the handle_file_upload function allows remote attackers to upload PHP files. CVSS score: 9.8.

WordPress File Upload Python
Details

Two chained vulnerabilities in PaperCut NG/MF print management software: an authentication bypass (CVE-2026-81578, CVSS 8.8) and an unsafe dynamic class loading issue (CVE-2026-82078, CVSS 9.4). Both were added to CISA's Known Exploited Vulnerabilities catalog.

PaperCut Auth Bypass Python
Details