Global Hacktivity
Public, curated security activity across the platform.
Authenticated SQL Injection via nested eager-loading criteria
Authenticated SQL Injection via nested eager-loading criteria
GQL entry mutation siteId bypasses schema site scope
GQL entry mutation `siteId` bypasses schema site scope, enabling cross-site content read/write/delete.
Arbitrary user password reset leading to administrator account takeover
The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the attacker to change other users’ passwords if the attacker’s account has `Edit users` permission (which doesn’t allow changing others’ passwords) and lacks `Administrate users` permission (which is required to change others’ passwords).
Authenticated RCE through Twig sandbox escape
The Twig sandbox mechanism in Craft CMS is configured to allow dangerous functionality from the Yii framework, leading to authenticated RCE similar to previously disclosed vulnerabilities.
Authenticated RCE via `condition.config` JSON cleanse bypass
Craft CMS has an authenticated remote code execution issue in the control panel element-search condition handling. Craft cleans the outer request-controlled condition array with `Component::cleanseConfig()`, but `Conditions::createCondition()` later decodes and merges the JSON string in `condition.config` without re-running `cleanseConfig()` on the decoded/merged configuration. Because `condition.config` is a JSON string during the first cleanse, Yii special config keys such as `as ...` and `on ...` can be hidden inside it. After JSON decoding, those keys reach FieldLayout object creation and are interpreted by Yii as behavior/event configuration.
Insufficient Origin Validation in Proctorio Chrome Extension postMessage Handlers
The Proctorio Chrome Extension contains multiple window.addEventListener('message', ...) handlers that do not properly validate the origin of incoming messages. Specifically, an internal messaging bridge processes messages based solely on the presence of a fromWebsite property without verifying the event.origin attribute resulting in unauthorized interaction with extension functionality.
CSRF at Self-close report function
It's important to note, that the lack of CSRF protection is generally out of scope, but I reported it, because this request is just a simple GET method. An attacker is able to craft an URL, what contains the ID of a report, and if the user, who has access to the report, clicks on it, the report is being self closed.
Cloudflare Transform via URL Injection (Potential SSRF Vulnerability)
A potential Server-Side Request Forgery (SSRF) vulnerability was identified in the Cloudflare image transformation feature via URL injection on the domain https://www.hckrt.com. The service allows arbitrary URLs to be processed through the /cdn-cgi/image/ endpoint, which may permit unauthorized internal or external requests.
About this feed
Global Hacktivity highlights selected security events published by the platform.
- Public by default
- Curated content only
- No sensitive details exposed
Submission policy
CVE coordination
Eligible, approved Hacktivity publications can follow Hackrate’s coordinated CNA process.
How CVE support worksHackrate
Our platform helps companies to identify software vulnerabilities in a cost-efficient way. It provides a secure and centralized view of ethical hacking projects for your company.
US Patent Applied for HackGATE #63/645,845
Products
From the Blog
-
Hackrate Ranked 1st in Hungary and 22nd Globally at Hack The Box’s Global Cyber Skills Benchmark 2026
May 29 • 13 min read
-
Press release: Hackrate becomes Hungary’s first CVE Numbering Authority
Jan 13 • 5 min read ★
-
Let 2026 be the year bug bounty becomes part of how you build and operate
Jan 05 • 4 min read