Global Hacktivity

Public, curated security activity across the platform.

Public Curated
Authenticated SQL Injection via nested eager-loading criteria
9/1/2026 9:54:19 PM Craft CMS Vulnerability Disclosure Program HCKRT-B5BSMM
@Uncle_cui233

Authenticated SQL Injection via nested eager-loading criteria

High Details available Resolved
GQL entry mutation siteId bypasses schema site scope
9/1/2026 9:48:10 PM Craft CMS Vulnerability Disclosure Program HCKRT-XEQKMX
@ddme

GQL entry mutation `siteId` bypasses schema site scope, enabling cross-site content read/write/delete.

High Details available Resolved
Arbitrary user password reset leading to administrator account takeover
9/1/2026 9:43:06 PM Craft CMS Vulnerability Disclosure Program HCKRT-ZDSZJH
@he4am

The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the attacker to change other users’ passwords if the attacker’s account has `Edit users` permission (which doesn’t allow changing others’ passwords) and lacks `Administrate users` permission (which is required to change others’ passwords).

High Details available Resolved
Authenticated RCE through Twig sandbox escape
8/27/2026 3:20:10 PM Craft CMS Private Bug Bounty Program HCKRT-8RQQ7K
@oskar-cure53

The Twig sandbox mechanism in Craft CMS is configured to allow dangerous functionality from the Yii framework, leading to authenticated RCE similar to previously disclosed vulnerabilities.

High Details available Resolved
Authenticated RCE via `condition.config` JSON cleanse bypass
8/24/2026 3:00:00 PM Craft CMS Vulnerability Disclosure Program HCKRT-JD662P
@saladin

Craft CMS has an authenticated remote code execution issue in the control panel element-search condition handling. Craft cleans the outer request-controlled condition array with `Component::cleanseConfig()`, but `Conditions::createCondition()` later decodes and merges the JSON string in `condition.config` without re-running `cleanseConfig()` on the decoded/merged configuration. Because `condition.config` is a JSON string during the first cleanse, Yii special config keys such as `as ...` and `on ...` can be hidden inside it. After JSON decoding, those keys reach FieldLayout object creation and are interpreted by Yii as behavior/event configuration.

High Details available Resolved
Insufficient Origin Validation in Proctorio Chrome Extension postMessage Handlers
2/11/2026 3:12:55 PM Proctorio Private Bug Bounty Program 46b61f36-b685-4667-aebf-82a67ad69ad6
@vcc3v

The Proctorio Chrome Extension contains multiple window.addEventListener('message', ...) handlers that do not properly validate the origin of incoming messages. Specifically, an internal messaging bridge processes messages based solely on the presence of a fromWebsite property without verifying the event.origin attribute resulting in unauthorized interaction with extension functionality.

Low Details available Resolved
CSRF at Self-close report function
12/29/2025 5:38:12 PM Hackrate Responsible Disclosure Program 5cb67624-6648-4c87-81f2-691130f95bd7
@Labda

It's important to note, that the lack of CSRF protection is generally out of scope, but I reported it, because this request is just a simple GET method. An attacker is able to craft an URL, what contains the ID of a report, and if the user, who has access to the report, clicks on it, the report is being self closed.

Low Details available Resolved
Cloudflare Transform via URL Injection (Potential SSRF Vulnerability)
12/29/2025 5:38:00 PM Hackrate Responsible Disclosure Program ad5e8ea0-78b1-4b6c-a3be-9132a7308e33
@MRKNIGHTNIDU

A potential Server-Side Request Forgery (SSRF) vulnerability was identified in the Cloudflare image transformation feature via URL injection on the domain https://www.hckrt.com. The service allows arbitrary URLs to be processed through the /cdn-cgi/image/ endpoint, which may permit unauthorized internal or external requests.

Medium Details available Resolved
About this feed

Global Hacktivity highlights selected security events published by the platform.

  • Public by default
  • Curated content only
  • No sensitive details exposed
Submission policy
Only platform administrators can publish items to this global feed. Events are reviewed before becoming public.
CVE coordination

Eligible, approved Hacktivity publications can follow Hackrate’s coordinated CNA process.

How CVE support works
Hackrate

Our platform helps companies to identify software vulnerabilities in a cost-efficient way. It provides a secure and centralized view of ethical hacking projects for your company.

US Patent Applied for HackGATE #63/645,845

Checking service status...

Hackrate Ethical Hacking Platform |
2026 ©

CVE Program Numbering Authority