Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Adrian Tobey — Vulnerabilities & Security Advisories 12

Browse all 12 CVE security advisories affecting Adrian Tobey. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adrian Tobey is primarily associated with identifying vulnerabilities in web applications and enterprise software, with a core focus on uncovering security flaws in widely used systems. Historically, their research has frequently centered on remote code execution, cross-site scripting, and privilege escalation vulnerabilities, contributing significantly to the disclosure of 9 CVEs. Adrian's work often involves thorough analysis of complex software architectures, with a notable emphasis on identifying authentication bypasses and insecure direct object references. While no major public incidents are directly linked to their research, their contributions have consistently addressed critical weaknesses in commercial and open-source products, helping to remediate potential attack vectors before widespread exploitation could occur.

CVE ID Title CVSS Severity Published
CVE-2026-85310 WordPress Groundhogg plugin <= 4.7.1 - Path Traversal vulnerability — Groundhogg CWE-35 6.5 Medium 2026-09-10
CVE-2026-57389 WordPress Groundhogg plugin <= 4.4.1 - Arbitrary File Deletion vulnerability — Groundhogg CWE-22 8.6 High 2026-07-13
CVE-2026-57667 WordPress Groundhogg plugin <= 4.5 - SQL Injection vulnerability — Groundhogg CWE-89 8.5 High 2026-06-26
CVE-2025-64367 WordPress Groundhogg plugin <= 4.2.6 - Cross Site Scripting (XSS) vulnerability — Groundhogg CWE-79 6.5 Medium 2025-10-31
CVE-2025-54053 WordPress Groundhogg plugin <= 4.2.2 - PHP Object Injection vulnerability — Groundhogg CWE-502 6.6 Medium 2025-08-20
CVE-2025-48300 WordPress Groundhogg plugin <= 4.2.1 - Arbitrary File Upload vulnerability — Groundhogg CWE-434 9.1 Critical 2025-07-16
CVE-2025-47654 WordPress FormLift for Infusionsoft Web Forms plugin <= 7.5.20 - Reflected Cross Site Scripting (XSS) vulnerability — FormLift for Infusionsoft Web Forms CWE-79 7.1 High 2025-06-27
CVE-2025-31015 WordPress SMTP Service, Email Delivery Solved! — MailHawk plugin <= 1.3.1 - Local File Inclusion Vulnerability — WordPress SMTP Service, Email Delivery Solved! — MailHawk CWE-98 7.5 High 2025-04-11
CVE-2025-31434 WordPress FormLift for Infusionsoft Web Forms plugin <= 7.5.19 - Cross Site Scripting (XSS) Vulnerability — FormLift for Infusionsoft Web Forms CWE-79 6.5 Medium 2025-03-28
CVE-2024-56289 WordPress Groundhogg plugin <= 3.7.3.3 - Reflected Cross Site Scripting (XSS) vulnerability — Groundhogg CWE-79 7.1 High 2025-01-07
CVE-2024-37235 WordPress Groundhogg plugin <= 3.4.2.3 - Cross Site Request Forgery (CSRF) vulnerability — Groundhogg CWE-352 4.3 Medium 2025-01-02
CVE-2024-38773 WordPress formlift plugin <= 7.5.17 - Unauthenticated Blind SQL Injection vulnerability — FormLift for Infusionsoft Web Forms CWE-89 9.3 Critical 2024-07-22

This page lists every published CVE security advisory associated with Adrian Tobey. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.