Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

marceljm — Vulnerabilities & Security Advisories 8

Browse all 8 CVE security advisories affecting marceljm. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Marceljm focuses on web application security research, primarily identifying vulnerabilities in open-source software and popular platforms. Their work commonly exposes remote code execution, cross-site scripting, and privilege escalation flaws, with a particular emphasis on authentication bypasses and insecure direct object references. The researcher maintains a consistent track record of responsibly disclosing critical issues, contributing to the security of widely-used systems. While no major public incidents are directly attributed to marceljm, their CVE portfolio demonstrates a pattern of discovering high-impact vulnerabilities that could lead to complete system compromise if unpatched. Their findings have frequently addressed security gaps in content management systems and e-commerce platforms.

Top products by marceljm: Featured Image from URL (FIFU)
CVE ID Title CVSS Severity Published
CVE-2025-13393 Featured Image from URL (FIFU) <= 5.3.1 - Authenticated (Contributor+) Server-Side Request Forgery via 'fifu_input_url' — Featured Image from URL (FIFU) CWE-918 4.3 Medium 2026-01-10
CVE-2025-7400 Featured Image from URL (FIFU) <= 5.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Featured Image Custom Fields — Featured Image from URL (FIFU) CWE-79 6.4 Medium 2025-10-07
CVE-2025-10036 Featured Image from URL (FIFU) <= 5.2.7 - Authenticated (Admin+) SQL Injection — Featured Image from URL (FIFU) CWE-89 4.9 Medium 2025-09-26
CVE-2025-9984 Featured Image from URL (FIFU) <= 5.2.7 - Missing Authorization to Password Protected Post Disclosure — Featured Image from URL (FIFU) CWE-862 5.3 Medium 2025-09-26
CVE-2025-9985 Featured Image from URL (FIFU) <= 5.2.7 - Unauthenticated Information Exposure via Log File — Featured Image from URL (FIFU) CWE-532 5.3 Medium 2025-09-26
CVE-2025-10037 Featured Image from URL (FIFU) <= 5.2.7 - Authenticated (Admin+) SQL Injection — Featured Image from URL (FIFU) CWE-89 4.9 Medium 2025-09-26
CVE-2024-1496 Featured Image from URL (FIFU) <= 4.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via fifu_input_url — Featured Image from URL (FIFU) CWE-79 6.4 Medium 2024-02-20
CVE-2023-6561 Featured Image from URL (FIFU) <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via featured image alt text — Featured Image from URL (FIFU) CWE-79 6.4 Medium 2024-01-11

This page lists every published CVE security advisory associated with marceljm. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.