Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

shabti — Vulnerabilities & Security Advisories 18

Browse all 18 CVE security advisories affecting shabti. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Shabti is a penetration testing tool designed for AWS environment exploitation, primarily used by security professionals to assess cloud infrastructure vulnerabilities. Historically, it has been associated with multiple critical vulnerabilities including remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws. The tool has accumulated 9 CVEs to date, reflecting its potential for significant security breaches. Shabti's ability to exploit misconfigurations and weaknesses in AWS services has made it notable in security circles, though no major public incidents have been directly attributed to its use. Its continued evolution underscores the ongoing challenges in securing cloud environments against specialized testing tools.

Top products by shabti: Frontend Admin by DynamiApps
CVE ID Title CVSS Severity Published
CVE-2026-75816 Frontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Account Takeover via '_acf_objects' Object Identifier — Frontend Admin by DynamiApps CWE-287 9.8 Critical 2026-09-06
CVE-2026-12747 Frontend Admin by DynamiApps <= 3.29.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'tag' Shortcode Attribute — Frontend Admin by DynamiApps CWE-79 6.4 Medium 2026-09-01
CVE-2026-19952 Frontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Arbitrary File Deletion via Path Traversal via custom_directory_name Merge Tag — Frontend Admin by DynamiApps CWE-22 7.5 High 2026-09-01
CVE-2026-18432 Frontend Admin by DynamiApps <= 3.29.9 - Unauthenticated Privilege Escalation via 'item_id' Parameter — Frontend Admin by DynamiApps CWE-269 9.8 Critical 2026-08-16
CVE-2026-15606 Frontend Admin by DynamiApps <= 3.29.9 - Authenticated (Subscriber+) Arbitrary Password Reset via Encrypted Object Token — Frontend Admin by DynamiApps CWE-862 8.8 High 2026-08-11
CVE-2026-10039 Frontend Admin by DynamiApps <= 3.28.28 - Authenticated (Administrator+) SQL Injection via 'order' Parameter — Frontend Admin by DynamiApps CWE-89 4.9 Medium 2026-05-29
CVE-2026-6226 Frontend Admin by DynamiApps <= 3.29.2 - Unauthenticated Privilege Escalation via Form Configuration Injection — Frontend Admin by DynamiApps CWE-269 8.8 High 2026-05-28
CVE-2026-7802 Frontend Admin by DynamiApps <= 3.29.2 - Missing Authorization to Authenticated (Subscriber+) Account Takeover via 'user_id' URL Query Parameter — Frontend Admin by DynamiApps CWE-862 8.8 High 2026-05-28
CVE-2026-6228 Frontend Admin by DynamiApps <= 3.28.36 - Unauthenticated Privilege Escalation via Edit User Form — Frontend Admin by DynamiApps CWE-269 8.8 High 2026-05-15
CVE-2026-3328 Frontend Admin by DynamiApps <= 3.28.31 - Authenticated (Editor+) PHP Object Injection via 'post_content' of Admin Form Posts — Frontend Admin by DynamiApps CWE-502 7.2 High 2026-03-26
CVE-2025-14741 Frontend Admin by DynamiApps <= 3.28.25 - Missing Authorization to Unauthenticated Arbitrary Data Deletion via 'delete post' Form Element — Frontend Admin by DynamiApps CWE-862 9.1 Critical 2026-01-09
CVE-2025-14937 Frontend Admin by DynamiApps <= 3.28.23 - Unauthenticated Stored Cross-Site Scripting via 'update_field' — Frontend Admin by DynamiApps CWE-79 7.2 High 2026-01-09
CVE-2025-14736 Frontend Admin by DynamiApps <= 3.28.29 - Unauthenticated Privilege Escalation to Administrator via Role Form Field — Frontend Admin by DynamiApps CWE-269 9.8 Critical 2026-01-09
CVE-2025-13342 Frontend Admin by DynamiApps <= 3.28.20 - Unauthenticated Arbitrary Options Update — Frontend Admin by DynamiApps CWE-862 9.8 Critical 2025-12-03
CVE-2024-11722 Frontend Admin by DynamiApps <= 3.25.1 - Unauthenticated SQL Injection — Frontend Admin by DynamiApps CWE-89 5.9 Medium 2024-12-21
CVE-2024-11721 Frontend Admin by DynamiApps <= 3.24.5 - Unauthenticated Privilege Escalation — Frontend Admin by DynamiApps CWE-269 8.1 High 2024-12-14
CVE-2024-11720 Frontend Admin by DynamiApps <= 3.24.5 - Unauthenticated Stored Cross-Site Scripting — Frontend Admin by DynamiApps CWE-79 7.2 High 2024-12-14
CVE-2024-3729 Frontend Admin by DynamiApps <= 3.19.4 - Improper Missing Encryption Exception Handling to Form Manipulation — Frontend Admin by DynamiApps CWE-636 9.8 Critical 2024-05-02

This page lists every published CVE security advisory associated with shabti. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.