Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Adrian Tobey — Vulnerabilities & Security Advisories 11

Browse all 11 CVE security advisories affecting Adrian Tobey. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Adrian Tobey is primarily associated with identifying vulnerabilities in web applications and enterprise software, with a core focus on uncovering security flaws in widely used systems. Historically, their research has frequently centered on remote code execution, cross-site scripting, and privilege escalation vulnerabilities, contributing significantly to the disclosure of 9 CVEs. Adrian's work often involves thorough analysis of complex software architectures, with a notable emphasis on identifying authentication bypasses and insecure direct object references. While no major public incidents are directly linked to their research, their contributions have consistently addressed critical weaknesses in commercial and open-source products, helping to remediate potential attack vectors before widespread exploitation could occur.

CVE IDTitleCVSSSeverityPublished
CVE-2026-57389 WordPress Groundhogg plugin <= 4.4.1 - Arbitrary File Deletion vulnerability — GroundhoggCWE-22 8.6 High2026-07-13
CVE-2026-57667 WordPress Groundhogg plugin <= 4.5 - SQL Injection vulnerability — GroundhoggCWE-89 8.5 High2026-06-26
CVE-2025-64367 WordPress Groundhogg plugin <= 4.2.6 - Cross Site Scripting (XSS) vulnerability — GroundhoggCWE-79 6.5 Medium2025-10-31
CVE-2025-54053 WordPress Groundhogg plugin <= 4.2.2 - PHP Object Injection vulnerability — GroundhoggCWE-502 6.6 Medium2025-08-20
CVE-2025-48300 WordPress Groundhogg plugin <= 4.2.1 - Arbitrary File Upload vulnerability — GroundhoggCWE-434 9.1 Critical2025-07-16
CVE-2025-47654 WordPress FormLift for Infusionsoft Web Forms plugin <= 7.5.20 - Reflected Cross Site Scripting (XSS) vulnerability — FormLift for Infusionsoft Web FormsCWE-79 7.1 High2025-06-27
CVE-2025-31015 WordPress SMTP Service, Email Delivery Solved! — MailHawk plugin <= 1.3.1 - Local File Inclusion Vulnerability — WordPress SMTP Service, Email Delivery Solved! — MailHawkCWE-98 7.5 High2025-04-11
CVE-2025-31434 WordPress FormLift for Infusionsoft Web Forms plugin <= 7.5.19 - Cross Site Scripting (XSS) Vulnerability — FormLift for Infusionsoft Web FormsCWE-79 6.5 Medium2025-03-28
CVE-2024-56289 WordPress Groundhogg plugin <= 3.7.3.3 - Reflected Cross Site Scripting (XSS) vulnerability — GroundhoggCWE-79 7.1 High2025-01-07
CVE-2024-37235 WordPress Groundhogg plugin <= 3.4.2.3 - Cross Site Request Forgery (CSRF) vulnerability — GroundhoggCWE-352 4.3 Medium2025-01-02
CVE-2024-38773 WordPress formlift plugin <= 7.5.17 - Unauthenticated Blind SQL Injection vulnerability — FormLift for Infusionsoft Web FormsCWE-89 9.3 Critical2024-07-22

This page lists every published CVE security advisory associated with Adrian Tobey. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.