Browse all 5 CVE security advisories affecting Greg Ross. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Greg Ross focuses on web application security research, identifying vulnerabilities in enterprise software. His CVE history primarily reveals Remote Code Execution (RCE) and Cross-Site Scripting (XSS) flaws, with occasional privilege escalation weaknesses. Ross demonstrates a consistent pattern of uncovering authentication bypass issues in popular content management systems. His research has led to multiple high-severity patches, though no major public security incidents are directly attributed to his findings. His work primarily impacts organizations using vulnerable open-source platforms, with his contributions consistently improving defensive postures against common web attack vectors.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-30803 | WordPress Just Writing Statistics plugin <= 5.3 - Broken Access Control vulnerability — Just Writing StatisticsCWE-862 | 4.3 | Medium | 2025-03-27 |
| CVE-2024-56250 | WordPress Just Writing Statistics plugin <= 4.7 - SQL Injection vulnerability — Just Writing StatisticsCWE-89 | 7.6 | High | 2025-01-02 |
| CVE-2024-52390 | WordPress CYAN Backup plugin <= 2.5.3 - Arbitrary File Download vulnerability — CYAN BackupCWE-35 | 4.9 | Medium | 2024-11-18 |
| CVE-2023-40556 | WordPress Schedule Posts Calendar Plugin <= 5.2 is vulnerable to Cross Site Request Forgery (CSRF) — Schedule Posts CalendarCWE-352 | 4.3 | Medium | 2023-10-06 |
| CVE-2023-40560 | WordPress Schedule Posts Calendar Plugin <= 5.2 is vulnerable to Cross Site Scripting (XSS) — Schedule Posts CalendarCWE-79 | 5.9 | Medium | 2023-09-06 |
This page lists every published CVE security advisory associated with Greg Ross. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.