Browse all 4 CVE security advisories affecting Max Chirkov. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Max Chirkov focuses on identifying and analyzing vulnerabilities in enterprise software and web applications, with a core use case centered on improving software security postures. Historically, their research has concentrated on remote code execution, cross-site scripting, and privilege escalation vulnerabilities, particularly in content management systems and e-commerce platforms. While no major public security incidents are directly attributed to Chirkov, their contributions include four CVE disclosures that addressed critical flaws in widely used software. Their work demonstrates a consistent focus on identifying exploitable weaknesses in complex systems, with an emphasis on practical remediation strategies for development teams.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-49438 | WordPress Simple Login Log plugin <= 1.1.3 - PHP Object Injection vulnerability — Simple Login LogCWE-502 | 8.1 | High | 2025-08-20 |
| CVE-2025-25082 | WordPress flexIDX Home Search plugin <= 2.1.2 - Stored Cross Site Scripting (XSS) vulnerability — FlexIDX Home SearchCWE-79 | 6.5 | Medium | 2025-02-07 |
| CVE-2023-26520 | WordPress Advanced Text Widget plugin <= 2.1.2 - Broken Access Control vulnerability — Advanced Text WidgetCWE-862 | 5.3 | Medium | 2024-12-09 |
| CVE-2023-26539 | WordPress Advanced Text Widget Plugin <= 2.1.2 is vulnerable to Cross Site Scripting (XSS) — Advanced Text WidgetCWE-79 | 5.9 | Medium | 2023-06-22 |
This page lists every published CVE security advisory associated with Max Chirkov. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.