cydave

cydave is a security researcher credited with 89 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #76 of 3,515 contributors. Their disclosures were published between 2022 and 2023. The most productive year was 2022, with 84 findings.

Their research concentrates on SQL Injection, which accounts for 43 of their findings (48%). Other recurring categories include Cross-Site Scripting, Unrestricted Upload Of File With Dangerous Type. The average CVSS score across these disclosures is 8.3, peaking at 9.8. Severity breakdown: 46 critical and 14 high.

The most affected software includes Awin Data Feed (2), BadgeOS (2), 3D Product configurator for WooCommerce (1), across 87 distinct plugins, themes and core versions in total.

72 of the 89 disclosed issues have a vendor fix, while 17 remain unpatched. The most severe finding, "Bitcoin / AltCoin Payment Gateway for WooCommerce <= 1.7.2 - Unauthenticated SQL Injection", scores 9.8 out of 10.

20222023
Critical
High
Medium
Low
Global Rank

#76

of 3,515 researchers

Vulns

89

Critical46
High14
Medium29
Low0
Affected Assets

87

87plugins
Avg CVSS

8.3

Average score of vulnerabilities

Researcher Submissions

89 records
2023-04-17 00:00CVE-2022-4118
9.8
Critical
cydaveYes
2023-02-13 00:00CVE-2022-4328
9.8
Critical
cydaveYes
2023-01-20 00:00CVE-2022-4445
9.8
Critical
cydaveNo
2023-01-16 00:00CVE-2022-4321
6.1
Medium
cydaveYes
2023-01-04 00:00CVE-2022-4395
9.8
Critical
cydaveYes
2022-12-27 00:00CVE-2022-4305
9.8
Critical
cydaveYes
2022-12-27 00:00CVE-2022-4307
7.2
High
cydaveYes
2022-12-27 00:00CVE-2022-4383
9.8
Critical
cydaveYes
2022-12-26 00:00CVE-2022-4060
9.8
Critical
cydaveNo
2022-12-23 00:00CVE-2022-4295
6.1
Medium
cydaveYes
Showing 1–10 of 89 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C