Jakub Herman

Jakub Herman is a security researcher credited with 106 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #70 of 3,515 contributors. The disclosure was published in 2026.

Their research concentrates on Missing Authorization, which accounts for 36 of their findings (34%). Other recurring categories include Exposure Of Sensitive Information To An Unauthorized Actor, Code Injection. The average CVSS score across these disclosures is 6.1, peaking at 9.8. Severity breakdown: 7 critical and 31 high.

The most affected software includes Kirki (4), Events Manager (3), Forminator Forms (2), across 98 distinct plugins, themes and core versions in total.

99 of the 106 disclosed issues have a vendor fix, while 7 remain unpatched. The most severe finding, "JetFormBuilder — Dynamic Blocks Form Builder < 3.6.5.2 - Unauthenticated Arbitrary Shortcode Execution", scores 9.8 out of 10.

2026
Critical
High
Medium
Low
Global Rank

#70

of 3,515 researchers

Vulns

106

Critical7
High31
Medium68
Low0
Affected Assets

100

100plugins
Avg CVSS

6.1

Average score of vulnerabilities

Researcher Submissions

106 records
2026-09-08 00:00CVE-2026-75793
5.3
Medium
Jakub HermanYes
2026-09-08 00:00CVE-2026-84219
7.2
High
Jakub HermanYes
2026-09-07 00:00CVE-2026-18480
8.8
High
Jakub HermanYes
2026-09-07 00:00CVE-2026-19858
5.3
Medium
Jakub HermanYes
2026-09-04 00:00CVE-2026-19224
7.2
High
Jakub HermanYes
2026-09-04 00:00CVE-2026-80437
6.5
Medium
Jakub HermanYes
2026-09-03 00:00CVE-2026-80467
7.3
High
Jakub HermanYes
2026-09-03 00:00CVE-2026-80439
6.5
Medium
Jakub HermanYes
2026-09-03 00:00CVE-2026-81583
6.3
Medium
Jakub HermanYes
2026-09-03 00:00CVE-2026-19859
9.8
Critical
Jakub HermanYes
Showing 1–10 of 106 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C