type5afe

type5afe is a security researcher credited with 40 disclosed vulnerabilities in the WordSec WordPress vulnerability database, ranked #153 of 3,515 contributors. Their disclosures were published between 2025 and 2026. The most productive year was 2026, with 21 findings.

Their research concentrates on Missing Authorization, which accounts for 14 of their findings (35%). Other recurring categories include Cross-Site Request Forgery (CSRF), SQL Injection. The average CVSS score across these disclosures is 5.4, peaking at 8.1. Severity breakdown: 0 critical and 7 high.

The most affected software includes AI Engine (2), My auctions allegro (2), SureForms (2), across 35 distinct plugins, themes and core versions in total.

All 40 disclosed issues have since received a vendor fix. The most severe finding, "My auctions allegro <= 3.6.32 - Unauthenticated Local File Inclusion via controller", scores 8.1 out of 10.

20252026
Critical
High
Medium
Low
Global Rank

#153

of 3,515 researchers

Vulns

40

Critical0
High7
Medium32
Low1
Affected Assets

35

35plugins
Avg CVSS

5.4

Average score of vulnerabilities

Researcher Submissions

40 records
2026-08-25 00:00CVE-2026-3235
5.3
Medium
type5afeYes
2026-05-27 17:18CVE-2026-7533
4.3
Medium
type5afeYes
2026-05-13 00:00CVE-2026-7525
4.3
Medium
type5afeYes
2026-05-04 18:43CVE-2026-3359
7.5
High
type5afeYes
2026-03-30 21:39CVE-2026-3139
4.3
Medium
type5afeYes
2026-02-25 08:50CVE-2026-2694
5.4
Medium
type5afeYes
2026-02-17 20:36CVE-2026-2126
5.3
Medium
type5afeYes
2026-02-13 19:48CVE-2026-1254
4.3
Medium
type5afeYes
2026-02-12 00:17CVE-2026-1316
7.2
High
type5afeYes
2026-02-05 19:33CVE-2026-1785
4.3
Medium
type5afeYes
Showing 1–10 of 40 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C