PXL Security LTD, Sofia, Bulgaria Offensive security since 2014[email protected]

Security research

We find the bugs — and we report them.

Beyond client engagements, our team researches the software the world runs on. Every vulnerability below was discovered by the PXL Security team and responsibly disclosed to the vendor, with a public CVE record.

Published CVEs

A selection of vulnerabilities credited to the PXL Security team. Each links to its public record. We publish advisories only after a fix is available or disclosure timelines have elapsed.

CVEAffected softwareClassYear
CVE-2025-50674 OpenMediaVault 7.4.17 Local privilege escalation 2025
CVE-2024-33911 Weblizar School Management Pro SQL injection 2024
CVE-2024-32136 BWL Advanced FAQ Manager SQL injection 2024
CVE-2024-31370 WordPress AIKit plugin SQL injection 2024
CVE-2024-30240 Typps Calendarista (≤ 15.5.7) SQL injection 2024
CVE-2024-0566 Smart Manager (WP, < 8.28.0) SQL injection 2024
CVE-2024-0405 Burst Statistics (WP, 1.5.3) SQL injection 2024
CVE-2024-0399 WooCommerce Customers Manager (< 29.7) SQL injection 2024
CVE-2024-0365 Fancy Product Designer (WP, < 6.1.5) SQL injection 2024
CVE-2023-0830 EasyNAS 1.1.0 OS command injection 2023

Responsible disclosure is part of how we work. If you believe you've found a vulnerability in something we build, email [email protected].