Security research
We find the bugs — and we report them.
Beyond client engagements, our team researches the software the world runs on. Every vulnerability below was discovered by the PXL Security team and responsibly disclosed to the vendor, with a public CVE record.
Published CVEs
A selection of vulnerabilities credited to the PXL Security team. Each links to its public record. We publish advisories only after a fix is available or disclosure timelines have elapsed.
| CVE | Affected software | Class | Year |
|---|---|---|---|
| CVE-2025-50674 | OpenMediaVault 7.4.17 | Local privilege escalation | 2025 |
| CVE-2024-33911 | Weblizar School Management Pro | SQL injection | 2024 |
| CVE-2024-32136 | BWL Advanced FAQ Manager | SQL injection | 2024 |
| CVE-2024-31370 | WordPress AIKit plugin | SQL injection | 2024 |
| CVE-2024-30240 | Typps Calendarista (≤ 15.5.7) | SQL injection | 2024 |
| CVE-2024-0566 | Smart Manager (WP, < 8.28.0) | SQL injection | 2024 |
| CVE-2024-0405 | Burst Statistics (WP, 1.5.3) | SQL injection | 2024 |
| CVE-2024-0399 | WooCommerce Customers Manager (< 29.7) | SQL injection | 2024 |
| CVE-2024-0365 | Fancy Product Designer (WP, < 6.1.5) | SQL injection | 2024 |
| CVE-2023-0830 | EasyNAS 1.1.0 | OS command injection | 2023 |
Responsible disclosure is part of how we work. If you believe you've found a vulnerability in something we build, email [email protected].