HieuPenguinnn Blog
Home CVE Write-up About
Home
CVE
Write-up
About
Type a keyword to search posts
HieuPenguinnn

HieuPenguinnn

CVE & CTF writeups by HieuPenguinnn

41
Posts
10
CVE
31
CTF

Categories

├── CVE (10) │ ├── Broken Access Control (6) │ ├── Information Disclosure (2) │ ├── IDOR (2) │ ├── Webhook Forgery (2) │ ├── SQL Injection (1) │ ├── Payment Bypass (1) │ ├── Stored XSS (1) │ ├── Price Tampering (1) │ └── Account Takeover (1) └── CTF (31) ├── GPNCTF 2026 (8) ├── PTITCTF Quals 2026 (7) ├── TJCTF 2026 (6) ├── UMassCTF 2026 (3) ├── UTCTF 2026 (3) ├── OmniCTF 2026 (2) └── SekaiCTF 2026 (2)

Random Picks

OmniCTF2026-web/Ganzir SekaiCTF2026-web/migurimental CVE-2026-54840 - Newsletters Unauthenticated Subscriber Management Account Takeover LEMON MELON COOKIE CVE-2026-42743 - Masteriyo LMS Lemon Squeezy Webhook Forgery
HieuPenguinnn

HieuPenguinnn Blog

CVE & CTF writeups by HieuPenguinnn

41
Posts
8
Categories
30
Tags

CVE

View all
CVE-2026-78259 - WPLegalPages API Secret Disclosure and Account Disconnect via Unauthenticated REST API
CVE

CVE-2026-78259 - WPLegalPages API Secret Disclosure and Account Disconnect via Unauthenticated REST API

Unauthenticated WPLegalPages <= 3.6.4 REST endpoints disclose API secrets and allow attackers to disconnect the connected account.

Read
CVE WordPress Information Disclosure Broken Access Control
CVE-2026-59557 - Events Made Easy Arbitrary Person Record Modification Without Login
CVE

CVE-2026-59557 - Events Made Easy Arbitrary Person Record Modification Without Login

Broken access control in Events Made Easy <= 3.0.67 lets unauthenticated attackers modify arbitrary person records through the public personal-information AJAX endpoint.

Read
CVE WordPress Broken Access Control IDOR
CVE-2026-61948 - Unauthenticated SQL Injection in Mini Cart Coupon REST Endpoint
CVE

CVE-2026-61948 - Unauthenticated SQL Injection in Mini Cart Coupon REST Endpoint

Unauthenticated SQL injection in WPDM Premium Packages <= 6.2.0 exposes the public Mini Cart coupon REST endpoint to blind time-based database extraction.

Read
CVE WordPress SQL Injection
CVE-2026-57408 - Peach Payments Gateway Payment Status Forgery via Unauthenticated Webhook
CVE

CVE-2026-57408 - Peach Payments Gateway Payment Status Forgery via Unauthenticated Webhook

Unauthenticated webhook forgery in Peach Payments Gateway <= 4.0.2 lets attackers mark pending WooCommerce orders as paid by submitting a forged successful payment result.

Read
CVE WordPress Webhook Forgery Payment Bypass

CTF

PTITCTF Quals 2026
7

PTITCTF Quals 2026

7 challenges

OmniCTF 2026
2

OmniCTF 2026

2 challenges

SekaiCTF 2026
2

SekaiCTF 2026

2 challenges

GPNCTF 2026
8

GPNCTF 2026

8 challenges

TJCTF 2026
6

TJCTF 2026

6 challenges

UMassCTF 2026
3

UMassCTF 2026

3 challenges

UTCTF 2026
3

UTCTF 2026

3 challenges

HieuPenguinnn

HieuPenguinnn

CVE & CTF writeups by HieuPenguinnn

41
Posts
10
CVE
31
CTF

Categories

├── CVE (10) │ ├── Broken Access Control (6) │ ├── Information Disclosure (2) │ ├── IDOR (2) │ ├── Webhook Forgery (2) │ ├── SQL Injection (1) │ ├── Payment Bypass (1) │ ├── Stored XSS (1) │ ├── Price Tampering (1) │ └── Account Takeover (1) └── CTF (31) ├── GPNCTF 2026 (8) ├── PTITCTF Quals 2026 (7) ├── TJCTF 2026 (6) ├── UMassCTF 2026 (3) ├── UTCTF 2026 (3) ├── OmniCTF 2026 (2) └── SekaiCTF 2026 (2)

Random Picks

UTCTF2026-Break the Bank CVE-2026-61948 - Unauthenticated SQL Injection in Mini Cart Coupon REST Endpoint TJCTF2026-web/chained CVE-2026-57365 - Stored XSS in reCAPTCHA for Asgaros Forum via Site Key TJCTF2026-web/free-cloud-storage
10 CVE 31 CTF writeups 41 posts
© 2026 HieuPenguinnn | Powered by Astro & Tailwind | Theme by santisify
Home CVE Write-up About