HieuPenguinnn Blog
Home CVE Write-up About
Home
CVE
Write-up
About
Type a keyword to search posts
HieuPenguinnn

HieuPenguinnn

CVE & CTF writeups by HieuPenguinnn

41
Posts
10
CVE
31
CTF

Categories

├── CVE (10) │ ├── Broken Access Control (6) │ ├── Information Disclosure (2) │ ├── IDOR (2) │ ├── Webhook Forgery (2) │ ├── SQL Injection (1) │ ├── Payment Bypass (1) │ ├── Stored XSS (1) │ ├── Price Tampering (1) │ └── Account Takeover (1) └── CTF (31) ├── GPNCTF 2026 (8) ├── PTITCTF Quals 2026 (7) ├── TJCTF 2026 (6) ├── UMassCTF 2026 (3) ├── UTCTF 2026 (3) ├── OmniCTF 2026 (2) └── SekaiCTF 2026 (2)

Random Picks

GPNCTF2026-Secure Secretpickle CVE-2026-54826 - SupportCandy Attachment IDOR via Thread Endpoint UMassCTF2026-ORDER66 GPNCTF2026-cookoff CVE-2026-42743 - Masteriyo LMS Lemon Squeezy Webhook Forgery

Tag: IDOR (2 posts)

CVE-2026-59557 - Events Made Easy Arbitrary Person Record Modification Without Login
CVE

CVE-2026-59557 - Events Made Easy Arbitrary Person Record Modification Without Login

Broken access control in Events Made Easy <= 3.0.67 lets unauthenticated attackers modify arbitrary person records through the public personal-information AJAX endpoint.

Read
CVE WordPress Broken Access Control IDOR
CVE-2026-54826 - SupportCandy Attachment IDOR via Thread Endpoint
CVE

CVE-2026-54826 - SupportCandy Attachment IDOR via Thread Endpoint

IDOR in SupportCandy <= 3.4.6 lets a low-privilege user reassign and download another user's private ticket attachments via the thread-creation endpoint.

Read
CVE WordPress IDOR
HieuPenguinnn

HieuPenguinnn

CVE & CTF writeups by HieuPenguinnn

41
Posts
10
CVE
31
CTF

Categories

├── CVE (10) │ ├── Broken Access Control (6) │ ├── Information Disclosure (2) │ ├── IDOR (2) │ ├── Webhook Forgery (2) │ ├── SQL Injection (1) │ ├── Payment Bypass (1) │ ├── Stored XSS (1) │ ├── Price Tampering (1) │ └── Account Takeover (1) └── CTF (31) ├── GPNCTF 2026 (8) ├── PTITCTF Quals 2026 (7) ├── TJCTF 2026 (6) ├── UMassCTF 2026 (3) ├── UTCTF 2026 (3) ├── OmniCTF 2026 (2) └── SekaiCTF 2026 (2)

Random Picks

TJCTF2026-web/paper-trail SekaiCTF2026-web_&lt;_w+ GPNCTF2026-cookoff CVE-2026-57341 - Colissimo Officiel Unauthenticated Shipping Rate Tampering UMassCTF2026-BrOWSER BOSS FIGHT
10 CVE 31 CTF writeups 41 posts
© 2026 HieuPenguinnn | Powered by Astro & Tailwind | Theme by santisify
Home CVE Write-up About