OWASP Top 10
The baseline map of web application risk. If a security review doesn't reference it, ask why.
Research & advisories
Vulnerability research under coordinated disclosure. 28 advisories in the HKV series published in 2026, plus ongoing tracking of the ecosystems I work with — currently the MyBB September 2026 batch.
Published September 15, 2026 via the coordinated disclosure process. Highlights below; the full set of 28 advisories — including severity ratings, affected versions and reproduction boundaries — lives on the Haikhavan advisory index.
| ID | Severity | Title | Summary | Published |
|---|---|---|---|---|
| HKV-ADV-2026-028 | high | Subscriber-to-author comprehensive WordPress data breach through legacy handlers | Four chained low-privilege disclosure paths exposing private content and identity data. | 2026-09-15 |
| HKV-ADV-2026-027 | high | Contributor-to-internal-network reflected SSRF proxy through URL details | URL-details endpoint abused as a reflected server-side HTTP proxy; internal service reading demonstrated. | 2026-09-15 |
| HKV-ADV-2026-026 | high | Unauthenticated administrator takeover via username disclosure and XML-RPC multicall | Low-noise password-guessing channel against known privileged accounts. | 2026-09-15 |
| HKV-ADV-2026-025 | high | Unauthenticated cloud-account compromise via pingback SSRF and DNS rebinding | Cloud metadata exposure via pingback SSRF plus incomplete special-use IP checks and a DNS TOCTOU gap. | 2026-09-15 |
| HKV-ADV-2026-015 | medium | Concurrent media uploads overwrite one another and share one path | Race condition in filename allocation lets two uploads commit to the same path. | 2026-09-15 |
| HKV-ADV-2026-014 | medium | Contributor creates a live private post through metaWeblog.newPost | XML-RPC path bypasses the publish_posts capability check for private status. | 2026-09-15 |
| HKV-ADV-2026-013 | medium | Quadratic comment-author URL cookie processing on every request | Unauthenticated CPU amplification via crafted cookie values. | 2026-09-15 |
| HKV-ADV-2026-024 | low | Block custom-CSS edit_css filter bypass through a block-recognizer differential | Author-role CSS capability gate bypassed via parser whitespace differential. | 2026-09-15 |
| HKV-ADV-2026-022 | low | Anonymous trackback content insertion and author/URL spoofing | Trackback endpoint accepts attacker-controlled fields without an authenticity boundary. | 2026-09-15 |
| HKV-ADV-2026-017 | low | Subscriber disclosure of commenter email and IP through XML-RPC | wp.getComments returns sensitive commenter data to Subscriber-level callers. | 2026-09-15 |
The MyBB team released a coordinated batch of fourteen advisories on September 16, 2026 — nine authorization issues across moderation surfaces, two MyCode/admin XSS and related hardening fixes, individually rated Low. Six further Moderate-severity advisories were published the same day. If you run MyBB forums: update, then review moderator permissions — individually-low authz gaps get interesting in combination.
| Advisory | Title | Severity | Link |
|---|---|---|---|
| GHSA-7wxq-cgj5-jqg2 | Image thumbnail memory exhaustion | low | GitHub ↗ |
| GHSA-q93v-rjvr-8ggg | Warnings — insufficient authorization | low | GitHub ↗ |
| GHSA-2vx9-fqjj-x3rp | Group Management — insufficient authorization | low | GitHub ↗ |
| GHSA-qqmp-gq43-8ch2 | Email User Ignore List — insufficient authorization | low | GitHub ↗ |
| GHSA-7w8v-m728-h542 | Moderation Queue — insufficient authorization | low | GitHub ↗ |
| GHSA-9c3r-g4fj-2gp4 | Post moderation — insufficient destination authorization | low | GitHub ↗ |
| GHSA-3g38-mp38-pgcw | Attachment moderation — insufficient authorization | low | GitHub ↗ |
| GHSA-hmjm-jvm7-2598 | Custom moderator tools — insufficient forum authorization | low | GitHub ↗ |
| GHSA-47mm-6v2r-2rr6 | Mod CP reports — insufficient authorization | low | GitHub ↗ |
| GHSA-3qqj-j98h-49x6 | Disabled video MyCode XSS | low | GitHub ↗ |
| GHSA-vwqg-2mp2-f9jf | New Reply Thread Review — insufficient authorization | low | GitHub ↗ |
| GHSA-58xm-q4mj-33q9 | New Reply — insufficient threads authorization | low | GitHub ↗ |
| GHSA-22wp-jxm2-5w7m | ACP Users View Manager XSS | low | GitHub ↗ |
| GHSA-6pm8-c5c6-r45p | ACP Login attempt improper restriction | low | GitHub ↗ |
| Advisory | Title | Severity | Link |
|---|---|---|---|
| GHSA-x885-jp99-4xf3 | ACP Awaiting Activation insufficient type distinction | low | GitHub ↗ |
| GHSA-f8hj-rxw5-v8mg | ACP Awaiting Activation group modification | medium | GitHub ↗ |
| GHSA-5p37-qp5c-54jf | ACP Ban group insufficient validation | medium | GitHub ↗ |
| GHSA-rxgj-m9jm-mxxw | Search — insufficient threads authorization | medium | GitHub ↗ |
| GHSA-p768-x2c9-7j8r | Online status — insufficient threads authorization | medium | GitHub ↗ |
| GHSA-232v-mm3q-9wpj | New Reply quote moderator — insufficient authorization | medium | GitHub ↗ |
Standards and indexes I use daily, for clients and researchers alike.
The baseline map of web application risk. If a security review doesn't reference it, ask why.
The canonical vulnerability record. Every advisory worth its identifier ends up here.
Upstream advisories and security notes for MyBB — where the batch above is documented.
If you're a vendor or admin dealing with one of these issues — or want your product reviewed before someone else reports it — get in touch.