Research & advisories

Findings, published properly.

Vulnerability research under coordinated disclosure. 28 advisories in the HKV series published in 2026, plus ongoing tracking of the ecosystems I work with — currently the MyBB September 2026 batch.

HKV advisory series — WordPress

Published September 15, 2026 via the coordinated disclosure process. Highlights below; the full set of 28 advisories — including severity ratings, affected versions and reproduction boundaries — lives on the Haikhavan advisory index.

Selected advisories, highest severity first
IDSeverityTitleSummaryPublished
HKV-ADV-2026-028 high Subscriber-to-author comprehensive WordPress data breach through legacy handlers Four chained low-privilege disclosure paths exposing private content and identity data. 2026-09-15
HKV-ADV-2026-027 high Contributor-to-internal-network reflected SSRF proxy through URL details URL-details endpoint abused as a reflected server-side HTTP proxy; internal service reading demonstrated. 2026-09-15
HKV-ADV-2026-026 high Unauthenticated administrator takeover via username disclosure and XML-RPC multicall Low-noise password-guessing channel against known privileged accounts. 2026-09-15
HKV-ADV-2026-025 high Unauthenticated cloud-account compromise via pingback SSRF and DNS rebinding Cloud metadata exposure via pingback SSRF plus incomplete special-use IP checks and a DNS TOCTOU gap. 2026-09-15
HKV-ADV-2026-015 medium Concurrent media uploads overwrite one another and share one path Race condition in filename allocation lets two uploads commit to the same path. 2026-09-15
HKV-ADV-2026-014 medium Contributor creates a live private post through metaWeblog.newPost XML-RPC path bypasses the publish_posts capability check for private status. 2026-09-15
HKV-ADV-2026-013 medium Quadratic comment-author URL cookie processing on every request Unauthenticated CPU amplification via crafted cookie values. 2026-09-15
HKV-ADV-2026-024 low Block custom-CSS edit_css filter bypass through a block-recognizer differential Author-role CSS capability gate bypassed via parser whitespace differential. 2026-09-15
HKV-ADV-2026-022 low Anonymous trackback content insertion and author/URL spoofing Trackback endpoint accepts attacker-controlled fields without an authenticity boundary. 2026-09-15
HKV-ADV-2026-017 low Subscriber disclosure of commenter email and IP through XML-RPC wp.getComments returns sensitive commenter data to Subscriber-level callers. 2026-09-15

Full advisory index (28) ↗

Tracked: MyBB security advisories

The MyBB team released a coordinated batch of fourteen advisories on September 16, 2026 — nine authorization issues across moderation surfaces, two MyCode/admin XSS and related hardening fixes, individually rated Low. Six further Moderate-severity advisories were published the same day. If you run MyBB forums: update, then review moderator permissions — individually-low authz gaps get interesting in combination.

September 16, 2026 coordinated batch — 14 advisories (all Low; credit: MyBB security team)
AdvisoryTitleSeverityLink
GHSA-7wxq-cgj5-jqg2 Image thumbnail memory exhaustion low GitHub ↗
GHSA-q93v-rjvr-8ggg Warnings — insufficient authorization low GitHub ↗
GHSA-2vx9-fqjj-x3rp Group Management — insufficient authorization low GitHub ↗
GHSA-qqmp-gq43-8ch2 Email User Ignore List — insufficient authorization low GitHub ↗
GHSA-7w8v-m728-h542 Moderation Queue — insufficient authorization low GitHub ↗
GHSA-9c3r-g4fj-2gp4 Post moderation — insufficient destination authorization low GitHub ↗
GHSA-3g38-mp38-pgcw Attachment moderation — insufficient authorization low GitHub ↗
GHSA-hmjm-jvm7-2598 Custom moderator tools — insufficient forum authorization low GitHub ↗
GHSA-47mm-6v2r-2rr6 Mod CP reports — insufficient authorization low GitHub ↗
GHSA-3qqj-j98h-49x6 Disabled video MyCode XSS low GitHub ↗
GHSA-vwqg-2mp2-f9jf New Reply Thread Review — insufficient authorization low GitHub ↗
GHSA-58xm-q4mj-33q9 New Reply — insufficient threads authorization low GitHub ↗
GHSA-22wp-jxm2-5w7m ACP Users View Manager XSS low GitHub ↗
GHSA-6pm8-c5c6-r45p ACP Login attempt improper restriction low GitHub ↗
Published the same day — 6 related advisories (Moderate)
AdvisoryTitleSeverityLink
GHSA-x885-jp99-4xf3 ACP Awaiting Activation insufficient type distinction low GitHub ↗
GHSA-f8hj-rxw5-v8mg ACP Awaiting Activation group modification medium GitHub ↗
GHSA-5p37-qp5c-54jf ACP Ban group insufficient validation medium GitHub ↗
GHSA-rxgj-m9jm-mxxw Search — insufficient threads authorization medium GitHub ↗
GHSA-p768-x2c9-7j8r Online status — insufficient threads authorization medium GitHub ↗
GHSA-232v-mm3q-9wpj New Reply quote moderator — insufficient authorization medium GitHub ↗

References I recommend

Standards and indexes I use daily, for clients and researchers alike.

OWASP Top 10

The baseline map of web application risk. If a security review doesn't reference it, ask why.

owasp.org ↗

NVD / CVE

The canonical vulnerability record. Every advisory worth its identifier ends up here.

nvd.nist.gov ↗

MyBB security

Upstream advisories and security notes for MyBB — where the batch above is documented.

mybb.com/security ↗

Found something in your stack?

If you're a vendor or admin dealing with one of these issues — or want your product reviewed before someone else reports it — get in touch.

Contact me