research — CVEs

Discovered and published CVEs

Vulnerabilities I found, reported under responsible disclosure and took through to CVE registration — each with a working PoC and a full technical write-up.

5 CVEs — 1 critical · 2 high · 2 medium
CVE-2026-XXXXXX
Dolibarr ERP/CRM
Remote Code Execution — sandbox bypass in dol_eval_standard() (computed extrafields).
Critical·Reserved
CVE-2026-33944
Dolibarr ERP/CRM
SQL Injection in the Third Party module — the localtax1_value parameter is not sanitized.
High·Reserved
CVE-2026-105090
Formbricks
Broken Access Control → Stored XSS in Custom Head Scripts (self-hosted).
Medium·Published
CVE-2026-38441
Zextras Carbonio
Persistent XSS in the Print function — participant names are not escaped, no CSP.
High·Reserved
CVE-2022-1438
Keycloak
Persistent XSS in the Admin Console during user impersonation.
Medium·Published