Skip to content
View wlayzz's full-sized avatar
🏴‍☠️
Looking for bugs
🏴‍☠️
Looking for bugs

Block or report wlayzz

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
wlayzz/README.md

🏴‍☠️ Lucien Doustaly · wlayzz

Offensive Security Researcher · Bug Bounty Hunter

YesWeHack profile HackerOne profile Bugcrowd profile Intigriti profile


🔬 Security Research

Other Vendors

Vendor Impact CVE
Thales Suspicious Remote Code Execution CVE-2026-13014
Mozilla PDF.js JavaScript Execution CVE-2026-16633
Open WebUI Server-Side Request Forgery CVE-2026-45331

Kiteworks · 53 CVEs

Discovered as part of a hunter squad working on the Kiteworks bug bounty program on YesWeHack. Team members: Supr4s · Icare · truff

critical
Product Impact CVE
Core Account takeover CVE-2026-102115 · CVE-2026-102147
EPG Arbitrary code execution CVE-2026-54154
EPG Access to internal network resources CVE-2026-102095
EPG Account takeover CVE-2026-85066
high
Product Impact CVE
Core Information disclosure CVE-2026-85067 · CVE-2026-102098 · CVE-2026-28349
Core Privilege escalation CVE-2026-102129 · CVE-2026-102112 · CVE-2026-102126 · CVE-2026-63486 · CVE-2026-102113 · CVE-2026-102120 · CVE-2026-102093 · CVE-2026-95841 · CVE-2026-102132 · CVE-2026-77428
Core Arbitrary code execution CVE-2026-102117 · CVE-2026-102142 · CVE-2026-62158 · CVE-2026-102114 · CVE-2026-102099 · CVE-2026-102101
Core Cross-user script execution CVE-2026-102092 · CVE-2026-28347 · CVE-2026-102100
Core Unauthorized file modification CVE-2026-102123
Core Account takeover CVE-2026-62159
EPG Unauthorized file modification CVE-2026-102143
EPG Arbitrary code execution CVE-2026-102119 · CVE-2026-102097 · CVE-2026-102131 · CVE-2026-102108 · CVE-2026-102130 · CVE-2026-102089 · CVE-2026-102116
SDF XSS CVE-2026-24752 · CVE-2026-24751
SDF Access to internal network resources CVE-2026-102091
medium
Product Impact CVE
Core Arbitrary code execution CVE-2026-102133
Core Access to internal network resources CVE-2026-102145
Core Privilege escalation CVE-2026-102141 · CVE-2026-102136
Core Security bypass CVE-2026-102124 · CVE-2026-102140
EPG Arbitrary code execution CVE-2026-102135
SDF Information disclosure CVE-2026-42243 · CVE-2026-62244 · CVE-2026-62161
SDF Security bypass CVE-2026-97372
low
Product Impact CVE
Core Access to internal network resources CVE-2026-102138
SDF Unauthorized data modification CVE-2026-42242

🎙️ Featured

Interview with YesWeHack — “You always need to fight against yourself to find bugs”


🔗 Elsewhere

LinkedIn X / Twitter

Pinned Loading

  1. RopstenCtf RopstenCtf Public archive

    RopstenCtf is an easy tool to interact with the ethereum ropsten network for ctf purpose and more.

    Python 16

  2. YWHScopeExtractor YWHScopeExtractor Public

    Extract api & web-application YesWeHack scope

    JavaScript 9 1