Hi 👋, I'm Jomar
YesWeHack • Intigriti • BBHunter
Hacker at ❤️, I bring my passion for cybersecurity to my work every day.
# Languages and tools
# Latest Blog Posts
# External contribution
Tenable Blog
Tenable Medium
BugBountyHunter Website
Synetis Blog
# Achievement & CVE
2023
- CVE-2023-4137 - Unauthenticated Reflected Cross-Site Scripting on AYS Popup Box
- CVE-2023-28667 - Unauthenticated Insecure Deserialization on Lead Generated
- CVE-2023-28666 - Authenticated Reflected Cross-Site Scripting on InPost Gallery WordPress plugin
- CVE-2023-28665 - Authenticated Reflected Cross-Site Scripting on Bulk Price Update
- CVE-2023-28664 - Authenticated Reflected Cross-Site Scripting on MDTF – Meta Data and Taxonomies Filter
- CVE-2023-28663 - Authenticated SQL Injection on Formidable PRO2PDF
- CVE-2023-28662 - Unauthenticated SQL Injection on Gift Vouchers and Packages
- CVE-2023-28661 - Authenticated SQL Injection on WP Popup Banners
- CVE-2023-28660 - Authenticated SQL Injection on Events Made Easy
- CVE-2023-28659 - Authenticated SQL Injection on Waiting: One-click countdowns
- CVE-2023-28017 - Stored Cross-Site Scripting on CraftCMS
- CVE-2023-26326 - Unauthenticated Insecure Deserialization on Buddyforms
- CVE-2023-26325 - Authenticated SQL Injection on ReviewX
- CVE-2023-23492 - Unauthenticated Reflected Cross-Site Scripting on Login with Phone Number
- CVE-2023-23491 - Unauthenticated Reflected Cross-Site Scripting on Quick Event Manager
- CVE-2023-23490 - Authenticated SQL Injection on Survey Maker
- CVE-2023-23489 - Unauthenticated SQL Injection on Easy Digital Downloads
- CVE-2023-23488 - Unauthenticated SQL Injection on Paid Memberships Pro
- CVE-2023-0448 - Unauthenticated Reflected Cross-Site Scripting on WP Helper Lite
2022
- CVE-2022-1731 - Unauthenticated SQL Injection on Metasonic Doc WebClient
- CVE-2022-38131 - Unauthenticated Open Redirect on RStudio Connect
2021
- CVE-2021-41262 - Authenticated SQL Injection on Galette
- CVE-2021-41261 - Authenticated Stored Cross-Site Scripting on Galette
- CVE-2021-41260 - Cross-Site Request Forgery on Galette
2020
- CVE-2020-25070 - Cross-Site Request Forgery on USVN with Serizao
- CVE-2020-25069 - Remote Code Execution on USVN with Serizao
- CVE-2020-15081 - Exposure of Sensitive Information on PrestaShop
- Top 3 in duo with Reptou during a YesWeHack live event.




