Below are listed all the CVEs I have discovered and reported.
Slah CMS v1.5.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the session() function at config.php. This vulnerability is exploitable via a crafted input.
Note: certain CVEs are still in the verification process due to MITRE's response time or the vendor's 90-day responsible disclosure period.
This list is constantly updated.