Lukashuser's vulnerability profile centers on a niche tournament-management application, with the durable signal evident in cross-site request forgery weaknesses affecting the EKC Tournament Manager product. Treat this as a compact vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lukashuser over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-9765MEDIUM The EKC Tournament Manager WordPress plugin before 2.2.2 allows a logged in admin to download system files outside of the WordPress directory | May 15, 2025 | 6.5 | 30 | NO | YES |
CVE-2024-49674CRITICAL Cross-Site Request Forgery (CSRF) vulnerability in lukashuser EKC Tournament Manager ekc-tournament-manager allows Upload a Web Shell to a Web Server.This issue affects EKC Tournam | Oct 31, 2024 | 9.6 | 25 | NO | NO |
CVE-2024-9711MEDIUM The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change | May 15, 2025 | 5.4 | 16 | NO | NO |
CVE-2024-9709MEDIUM The EKC Tournament Manager WordPress plugin before 2.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change | May 15, 2025 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lukashuser.
Media articles that mention a CVE ID that affects a product developed by Lukashuser — matched by CVE ID, not by vendor name.