#1Tools for creating, managing, and analyzing fake login pages and email campaigns.
Kitploit recommended

All-in-One WP Migration < 7.63 - Unauthenticated Reflected XSS + CSRF

Valid JQuery that profiles the system and returns info to the server in a fake analytics GET request

Secure Web Gateway 10.2.11 - Cross-Site Scripting (XSS)

In LetterPress plugin <= 1.2.1 is vulnerable to Html Injection Vulnerability which can futher leads to Open Redirection Vulnerabilty.

Roundcube mail server exploit for CVE-2024-37383 (Stored XSS)

Script in Go that analyzes a list of passwords based on in its entropy and weak passwords from a dictionary. Useful for penetration tests and…

Proof-of-concept exploit for CVE-2018-25031 (Swagger UI XSS) that exfiltrates authorization codes via crafted configUrl/url parameters.

xll windows reverse shell

Example on how to injection(currently under work) of keylogger js through Safari Extension(that part done)

mjml-app v3.0.4 & 3.1.0-beta RCE exploit

This repository contains exploits for iTOP CVE-2024-52002, 52000, 31998, 31448 that involve CSRF+XSS chaining to get RCE

Repository for CVE-2023-4549 vulnerability.

Microweber version 2.0.4 vulnerable to "Uploading Malicious Files"

CVE-2020-13965: Cross-Site Scripting via Malicious XML Attachment in Roundcube Webmail

Survey XSS combined with CSRF leads to Admin Account Takeover in Concrete5 8.5.4


RiteCMS 3.0 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed will…

ConcreteCMS v.9.2.1 is affected by Arbitrary File Upload vulnerability that allows Cross-Site Scriting (XSS) Stored.