Public security advisories and PoCs for vulnerabilities discovered in open-source web software, with root-cause analysis, CVE references, reproduction steps and mitigation guidance.
Public repository containing security advisories, technical analyses, and Proof-of-Concepts (PoCs) for vulnerabilities independently discovered in open-source software.
All vulnerabilities were identified through manual source code review, secure code analysis, and dynamic application security testing in controlled laboratory environments. The research follows responsible disclosure practices, with technical details published after disclosure or CVE assignment.
| Field | Value |
|---|---|
| Researcher | Carlos Tuma (bl4dsc4n) |
| Organization | RedScan Academy |
| Community | 0ff3ns!v3 S3cur!ty |
| Research Focus | Web Application Security, Red Team, Vulnerability Research |
| Disclosure Policy | Responsible / Coordinated Disclosure |
CLOUD-CLASSROOMS-php-1.0
Technical documentation including:
Repository
https://github.com/carlosalbertotuma/CLOUD-CLASSROOMS-php-1.0
Repository
https://github.com/carlosalbertotuma/Cloud-Classroom-PHP-1.0---Poc2
Covered Advisories
Repository
https://github.com/carlosalbertotuma/Cloud-ClassRooms-PHP-1.0-Poc3
Covered Advisories
Repository
https://github.com/carlosalbertotuma/CVE-2026-2058-PoC
Contains the complete Proof-of-Concept for CVE-2026-2058, including vulnerable request, exploitation steps, technical analysis, and reproduction instructions.
| CVE ID | Vulnerability | CWE | Affected Component | Parameter |
|---|---|---|---|---|
| CVE-2026-2058 | SQL Injection | CWE-89 | Post Query (postquerypublic) | gnamex |
| CVE-2025-56713 | SQL Injection Authentication Bypass | CWE-89 | loginlinkstudent | sid |
| CVE-2025-56714 | SQL Injection (UNION-Based) | CWE-89 | viewresult.php | seno |
| CVE-2025-61561 | IDOR | CWE-639 | updatedetailsfromstudent.php | eno |
| CVE-2025-61562 | IDOR | CWE-639 | mydetailsfaculty.php | myfid |
| CVE-2025-61563 | IDOR | CWE-639 | mydetailsstudent.php | myds |
| CVE-2025-61565 | IDOR | CWE-639 | updatedetailsfromfaculty.php | myfid |
| CVE-2025-61566 | Reflected Cross-Site Scripting (XSS) | CWE-79 | askquery.php | eid |
| CVE-2025-61567 | Reflected Cross-Site Scripting (XSS) | CWE-79 | takeassessment2.php | exid |
| CVE-2025-61568 | SQL Injection (UNION-Based) | CWE-89 | takeassessment2.php | exid |
| CVE-2025-61569 | Stored Cross-Site Scripting (XSS) | CWE-79 | updatedetailsfromstudent.php | Address |
| CVE-2025-61570 | Stored Cross-Site Scripting (XSS) | CWE-79 | updatedetailsfromfaculty.php | Address |
The following CVE identifiers have been assigned and are currently reserved. Technical advisories will be published after the corresponding coordinated disclosure process has been completed.
| Status | Count |
|---|---|
| Public Advisories | 1 |
| Reserved CVEs | 35 |
| Total Assigned CVEs | 36 |
| Class | Count |
|---|---|
| SQL Injection | 4 |
| Broken Access Control (IDOR) | 4 |
| Reflected Cross-Site Scripting | 2 |
| Stored Cross-Site Scripting | 2 |
The vulnerabilities documented in this repository were identified through:
All testing was performed against locally deployed instances of the affected software.
No production systems were accessed during the research process.
CVE-2026-2058
https://nvd.nist.gov/vuln/detail/CVE-2026-2058
https://github.com/carlosalbertotuma/CVE-2026-2058-PoC
https://github.com/carlosalbertotuma/CLOUD-CLASSROOMS-php-1.0
https://github.com/carlosalbertotuma/Cloud-Classroom-PHP-1.0---Poc2
https://github.com/carlosalbertotuma/Cloud-ClassRooms-PHP-1.0-Poc3
Each published advisory includes:
Additional reserved CVEs will be published after completion of the coordinated disclosure process.
This repository is intended exclusively for educational, defensive, and security research purposes.
No weaponized exploit frameworks or offensive tooling are included.
The goal of this project is to promote responsible vulnerability disclosure, improve software security, and provide high-quality technical documentation for the security community.