Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
advisory — Public security advisories and PoCs for vulnerabilities discovered in open-source web software, with root-cause analysis, CVE references, reproduction steps and mitigation guidance. | Kitploit
Tools/GitHubGitHub/carlosalbertotuma/advisory
Vulnerability ScannersStatic Code Analysis (SAST)Vulnerability AnalysisCode AnalysisExploitationWeb Application ExploitationWeb SecurityPapers & ResearchLearning & EducationCurated Resources
GitHub
265 days agoNot yet reviewed
carlosalbertotuma/advisory

advisory

Public security advisories and PoCs for vulnerabilities discovered in open-source web software, with root-cause analysis, CVE references, reproduction steps and mitigation guidance.

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Security Advisories — bl4dsc4n

Public repository containing security advisories, technical analyses, and Proof-of-Concepts (PoCs) for vulnerabilities independently discovered in open-source software.

All vulnerabilities were identified through manual source code review, secure code analysis, and dynamic application security testing in controlled laboratory environments. The research follows responsible disclosure practices, with technical details published after disclosure or CVE assignment.


Researcher

FieldValue
ResearcherCarlos Tuma (bl4dsc4n)
OrganizationRedScan Academy
Community0ff3ns!v3 S3cur!ty
Research FocusWeb Application Security, Red Team, Vulnerability Research
Disclosure PolicyResponsible / Coordinated Disclosure

Advisory Repositories

Main Advisory Repository

CLOUD-CLASSROOMS-php-1.0

Technical documentation including:

  • Root cause analysis
  • Vulnerability details
  • Affected source code
  • Security impact
  • Mitigation guidance
  • CVE references

Repository

https://github.com/carlosalbertotuma/CLOUD-CLASSROOMS-php-1.0


Proof-of-Concept Repository #1

Repository

https://github.com/carlosalbertotuma/Cloud-Classroom-PHP-1.0---Poc2

Covered Advisories

  • CVE-2026-2058
  • CVE-2025-56713

Proof-of-Concept Repository #2

Repository

https://github.com/carlosalbertotuma/Cloud-ClassRooms-PHP-1.0-Poc3

Covered Advisories

  • CVE-2025-56714
  • CVE-2025-61561
  • CVE-2025-61562
  • CVE-2025-61563
  • CVE-2025-61565
  • CVE-2025-61566
  • CVE-2025-61567
  • CVE-2025-61568
  • CVE-2025-61569
  • CVE-2025-61570

Dedicated PoC Repository

Repository

https://github.com/carlosalbertotuma/CVE-2026-2058-PoC

Contains the complete Proof-of-Concept for CVE-2026-2058, including vulnerable request, exploitation steps, technical analysis, and reproduction instructions.


Public CVE Index

CloudClassroom PHP Project 1.0

CVE IDVulnerabilityCWEAffected ComponentParameter
CVE-2026-2058SQL InjectionCWE-89Post Query (postquerypublic)gnamex
CVE-2025-56713SQL Injection Authentication BypassCWE-89loginlinkstudentsid
CVE-2025-56714SQL Injection (UNION-Based)CWE-89viewresult.phpseno
CVE-2025-61561IDORCWE-639updatedetailsfromstudent.phpeno
CVE-2025-61562IDORCWE-639mydetailsfaculty.phpmyfid
CVE-2025-61563IDORCWE-639mydetailsstudent.phpmyds
CVE-2025-61565IDORCWE-639updatedetailsfromfaculty.phpmyfid
CVE-2025-61566Reflected Cross-Site Scripting (XSS)CWE-79askquery.phpeid
CVE-2025-61567Reflected Cross-Site Scripting (XSS)CWE-79takeassessment2.phpexid
CVE-2025-61568SQL Injection (UNION-Based)CWE-89takeassessment2.phpexid
CVE-2025-61569Stored Cross-Site Scripting (XSS)CWE-79updatedetailsfromstudent.phpAddress
CVE-2025-61570Stored Cross-Site Scripting (XSS)CWE-79updatedetailsfromfaculty.phpAddress

Reserved CVEs

The following CVE identifiers have been assigned and are currently reserved. Technical advisories will be published after the corresponding coordinated disclosure process has been completed.

  • CVE-2025-56716
  • CVE-2025-56719
  • CVE-2025-56720
  • CVE-2025-56721
  • CVE-2025-56722
  • CVE-2025-56723
  • CVE-2025-56724
  • CVE-2025-56725
  • CVE-2025-56727
  • CVE-2025-56728
  • CVE-2025-56729
  • CVE-2025-56730
  • CVE-2025-56731
  • CVE-2025-56732
  • CVE-2025-56733
  • CVE-2025-56734
  • CVE-2025-56735
  • CVE-2025-56736
  • CVE-2025-56737
  • CVE-2025-56738
  • CVE-2025-56739
  • CVE-2025-56741
  • CVE-2025-56742
  • CVE-2025-56744

Research Statistics

Assigned CVEs

StatusCount
Public Advisories1
Reserved CVEs35
Total Assigned CVEs36

Published Vulnerability Classes

ClassCount
SQL Injection4
Broken Access Control (IDOR)4
Reflected Cross-Site Scripting2
Stored Cross-Site Scripting2

Research Methodology

The vulnerabilities documented in this repository were identified through:

  • Manual source code review
  • Secure code analysis
  • Dynamic application security testing
  • Authentication testing
  • Authorization testing
  • Business logic assessment
  • Input validation analysis
  • Manual Proof-of-Concept development

All testing was performed against locally deployed instances of the affected software.

No production systems were accessed during the research process.


References

National Vulnerability Database (NVD)

CVE-2026-2058

https://nvd.nist.gov/vuln/detail/CVE-2026-2058


GitHub Proof-of-Concept

https://github.com/carlosalbertotuma/CVE-2026-2058-PoC


Main Advisory

https://github.com/carlosalbertotuma/CLOUD-CLASSROOMS-php-1.0


Additional Proof-of-Concepts

https://github.com/carlosalbertotuma/Cloud-Classroom-PHP-1.0---Poc2

https://github.com/carlosalbertotuma/Cloud-ClassRooms-PHP-1.0-Poc3


Responsible Disclosure

Each published advisory includes:

  • Vulnerability description
  • Technical impact
  • Root cause analysis
  • Affected component
  • Proof-of-Concept
  • Reproduction steps
  • Mitigation recommendations

Additional reserved CVEs will be published after completion of the coordinated disclosure process.


Disclaimer

This repository is intended exclusively for educational, defensive, and security research purposes.

No weaponized exploit frameworks or offensive tooling are included.

The goal of this project is to promote responsible vulnerability disclosure, improve software security, and provide high-quality technical documentation for the security community.

Download Tool