
CVE-2021-24647
CVE-2021-24647 Pie Register < 3.7.1.6 - Unauthenticated Arbitrary Login

CVE-2021-24647 Pie Register < 3.7.1.6 - Unauthenticated Arbitrary Login

Proof-of-concept exploit for CVE-2023-47504 targeting Elementor WordPress plugin. Requires subscriber credentials and wp-config.php access to delete…

Proof of concept for Strapi CVE-2019-18818 - Unauthenticated Password Reset Vulnerability / Privilege Escalation

CVE-2019-14830

Proof-of-concept CSRF exploit for Casdoor's `/api/set-password` endpoint (CVE-2023-34927), enabling unauthorized password changes via cross-site POST…

CVE-2025-7892

Proof-of-concept exploit for CVE-2026-29000, an authentication bypass in pac4j-jwt via nested PlainJWT with alg:none inside a JWE container.

An implementation of CVE-2015-3306

CVE-2026-23550 - Modular DS WordPress Plugin **Unauthenticated Admin Access**

PoC for CVE-2021-34646

An issue in Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements.

PoC for testing if a target is vulnerable to RCE

CWE-287: Improper Authentication in parse-community parse-server

Exploit for CVE-2022-23131 targeting Zabbix SAML SSO authentication bypass vulnerability. Enables session hijacking and unauthorized admin access.

Proof-of-concept for an authentication bypass in PerfexCRM prior to 3.3.1, demonstrating how empty credentials can grant unauthorized admin access.

LiquidPoll – Advanced Polls for Creators and Brands <= 3.3.68 - Missing Authorization via activate_addon

CVE-2025-8517 proof-of-concept demonstrating session fixation in Vvveb CMS v1.0.6.1, enabling full administrative account takeover via arbitrary…

Proof-of-concept exploit for CVE-2025-22963, a CSRF vulnerability in Teedy v1.11 allowing account takeover via user information change endpoint.