
Craftcms-PoC-CVE-2026-31266
Security research on Craft CMS authentication mechanism

Security research on Craft CMS authentication mechanism

PoC for the type confusion vulnerability in Mac's CMS that results in authentication bypass and administrator account takeover.

This Python script exploits a critical mass assignment vulnerability in Camaleon CMS version 2.9.0, allowing any registered user to escalate their…

Security write-up for an IDOR in Concrete CMS exposing conversation ratings through missing authorization on the get_rating endpoint, with root…

In-depth IDOR write-up for Concrete CMS, covering the message_detail endpoint, missing authorization root cause, attack scenarios, impact, and fix.

Pre-auth RCE exploit for Craft CMS in Go. Grabs session/CSRF token, poisons PHP session, triggers deserialization for command execution or reverse…

Python script for checking authentication bypass vulnerability (WT-2025-0011) in Kentico Xperience 13 CMS Staging Service via POST request analysis.

Authentication bypass detection script for Kentico Xperience 13 CMS Staging Service using a single POST request to verify vulnerability.

WordPress CVE-2024-10924 Exploit for Really Simple Security plugin