
cve-2026-41940-PoC
Exploits cPanel/WHM CVE-2026-41940 authentication bypass via CRLF session injection for unauthenticated root-level WHM access, then lists accounts,…

Exploits cPanel/WHM CVE-2026-41940 authentication bypass via CRLF session injection for unauthenticated root-level WHM access, then lists accounts,…

PoC: Shiori JWT CheckToken never re-validates account state (CVE-2026-71206, High 8.2)

Docker lab reproducing CVE-2026-71362 Magento/Adobe Commerce account takeover via customer-session identity switch, with PoC and official-patch A/B/A…

Exploit for CVE-2026-41940, an unauthenticated authentication bypass in cPanel/WHM that grants root-level WHM access via CRLF session injection, with…

Pre-auth RCE exploit for Craft CMS in Go. Grabs session/CSRF token, poisons PHP session, triggers deserialization for command execution or reverse…

Boundary enables identity-based access management for dynamic infrastructure.

PoC exploit for CVE-2026-2991 — authentication bypass in KiviCare WordPress plugin (≤4.1.2) allowing unauthenticated patient account takeover and…


The VTEX Checkout Service exposes OrderForm data through the endpoints `/api/checkout/pub/orderForm/{orderFormId}` and `/attachments/*`. These…

Apahce-Superset身份认证绕过漏洞(CVE-2023-27524)检测工具

Technical analysis of the cPanel/WHM auth bypass



This repository details an IDOR vulnerability in AbsysNet 2.3.1, which allows a remote attacker to brute-force session IDs via the /cgi-bin/ocap/…

Authentication Bypass for FreeScout End-User Portal

A POC for the all new CVE-2023-27524 which allows for authentication bypass and gaining access to the admin dashboard.

Automated scanner & post-exploitation toolkit for CVE-2026-41940 — cPanel & WHM root authentication bypass via session-file CRLF injection

🚀 CVE-2026-41940 cPanel/WHM Auth Bypass Exploit - Best Flow 💥 CRLF injection leads to auth bypass, session hijacking & account leak. ✅ Proxy,…