
CVE-2026-73309
Proof-of-concept and technical write-up for CVE-2026-73309, an OAuth2 authentication bypass in XenForo before 2.3.13. Demonstrates empty…

Proof-of-concept and technical write-up for CVE-2026-73309, an OAuth2 authentication bypass in XenForo before 2.3.13. Demonstrates empty…

Proof-of-concept exploit for XenForo CVE-2026-73318, an authorization bypass allowing ACP administrators to trigger site-wide policy re-agreement.…

Exploit script for CVE-2026-41940, an authentication bypass in cPanel/WHM using CRLF injection to gain admin access and change root password, with…

Educational Docker lab demonstrating CVE-2026-39987, a pre-auth RCE via WebSocket authentication bypass in marimo, with exploit script and patch…

cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

Python PoC for CVE-2026-3456 demonstrating OAuth2 PKCE race-condition account takeover, with a vulnerable auth server and concurrent code-verifier…

cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)

Python script for checking authentication bypass vulnerability (WT-2025-0011) in Kentico Xperience 13 CMS Staging Service via POST request analysis.

Python script to exploit the OWASSRF + TabShell chain on vulnerable Microsoft Exchange servers, leveraging Kerberos authentication for command…

JetBrains TeamCity Authentication Bypass CVE-2023-42793 Exploit

Proof-of-concept exploit for CVE-2024-41713, demonstrating authentication bypass in Mitel MiCollab leading to arbitrary file read. Includes a Python…

ScriptCase Pre-Authenticated Remote Command Execution exploitation script (CVE-2025-47227, CVE-2025-47228).

Python exploit script for CVE-2025-41646, an authentication bypass in RevPi Webstatus <= 2.4.5. Supports single/mass exploitation, proxy, silent…

WordPress Plugin Digits < 8.4.6.1 - OTP Auth Bypass via Bruteforce (CVE-2025-4094)

This Python script exploits a critical mass assignment vulnerability in Camaleon CMS version 2.9.0, allowing any registered user to escalate their…

Python exploit script for CVE-2024-1709, an authentication bypass vulnerability in ConnectWise ScreenConnect. Adds a new administrative user to the…

Python script to detect CVE-2023-3128 authentication bypass in Grafana via Azure AD email claim validation. Checks Azure AD SSO configuration and…