
wp-secure-mcp
A WordPress plugin exposing an MCP server over the REST API, with the security model as the point -- closes the CVE-2026-15015 OAuth-bypass shape by…

A WordPress plugin exposing an MCP server over the REST API, with the security model as the point -- closes the CVE-2026-15015 OAuth-bypass shape by…

The Super Vulnerable Java Application (SVJA), as demonstrated in the Roniel and DaRon Podcast Show, is an Apache Struts application designed to…

Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input validation,…

Java security framework providing authentication, authorization, cryptography, and session management APIs to secure any application from mobile to…

Security research on Fortinet FortiWeb vulnerabilities (CVE-2025-64446, CVE-2025-58034)

Exploit module for Apache JSPWiki CVE-2022-46907, targeting a Java-based wiki platform with JAAS security integration. Provides vulnerability…

A project demonstrating an app that is vulnerable to Spring Security authorization bypass CVE-2022-31692

CVE-2025-29927 is a critical security vulnerability affecting Next.js, a popular React framework for building full-stack web applications. This flaw…

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application…

Open source Dropbox-like file sharing with full client encryption !

An organizational asset and vulnerability management tool, with Jira integration, designed for generating application security reports.