
sudowp-crowdsignal-forms
A security-hardened fork of Crowdsignal Forms. Patches CVE-2025-69015 (Broken Access Control), modernizes for PHP 8.2+, and enforces strict…

A security-hardened fork of Crowdsignal Forms. Patches CVE-2025-69015 (Broken Access Control), modernizes for PHP 8.2+, and enforces strict…

PHP 8.4+ security library (mirror)

The Symfony PHP framework

Better PHP rate limiting using Redis.

Collaborative Passwords Manager

PHP-RBAC is an authorization library for PHP. It provides developers with NIST Level 2 Standard Role Based Access Control and more, in the fastest…

Pre-auth RCE exploit for Craft CMS in Go. Grabs session/CSRF token, poisons PHP session, triggers deserialization for command execution or reverse…

Shadow Vault – Add shadow users with SHA-512 hash, auto aging match, multiple write fallbacks.

Multiple exploits for Monitorr

PoC for the type confusion vulnerability in Mac's CMS that results in authentication bypass and administrator account takeover.

Proof of Concept for vulnerability CVE-2023-2986 in 'Abandoned Cart Lite for WooCommerce' Plugin in WordPress

Public Disclosure