



👻 CVE-2026-54121 - Best CertiGhost AD CS Multi-Exploit Framework | Advanced toolkit with rogue DC/LDAP servers, certificate abuse, PKINIT hash…

WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action

CVE-2026-41452 — Krayin CRM unauth installer bypass (X-Requested-With) → admin takeover. Verified: overwrite + login on 2.2.4, blocked on 2.2.5

Unauthenticated administrator takeover exploit for CVE-2026-66012 using MCP missing authorization to exfiltrate credentials and achieve remote code…

CVE-2026-8206 Kirki Plugin Unauthenticated Account Takeover Exploit

CVE-2026-7459 Simple History Missing Authorization Account Takeover Exploit

PoC exploit for CVE-2026-10580 - Authentication Bypass in Hippoo Mobile App for WooCommerce <= 1.9.4 leading to Admin Account Takeover

PoC exploit for CVE-2026-2991 — authentication bypass in KiviCare WordPress plugin (≤4.1.2) allowing unauthenticated patient account takeover and…

The forgot-password endpoint in Flowise returns sensitive information including a valid password reset tempToken without authentication or…

Flynax Bridge <= 2.2.0 - Unauthenticated Privilege Escalation via Account Takeover

Eventin <= 4.0.34 - Authenticated (Contributor+) Privilege Escalation via User Email Change/Account Takeover

Stacks Mobile App Builder <= 5.2.3 - Authentication Bypass via Account Takeover

PoC for the type confusion vulnerability in Mac's CMS that results in authentication bypass and administrator account takeover.

1-Click Login: Passwordless Authentication 1.4.5 - Authentication Bypass via Account Takeover

Docker lab reproducing CVE-2026-71362 Magento/Adobe Commerce account takeover via customer-session identity switch, with PoC and official-patch A/B/A…

CVE-2023-7028