
CVE-2026-41940-PoC-Exploit
🚀 CVE-2026-41940 cPanel/WHM Auth Bypass Exploit - Best Flow 💥 CRLF injection leads to auth bypass, session hijacking & account leak. ✅ Proxy,…

🚀 CVE-2026-41940 cPanel/WHM Auth Bypass Exploit - Best Flow 💥 CRLF injection leads to auth bypass, session hijacking & account leak. ✅ Proxy,…

Pre-auth RCE exploit for Craft CMS in Go. Grabs session/CSRF token, poisons PHP session, triggers deserialization for command execution or reverse…

POC for CVE-2026-30950 which allows session hijacking in AutoGpt

The VTEX Checkout Service exposes OrderForm data through the endpoints `/api/checkout/pub/orderForm/{orderFormId}` and `/attachments/*`. These…

PoC exploit for CVE-2026-2991 — authentication bypass in KiviCare WordPress plugin (≤4.1.2) allowing unauthenticated patient account takeover and…

Poc for Unauthenticated Admin Session Hijack - Pie Register Plugin (≤ 3.7.1.4)

This repository details an IDOR vulnerability in AbsysNet 2.3.1, which allows a remote attacker to brute-force session IDs via the /cgi-bin/ocap/…

PaperCut NG/MG Authentication Bypass and Remote Code Execution (RCE) Exploit Tool. A standalone Bash implementation of the PaperCut exploit chain,…

Vertical Privilege Escalation via Session Storage by Amjad Ali (CVE-2023-43317)

Exploits cPanel/WHM CVE-2026-41940 authentication bypass via CRLF session injection for unauthenticated root-level WHM access, then lists accounts,…

Exploit for CVE-2026-41940, an unauthenticated authentication bypass in cPanel/WHM that grants root-level WHM access via CRLF session injection, with…

Boundary enables identity-based access management for dynamic infrastructure.

Apahce-Superset身份认证绕过漏洞(CVE-2023-27524)检测工具

Technical analysis of the cPanel/WHM auth bypass

PHP 8.4+ security library (mirror)


Admin-only terminal bootstrap routes checked only for login state, which let a normal team member drive Coolify's realtime terminal backend and…

Automated scanner & post-exploitation toolkit for CVE-2026-41940 — cPanel & WHM root authentication bypass via session-file CRLF injection