
CVE-2026-76564
Stored XSS via User-Agent in Admin Order View in PhocaCart

Stored XSS via User-Agent in Admin Order View in PhocaCart
Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…

CVE-2023-22518 exploit analysis for Atlassian Confluence Server covering setup, JAR diffing, root cause, and unauthorized restore to regain admin…

The code for personally reproducing the corresponding vulnerability

Pre-authentication remote code execution tool for WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1. Chains SQLi with REST API desync to create admin accounts…

Exploit for CVE-2021-27651: bypasses Pega Infinity password reset flow to reset any user's password, enabling admin login and subsequent remote code…

Proof-of-concept exploit for CVE-2021-26121: Server-Side Template Injection in CS-Cart <=4.12.x allowing shop admin to achieve remote code execution…

Proof-of-concept for SQL injection vulnerability (CVE-2024-25422) in SEMCMS v4.8, with payload construction and filter bypass analysis for the admin…

WordPress Custom Login And Signup Widget Plugin <= 1.0 is vulnerable to Arbitrary Code Execution

Python exploit for CVE-2025-13486 targeting unauthenticated remote code execution and privilege escalation in the ACF Extended WordPress plugin, with…

Proof-of-concept exploit for CVE-2024-22411 targeting the Avo admin panel. Demonstrates vulnerability exploitation in Ruby-based web applications.

Proof-of-concept exploit for CVE-2024-34832: directory traversal in CubeCart admin panel leading to remote code execution via crafted `_g` parameter…

Authenticated remote code execution exploit for Pluck CMS v4.7.18. Automatically creates and uploads a malicious ZIP module containing a PHP shell to…

Instantio - Wordpress Plugin <= 3.3.16 - Authenticated (Admin+) Arbitrary File Upload via ins_options_save

Ultimate Before After Image Slider & Gallery – BEAF <= 4.6.10 - Authenticated (Admin+) Arbitrary File Upload via beaf_options_save

An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if…

Download Plugin <= 2.2.8 - Authenticated (Administrator+) Arbitrary File Upload

Migration,Backup, Staging – WPvivid <= 0.9.112 - Authenticated (Admin+) Arbitrary File Upload via wpvivid_upload_file