
static-code-analysis-helper
Scans project source code across 16 languages to flag dangerous functions linked to SQLi, XSS, SSRF, command injection, weak crypto, and other web…

Scans project source code across 16 languages to flag dangerous functions linked to SQLi, XSS, SSRF, command injection, weak crypto, and other web…

CVE-2026-19264 - Critical unauthenticated path traversal to full instance takeover in Postiz (< 2.22.1). Technical writeup: decode-order bypass,…

Twitter vulnerable snippets

Mind-Maps of Several Things


CVE-2026-52887 — NocoBase SQL injection -> PostgreSQL-superuser RCE (myInAppChannels:list filter, CVSS 10.0). Author PoC + source analysis + docker…

GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection

ARPrice <= 4.0.3 - Authenticated (Subscriber+) PHP Object Injection

MAGNOLIA-8281: FreeMarker Restriction Bypass 2 in Magnolia CMS

WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting

CraftCMS CVE-2025-32432 - Clean PoC

Nuclio Dashboard (NOP mode) accepts unauthenticated POST /api/functions. The spec.handler field isn't path-validated, so…

Security Advisory: HTTP Response Splitting via Unvalidated Response Header Values (rouille)

Security Advisory: Unchecked Room Lookup Leads to Server Crash (Let's Chat)

Security Advisory: Camaleon CMS - Authenticated RCE via `select_eval` Custom Field