
CVE-2026-76564
Stored XSS via User-Agent in Admin Order View in PhocaCart

Stored XSS via User-Agent in Admin Order View in PhocaCart
Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…

Pre-authentication remote code execution tool for WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1. Chains SQLi with REST API desync to create admin accounts…

The code for personally reproducing the corresponding vulnerability

CVE-2026-2587 PoC validator for Eclipse GlassFish EL Injection RCE in the admin console gadget.jsf handler. Safe authenticated vulnerability scanner…

Python exploit for CVE-2025-13486 targeting unauthenticated remote code execution and privilege escalation in the ACF Extended WordPress plugin, with…

An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if…

WordPress Custom Login And Signup Widget Plugin <= 1.0 is vulnerable to Arbitrary Code Execution

Download Plugin <= 2.2.8 - Authenticated (Administrator+) Arbitrary File Upload

Authenticated remote code execution exploit for Pluck CMS v4.7.18. Automatically creates and uploads a malicious ZIP module containing a PHP shell to…

Instantio - Wordpress Plugin <= 3.3.16 - Authenticated (Admin+) Arbitrary File Upload via ins_options_save

Ultimate Before After Image Slider & Gallery – BEAF <= 4.6.10 - Authenticated (Admin+) Arbitrary File Upload via beaf_options_save

CVE-2023-22518 exploit analysis for Atlassian Confluence Server covering setup, JAR diffing, root cause, and unauthorized restore to regain admin…

Migration,Backup, Staging – WPvivid <= 0.9.112 - Authenticated (Admin+) Arbitrary File Upload via wpvivid_upload_file

Proof-of-concept exploit for CVE-2024-34716, a PNG-driven XSS to RCE chain in PrestaShop 8.1.5, enabling remote code execution via crafted image…

Proof-of-concept exploit for CVE-2024-34832: directory traversal in CubeCart admin panel leading to remote code execution via crafted `_g` parameter…

Proof-of-concept for SQL injection vulnerability (CVE-2024-25422) in SEMCMS v4.8, with payload construction and filter bypass analysis for the admin…

Proof-of-concept exploit for CVE-2024-22411 targeting the Avo admin panel. Demonstrates vulnerability exploitation in Ruby-based web applications.