
VulnReach
Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.
code-analysisdevsecopsdynamic-analysis-sandboxing+5
13

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

WordPress wp2shell pre-auth RCE exploit kit (CVE-2026-63030 + CVE-2026-60137)

CVE-2026-63030: WordPress REST batch-endpoint array desync. Mechanism, detection, mitigation, and a safe reproduction lab.

Educational PoC + lab for CVE-2026-63030 + CVE-2026-60137: pre-auth SQLi in WordPress core via REST batch-route confusion

PoC for CVE-2024-1512 in MasterStudy LMS WordPress Plugin.

Link sources to sinks in C# applications.