
CVE-2026-64638
Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…

Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…

Proof of concept and root-cause analysis for an authenticated arbitrary file upload in WordPress Theme Demo Import leading to remote code execution…

CVE Reproduction: cve-2026-63030_60137-wordpress_rce_reproduction

CVE Reproduction: cve-2024-50330-ivanti_epm_sqli_reproduction

Frontend File Manager Plugin (WordPress) <= 23.6 - Unauthenticated Arbitrary File Deletion to RCE

Reproducer for CVE-2026-33454: Apache Camel camel-mail header injection to RCE via camel-exec

PoC Magento Session Reaper - CVE-2025-54236

CVE-2024-37032 (Probllama) PoC for Ollama ≤0.1.33: path traversal and arbitrary file write via model digest handling, leading to automated privilege…

A JavaScript Obfuscator based on Cryptographic Indistinguishability Obfuscation techniques

Finding Java/C# gadget chains with CodeQL

Publicly disclosed Proof-of-Concept (POC) exploit for the [email protected] version

Exploit for CVE-2026-3300, an unauthenticated stored XSS leading to RCE in Everest Forms Pro WordPress plugin, with a Python script to generate a…

This is POC repo for CVE-2026-48208

Automated RCE exploit for WordPress WPCode Lite v2.3.5 (CVE-2026-8832) with 8 built-in PHP payloads, XML-RPC bypass, and web-based interactive shell…

Automated RCE exploit for WordPress WPCode Lite v2.3.5. Executes 6-step exploitation chain via XML-RPC bypass with 8 built-in PHP payloads, including…

CVE-2026-3296 is a CVSS 9.8 Critical unauthenticated PHP Object Injection vulnerability in the Everest Forms WordPress plugin

CVE-2026-5718: Unauthenticated File Upload To RCE in DnD Upload CF7 Plugin

CVE-2026-44403-WingFTP-v8.1.2-POC-Exploit