
sudowp-postgallery
A security-hardened fork of the abandoned "PostGallery" WordPress plugin. Fixes critical Arbitrary File Upload (CVE-2025-13543) and Guest Access…

A security-hardened fork of the abandoned "PostGallery" WordPress plugin. Fixes critical Arbitrary File Upload (CVE-2025-13543) and Guest Access…

Multi-language detection scripts for CVE-2025-55182 (React2Shell) that scan package.json files to identify vulnerable React dependency versions and…

Obfuscate a python code 2.x and 3.x

CVE-2022-1329 exploit for WordPress Elementor plugin (3.6.0-3.6.2) enabling authenticated remote code execution via missing capability check and…

a javascript static security analysis tool

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

bypass all stages of the password reset flow

The Secure Coding Framework


WordPress Passster Plugin <= 4.2.18 is vulnerable to Cross Site Scripting (XSS)

More than a ReClass port to the .NET platform.

Security Advisory: Unauthenticated Path Traversal Allows Arbitrary File Read (TinyWeb)

Educational CVE-2024-12877 exploit demo for PHP Object Injection in GiveWP WordPress plugin. Includes root cause analysis, regex bypass techniques,…

A lightweight dynamic instrumentation library

VBScript & VBA source-to-source deobfuscator with partial-evaluation

Cross Site Scripting vulnerability in ConcreteCMS v.9.2.1 allows a local attacker to execute arbitrary code via a crafted script to the Plural Handle…

The AI Security Verification Standard (AISVS) focuses on providing developers, architects, and security professionals with a structured checklist to…