
CVE-2026-7393-RCE
Proof-of-concept exploit for CVE-2026-7393: unrestricted file upload in Pizzafy Ecommerce System 1.0 allowing authenticated administrators to upload…

Proof-of-concept exploit for CVE-2026-7393: unrestricted file upload in Pizzafy Ecommerce System 1.0 allowing authenticated administrators to upload…

CVE-2020-26259 &&XStream Arbitrary File Delete

Proof-of-concept exploit for authenticated unrestricted file upload leading to remote code execution in MachForm up to version 21, with detailed…

Detection scripts for CVE-2023-50164 in Apache Struts2, providing PowerShell and Bash tools to scan for vulnerable versions across file systems and…

Medical Prescription Attachment Plugin for WooCommerce <= 1.2.3 - Unauthenticated Arbitrary File Upload.

WooCommerce Designer Pro 1.9.26 - Arbitrary File Upload

CIBELES AI <= 1.10.8 - Unauthenticated Arbitrary File Upload

Tainacan <= 0.21.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read

PoC exploit for CVE-2024-52302: unrestricted file upload in common-user-management Spring Boot app leading to remote code execution via…

Python exploit for CVE-2015-10137 targeting an arbitrary file upload vulnerability in the WordPress N-Media Website Contact Form plugin, enabling…

Kalrav AI Agent <= 2.3.3 - Unauthenticated Arbitrary File Upload via kalrav_upload_file AJAX Action

Flex QR Code Generator <= 1.2.6 - Unauthenticated Arbitrary File Upload

S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator <= 1.7.7 - Authenticated (Editor+) Arbitrary File Upload

Ultimate Addons for Contact Form 7 <= 3.5.12 - Authenticated (Administrator+) Arbitrary File Upload via 'save_options'

StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More <= 1.4.0 - Authenticated (Subscriber+)…

Python exploit script for CVE-2025-2294, an unauthenticated Local File Inclusion vulnerability in WordPress Kubio AI Page Builder ≤ 2.5.1. Supports…

Proof-of-concept exploit for CVE-2021-29425, an XML External Entity (XXE) vulnerability in Apache Tika, demonstrating file disclosure and SSRF via…

Download Plugin <= 2.2.8 - Authenticated (Administrator+) Arbitrary File Upload