
CVE-2023-50564
Authenticated remote code execution exploit for Pluck CMS v4.7.18. Automatically creates and uploads a malicious ZIP module containing a PHP shell to…

Authenticated remote code execution exploit for Pluck CMS v4.7.18. Automatically creates and uploads a malicious ZIP module containing a PHP shell to…

Proof-of-concept exploit for authenticated PHP code injection in ISPConfig <= 3.2.11, enabling remote code execution via unsanitized language file…

CVE-2021-46076 - Sourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload. An attacker can upload a malicious php file in…

Remote code execution exploit for CVE-2019-11043 targeting Nginx with php-fpm. Includes Go and pre-compiled exploit binaries for testing vulnerable…

Instantio - Wordpress Plugin <= 3.3.16 - Authenticated (Admin+) Arbitrary File Upload via ins_options_save

Ultimate Before After Image Slider & Gallery – BEAF <= 4.6.10 - Authenticated (Admin+) Arbitrary File Upload via beaf_options_save

CVE-2025-3914-PoC | The Aeropage Sync for Airtable WordPress plugin (≤ v3.2.0) is vulnerable to authenticated arbitrary file uploads due to…

Migration,Backup, Staging – WPvivid <= 0.9.112 - Authenticated (Admin+) Arbitrary File Upload via wpvivid_upload_file

ARPrice <= 4.0.3 - Authenticated (Subscriber+) PHP Object Injection

GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection

Exploit tool for CVE-2021-44228 (Log4Shell) with LDAP/JNDI injection server, payload generation, and single-target exploitation script for testing…

Builds proof-of-concept payloads for CVE-2021-46703, a RazorEngine template injection vulnerability, with C# and Python implementations for testing…

nameko Arbitrary code execution due to YAML deserialization

Proof-of-concept exploit for CVE-2024-32830 demonstrating file download via PHP filter chain bypassing getimagesize() restrictions using iconv and…

Proof-of-concept exploit for CVE-2024-10410: unrestricted file upload in Online Hotel Reservation System. Demonstrates bypass of image validation via…

Proof-of-concept exploit for CVE-2017-7504 targeting JBoss 4.x JBossMQ JMS deserialization vulnerability. Includes usage help via -h flag.

Proof-of-concept for authenticated arbitrary file upload in Sitecore 10.3, enabling webshell deployment and remote code execution via the import…

Exploit for CVE-2020-35314 delivering a PHP code payload embedded in a ZIP file for web application exploitation.