
SecureCodingDojo
The Secure Coding Dojo is a platform for delivering secure coding knowledge.

The Secure Coding Dojo is a platform for delivering secure coding knowledge.

Proof-of-concept for authenticated arbitrary file upload in Sitecore 10.3, enabling webshell deployment and remote code execution via the import…

Security Advisory: Unchecked Room Lookup Leads to Server Crash (Let's Chat)

Exploit on the default cache of superset by using pickle

Proof-of-concept exploit for CVE-2026-34197, demonstrating authenticated remote code execution in Apache ActiveMQ via Jolokia JMX-HTTP bridge and…

PHP Object Injection exploit for Adminer <4.8.1 via Monolog, causing Denial of Service through crafted serialized payloads. Includes PoC, CVSS…

SnakeYAML-CVE-2022-1471-POC

PoC Magento Session Reaper - CVE-2025-54236

More than a ReClass port to the .NET platform.

Android security insights in full spectrum.

PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container

Sandbox untrusted code with safe access to the host.

Silent dependency injection through AI documentation pipelines. 240 isolated Docker runs proving Context Hub's zero-sanitization MCP server lets…

Example application, vulnerable to CVE-2023-32692 (Validation Rule Injection in the PHP Framework CodeIgniter)

Educational PoC and analysis of CVE-2012-1823, a PHP-CGI remote code execution vulnerability. Includes Docker-based test environment, exploit…

The CVE-2024-28397 vulnerability affects versions of js2py up to v0.74, a Python library that allows JavaScript code to be executed within the Python…

Vulnearability Report of the New Jersey official site

Educational lab demonstrating CVE-2017-8291 (PIL/GhostScript RCE) via crafted EPS file upload with PNG extension, including Docker setup and PoC…