
CVE-2024-25092
NextMove Lite < 2.18.0 - Subscriber+ Arbitrary Plugin Installation/Activation

NextMove Lite < 2.18.0 - Subscriber+ Arbitrary Plugin Installation/Activation

WordPress Passster Plugin <= 4.2.18 is vulnerable to Cross Site Scripting (XSS)

Download Plugin <= 2.2.8 - Authenticated (Administrator+) Arbitrary File Upload

GiveWP – Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection

GiveWP – Donation Plugin and Fundraising Platform <= 3.19.3 - Unauthenticated PHP Object Injection

PostX <= 4.1.16 - Missing Authorization to Arbitrary Plugin Installation/Activation

Wordpress IgniteUp plugin < 3.4.1 allows unauthenticated users to arbitrarily delete files on the webserver possibly causing DoS.

Instantio - Wordpress Plugin <= 3.3.16 - Authenticated (Admin+) Arbitrary File Upload via ins_options_save

Plugin to fix security vulnerability CVE-2023-40626 in Joomla 3.10.12

Maps execution-coverage data onto Ghidra disassembly to highlight visited code paths and accelerate reverse-engineering workflows.

PoC of CVE-2025-22783


CVE-2025-13486 - Remote Code Execution & Privilege Escalation exploit

CIBELES AI <= 1.10.8 - Unauthenticated Arbitrary File Upload

S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator <= 1.7.7 - Authenticated (Editor+) Arbitrary File Upload

WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting

Kalrav AI Agent <= 2.3.3 - Unauthenticated Arbitrary File Upload via kalrav_upload_file AJAX Action

Flex QR Code Generator <= 1.2.6 - Unauthenticated Arbitrary File Upload