
CVE-2025-4334
Simple User Registration <= 6.3 - Unauthenticated Privilege Escalation

Simple User Registration <= 6.3 - Unauthenticated Privilege Escalation

Simple flask application to implement an intentionally vulnerable web app to demo CVE-2023-2822.

PoC exploit for CVE-2024-1813: PHP object injection in Simple Job Board WordPress plugin, achieving unauthenticated RCE via gadget chain. Includes…

Lab environment and exploit script for CVE-2024-10924, demonstrating MFA bypass in WordPress via the Really Simple SSL plugin's skip_onboarding…

PoC didático em Python 3 para a CVE-2019-9053, uma SQL Injection time-based blind no CMS Made Simple <= 2.2.9. Esta versão foi adaptada para uso em…

A simple python script to exploit CVE-2025-59528, this an Authenticated RCE vulnerability in Flowise application, a popular AI tool. That is also…

HackTheBox TwoMillion machine writeup — API abuse, command injection & CVE-2023-0386

Step-by-step walkthrough of exploiting CVE-2022-22965 (Spring4Shell) with Metasploit, deploying a C2 listener, and mitigating the vulnerability by…

Professional TryHackMe Simple CTF walkthrough covering enumeration, CMS Made Simple SQL Injection (CVE-2019-9053), credential recovery, SSH access,…

First CTF successfully completed! This repo documents my walkthrough of TryHackMe's Simple CTF. It covers network reconnaissance (Nmap), web…

CMS Made Simple < 2.2.10 - SQL Injection . Actual working version

Python3 exploit for CVE-2019-9053 (CMS Made Simple <= 2.2.9 SQLi). No deps, time-based blind SQLi → admin creds dump. HTB Writeup owned.

This is a modified version of the time-based SQL injection exploit for CMS Made Simple <= 2.2.9. The exploit was originally created by Daniele Scanu…

A simple python script to exploit CVE-2021-31630 on HTB WifineticTwo CTF

Step-by-step CTF walkthrough demonstrating CVE-2019-9053 SQL injection exploitation and GTFOBins-based privilege escalation on a CMS Made Simple…

It is a simple script to automate internal port scanning dueto SSRF in requests-baskets v 1.2.1. this script can also assisst in solving 'SAU'…

A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.

Proof-of-concept exploit for CVE-2025-49132, abusing a file inclusion vulnerability in Pterodactyl to achieve remote code execution via pearcmd.php.