


POC to exploit WordPress 5.6-5.7 (PHP 8+) Authenticated XXE Injection.


PoC and Disclosure for CVE-2023-7231 – Memcached Gopher RCE chain

This is a PoC/Exploit for the CVE-2024-47875 PhpSpreadsheet XSS Vuln

Info and exploit for CVE-2023-29930: blind file read/write in Genesys TFTP provisioning server configuration

Axigen < 10.3.3.47, 10.2.3.12 - Reflected XSS

CVE-2025-55182 & CVE-2025-66478 proof of concepts

React2Shell Exploitation Tool (CVE-2025-55182)



Citrix Bleed 2 PoC Scanner (CVE-2025-5777)

Roundcube mail server exploit for CVE-2024-37383 (Stored XSS)


Unauthenticated SQL injection exploit for Ghost CMS Content API (CVE-2026-26980); dumps database tables from SQLite/MySQL with active/passive checks…

POC of CVE-2026-51031 for arbitrary local file read

Notepad++ CVE-2026-52886 — session.xml backupFilePath starts_with() path traversal (GHSA-rqfm-pw34-r7j6)