
CVE-2026-26980
Unauthenticated SQL injection exploit for Ghost CMS Content API (CVE-2026-26980); dumps database tables from SQLite/MySQL with active/passive checks…

Unauthenticated SQL injection exploit for Ghost CMS Content API (CVE-2026-26980); dumps database tables from SQLite/MySQL with active/passive checks…

Proof-of-concept exploit for an authenticated SQL injection vulnerability in JFinal CMS 5.1.0, demonstrating information disclosure and potential…

CVE-2022-37203 POC

Ghost CMS Content API Blind SQL Injection

CVE-2022-37210 POC

CVE-2022-37205 POC

CVE-2023-45503 Reference

RedDot CMS versions 7.5 Build 7.5.0.48 and below full database enumeration exploit that takes advantage of a remote SQL injection vulnerability in…

Proof-of-concept exploit for CVE-2018-6376, a second-order SQL injection vulnerability in Joomla! CMS, with Docker-based test environment.

Proof-of-concept exploit for CVE-2023-31714, a pre-authentication SQL injection in Chitor-CMS < 1.1.2. Automates database enumeration and credential…

Proof-of-concept exploit for CVE-2025-22964, a time-based blind SQL injection vulnerability in DDSN Interactive cm3 Acora CMS 10.1.1, enabling…

SQL Injection in MongoLite Aggregation Optimizer via toJsonExtractRaw()

CVE-2024-45265

CVE-2022-37206 POC

CVE-2026-26980 — Ghost CMS Content API SQL Injection Lab (unauthenticated blind SQLi via slug filter ordering)

Exploit script for CVE-2024-32640, an SQL injection vulnerability in Mura/Masa CMS, using ghauri to enumerate and dump database contents.

Proof-of-concept exploit for a critical time-based blind SQL injection vulnerability in WBCE CMS, enabling low-privileged users to execute arbitrary…