
CVE-2021-24145
WordPress File Upload Vulnerability, Modern Events Calendar Lite WordPress plugin before 5.16.5

WordPress File Upload Vulnerability, Modern Events Calendar Lite WordPress plugin before 5.16.5

Web application penetration testing lab — vulnerable Flask app, automated scanner, and professional pentest report. Covers OWASP Top 10, SQLi, XSS,…

Ninja Forms File Uploads <= 3.3.26 - Unauthenticated Arbitrary File Upload

Automated exploit tool for CVE-2018-9206 (jQuery File Upload) with single/multi-target scanning, Tor proxy support, and output logging for…

Lab Environment for CVE-2026-22241

Proof-of-concept exploit for CVE-2022-30887, demonstrating remote code execution via file upload in Pharmacy Management System 1.0, with mitigation…

Drag and Drop Multiple File Upload for WooCommerce <= 1.1.6 - Unauthenticated Arbitrary File Upload via upload Function

Detailed security advisory for CVE-2026-36669: unauthenticated arbitrary file upload in Feng Office, enabling stored XSS and session hijacking.…

Post Saint <= 1.3.1 plugin for WordPress Arbitrary File Upload

Local Docker lab demonstrating CVE-2026-5718 arbitrary file upload in a WordPress plugin, with vulnerable and patched services for side-by-side…

Python exploit for CVE-2020-29607 that bypasses file upload restrictions in Pluck CMS to upload a PHP webshell, enabling remote command execution on…

PHP script and guide for injecting PHP webshells into JPEG images using Jhead. Used to bypass file upload filters and achieve remote command…

Cross-site scripting labs for web application security enthusiasts

PoC and lab reproduction for CVE-2026-88533, an unauthenticated arbitrary file write leading to root RCE in QAnything via path traversal in the…

The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.12 via the…

Exploit script for CVE-2023-24249 - a vulnerability allowing remote code execution via file upload and command injection.

PoC CVE-2023-29386 — Manager for Icomoon < 2.1 - Unauthenticated Arbitrary File Upload

CVE-2023-40028 affects Ghost, an open source content management system, where versions prior to 5.59.1 allow authenticated users to upload files that…