
CVE-2026-11991-Exploit
Automated exploit for CVE-2026-11991, an authorization bypass in FlowForms WordPress plugin allowing Contributor+ users to publish any draft form via…

Automated exploit for CVE-2026-11991, an authorization bypass in FlowForms WordPress plugin allowing Contributor+ users to publish any draft form via…

Proof-of-concept for CVE-2026-79483, a NoSQL injection in FastGPT Community Edition allowing unauthenticated access to chat history titles. Includes…

Tozed ZLT X300 5G CPE — Remote Root Code Execution via SDR Rogue Base Station (CVE-2026-2035703, CWE-78, CVSS 9.8) — Coordinated Disclosure

Reproduces CVE-2026-1581, an unauthenticated time-based SQL injection in wpForo Forum <=2.4.14, with a Docker lab and PoC to demonstrate the…

Security Research and Proof-of-Concept (PoC) for CVE-2026-0300 : Unauthenticated Remote Code Execution (RCE) in Palo Alto Networks PAN-OS User-ID…

Detailed analysis of CVE-2026-22038, a high-severity vulnerability in AutoGPT Stagehand blocks that logs API keys in plaintext, including root cause,…

Proof-of-concept for CVE-2023-7173, a stored XSS in Hospital Management System 1.0, with Docker setup and reproduction steps.

Reflected XSS proof-of-concept for School Management System 1.0, demonstrating unauthenticated JavaScript execution via the type parameter in…

Advisory detailing a reflected XSS vulnerability in PuneethReddyHC Event Management System v1.0, including impact analysis, reproduction steps, and…

Advisory and proof-of-concept for a time-based blind SQL injection vulnerability in an online shopping system, including technical details, impact…

Proof-of-concept demonstrating command injection in Windows Notepad via crafted Markdown links, enabling remote code execution. Includes attack…

Educational CSRF vulnerability demonstration with a controlled lab environment, including a proof-of-concept exploit and a fixed version with proper…

CVE-2026-27579 - CORS Misconfiguration – Arbitrary Origin with Credentials → Authenticated Cross-Origin Account Data Exposure

esponsible disclosure write-ups for CVE-2026-8793 - PaperCut NG 25.0.11

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

You didn't think I'd go and leave the blue team out, right?

Blog post exploring macOS App Sandbox, entitlements via codesign, and sandbox escape techniques using launchd, LaunchAgents, and quarantine…

Educational lab environment for CVE-2021-3156 (Baron Samedit) with a Dockerized vulnerable sudo target, exploit scaffold, canary test, root-cause…