
CVE-2026-63072
Technical analysis of CVE-2026-63072, a heap buffer overflow in OpenSSL CMS key unwrapping, covering root cause, affected versions, detection, and…

Technical analysis of CVE-2026-63072, a heap buffer overflow in OpenSSL CMS key unwrapping, covering root cause, affected versions, detection, and…

A fuel CMS exploit based on Python for RCE mentioned in CVE-2018-16763.

渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor…

PoC exploit for Wolf CMS <= 0.8.3.1: authenticates to Admin, writes an arbitrary PHP file to /public via FileManagerController, and executes commands…

Analysis and Docker reproduction of CVE-2024-28116 - SSTI with sandbox bypass in Grav CMS

Advisory and Python PoC for Pluck CMS CSRF: fail-open Referer check plus double-extension upload enables webshell deployment and remote code…

Persistent XSS in Typemill CMS: the Markdown parser lets javascript: URIs through unfiltered. Writeup + PoC.

Maintained Python 3 port of the original FUEL CMS CVE-2018-16763 proof-of-concept.

Proof-of-concept exploit for CVE-2026-70553, enabling unauthenticated RCE in MaxSite CMS via persistent PHP injection into database.php through the…

Technical write-up for CVE-2026-8337, an IDOR in Concrete CMS Survey that lets unauthenticated attackers influence private survey results by…

In-depth IDOR write-up for Concrete CMS, covering the message_detail endpoint, missing authorization root cause, attack scenarios, impact, and fix.

Security write-up for an IDOR in Concrete CMS exposing conversation ratings through missing authorization on the get_rating endpoint, with root…


PoC for CVE-2026-65694 — Microweber CMS (<=2.0.20) unauthenticated path traversal → arbitrary file read (.env / secrets)

Single-target proof of concept for CVE-2025-32432, a pre-authentication remote code execution in Craft CMS. Performs vulnerability confirmation via…

Safely demonstrates CVE-2026-16219 path traversal in Croogo CMS with a loopback-only PoC, technical analysis, remediation guidance, and standalone…

Proof-of-concept exploit for CVE-2026-48909: unauthenticated remote code execution via PHP object injection in JoomShaper SP LMS. Includes detection,…

PoC for CVE-2026-54415 — Azuriom CMS (<1.2.11) Broken Access Control → account takeover