
CVE-2026-11113-SMTP-Header-Injection-in-Contact-Form
Proof-of-concept exploit for CVE-2026-11113, demonstrating SMTP header injection in a Flask contact form via unsanitized email input; includes…

Proof-of-concept exploit for CVE-2026-11113, demonstrating SMTP header injection in a Flask contact form via unsanitized email input; includes…

Local Docker lab demonstrating CVE-2026-8206 unauthenticated account takeover in Kirki WordPress plugin. Compares vulnerable 6.0.6 vs patched 6.0.7…

Classic stack-based buffer overflow in SLMail 5.1 showing how early mail servers could be compromised through oversized SMTP and POP3 commands.

Insecure attachment handling when using Canary Mail or Blue mail

This repository contains research notes and a high-level proof-of-concept (PoC) for CVE-2024-21413, a vulnerability observed in certain mail clients…

Modular Java mail server supporting IMAP, SMTP, POP3, and JMAP with Docker deployment, distributed architecture, and CLI management for secure…

Docker-based environment to reproduce CVE-2020-7247 (OpenSMTPD) with a Python exploit script for arbitrary command execution and reverse shell via…

Documentation of CVE-2024-50964: critical DMARC policy bypass in DonWeb MX server allowing email spoofing, with low attack complexity and no required…

POC to test CVE-2024-39929 against EXIM mail servers

Exploit script for WordPress Plugin Mail Masta 1.0 - CVE-2016-10956

Roundcube 1.0.0 <= 1.2.2 Remote Code Execution exploit and vulnerable container

Buffer Overflow in Seattle Lab Mail (SLmail) 5.5 - POP3

Send Mail Anonymously with this Script