
CVE-2024-9707-Poc
he Hunk Companion Plugin for WordPress: Vulnerable to Unauthorized Plugin Installation/Activation (Versions Up to and Including 1.8.4)

he Hunk Companion Plugin for WordPress: Vulnerable to Unauthorized Plugin Installation/Activation (Versions Up to and Including 1.8.4)

A program for testing WAF functionality

Burp extension for wordpress security scanning

PoC for CVE-2025-59528 used to achieve remote code execution on the Silentium machine at HTB

Reproducer for CVE-2026-46453 — Apache Camel camel-elasticsearch-rest-client unprefixed-header injection (operation/query override via inbound HTTP…



Validation target: minimal WordPress core slice reproducing the wp2shell (CVE-2026-63030 + CVE-2026-60137) REST-to-SQLi chain



Research on GraphQL from an AppSec point of view.

A modern vulnerable web app

An intentionally designed broken web application based on REST API.

Damn Vulnerable C# Application (API)