
nextjs-middleware-auth-bypass-lab
Bu laboratuvar ortamını sıfırdan kendim oluşturdum. Next.js uygulaması içerisinde giriş, ana sayfa ve admin sayfalarını hazırladım. Middleware ile…

Bu laboratuvar ortamını sıfırdan kendim oluşturdum. Next.js uygulaması içerisinde giriş, ana sayfa ve admin sayfalarını hazırladım. Middleware ile…

Go-based MITM HTTP/HTTPS proxy with HTTP/2 and HTTP/1.1 interception, local CA/per-host cert generation, CONNECT/WebSocket tunneling, disk caching,…

Advisory and Python PoC for Pluck CMS CSRF: fail-open Referer check plus double-extension upload enables webshell deployment and remote code…

Vuln lab: MainWP Dashboard <= 3.1.2 Unauthenticated Stored XSS

PoC exploit for CVE-2026-17543: SQL injection in PHP ext/pgsql via backslash breakout, with data exfiltration and admin privilege-escalation payloads…

WooCommerce Payments: Unauthorized Admin Access Exploit

Proof-of-concept exploit for CVE-2023-3460 enabling unauthorized admin access in Ultimate Member WordPress plugin versions below 2.6.7. Intended for…

ProxyLogon is the formally generic name for CVE-2021-26855, a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the…

Exploit for CVE-2023-22515 in Atlassian Confluence that creates a new admin user and deploys a web-based shell plugin for command execution on the…

CVE-2024-27198 & CVE-2024-27199 PoC - RCE, Admin Account Creation, Enum Users, Server Information

Moodle (< 3.6.2, < 3.5.4, < 3.4.7, < 3.1.16) XSS PoC for Privilege Escalation (Student to Admin)

Proof-of-concept exploit for CVE-2021-26121: Server-Side Template Injection in CS-Cart <=4.12.x allowing shop admin to achieve remote code execution…

Proof-of-concept exploit for CVE-2022-1421, a CSRF vulnerability in Discy WordPress theme allowing admin settings modification via crafted AJAX…

CVE-2026-8181 - Burst Statistics 3.4.0-3.4.1.1 Unauthenticated Authentication Bypass to Admin Account Takeover | Proof of Concept

Exploit and scanner for CVE-2023-3460, a WordPress Ultimate Member plugin privilege escalation vulnerability allowing unauthenticated admin account…

Python exploit script for CVE-2024-4040 CrushFTP file read vulnerability with file reading, admin session token retrieval, and vulnerability check…

CVE-2026-29000 – pac4j-jwt Authentication Bypass (🔥 CVSS 10.0). One-click admin forge via public key JWE wrapping. Leaks configs, users, secrets.…

Dockerized Typesetter CMS environment reproducing CVE-2020-25790 file upload vulnerability, with default admin credentials and a walkthrough for…