
CVE-2025-34157
A stored XSS in the project delete flow allows execution of attacker-controlled JavaScript in an administrator’s browser when the admin attempts to…

A stored XSS in the project delete flow allows execution of attacker-controlled JavaScript in an administrator’s browser when the admin attempts to…

Takeover of Oracle WebLogic Server

Proof-of-concept demonstrating unauthenticated cross-origin takeover of Nhost MCP Server, enabling database exfiltration, table drops, and permission…

CVE-2026-8181 - Burst Statistics 3.4.0-3.4.1.1 Unauthenticated Authentication Bypass to Admin Account Takeover | Proof of Concept

Implementation and exploitation of CVE-2023-7028 account takeover vulnerability related to GO-TO CVE weekly articles of the 11th week.

PoC exploit for CVE-2026-10580 - Authentication Bypass in Hippoo Mobile App for WooCommerce <= 1.9.4 leading to Admin Account Takeover

Educational Proof of Concept exploit for CVE-2024-25723, demonstrating unauthorized account takeover in ZenML via API password reset, with version…

A simple, educational proof-of-concept script demonstrating the zero-click account takeover vulnerability in the PrestaShop Checkout module…

Detailed disclosure of CVE-2025-22963, a CSRF vulnerability in Teedy <= v1.11 enabling account takeover via forced user information changes.

CVE-2026-19264 - Critical unauthenticated path traversal to full instance takeover in Postiz (< 2.22.1). Technical writeup: decode-order bypass,…

Detailed disclosure of CVE-2025-63314: static, non-expiring password reset token in Acora CMS 10.7.1 enabling account takeover and privilege…

Curated collection of bug bounty writeups covering OWASP Top 10 vulnerabilities, including XSS, SQLi, SSRF, and RCE, for educational learning and…

CVE-2026-8181: Burst Statistics Auth Bypass → REST API takeover & admin creation. Python 2.7. Educational use only.

Proof-of-concept exploit for CVE-2026-49757 demonstrating OAuth2/OIDC account takeover via email-based user matching in AshAuthentication, with…


Proof-of-concept exploit for CVE-2026-18963, a critical Keycloak reset-credentials bypass enabling unauthenticated account takeover. Includes lab…

Proof-of-concept exploit for CVE-2023-7028, automating GitLab account takeover via password reset email manipulation. Includes temp-mail integration…

CVE-2024–27631 Reference