
CVE-2026-73570
Proof-of-concept exploit for CVE-2026-73570, demonstrating SMTP command injection via crafted RCPT TO header to trigger service status changes.

Proof-of-concept exploit for CVE-2026-73570, demonstrating SMTP command injection via crafted RCPT TO header to trigger service status changes.

Proof-of-concept exploit for an actively exploited Zimbra Collaboration Suite vulnerability, designed for authorized penetration testing and…

Configurable Python PoC for CVE-2026-54433, a stored XSS in Roundcube's plain-text email renderer. Generates crafted .eml, sends via SMTP, and…

Proof-of-concept exploit for CVE-2025-68645 targeting Zimbra Mail, intended for security validation and CSIRT testing. Redirects to the maintained…

Proof-of-concept exploit for CVE-2026-11113, demonstrating SMTP header injection in a Flask contact form via unsanitized email input; includes…

Proof-of-concept repository for CSS injection attacks against webmail clients: token exfiltration, UI redressing, keyloggers, and AI prompt injection.

Research tool that tests Outlook for HTML email leakage, allowing SMB hash hijacking and user tracking via crafted email payloads.

Zero-click unauthenticated RCE exploit for FreeScout (CVE-2026-28289) via email attachment filename bypass using Unicode characters, achieving remote…

Proof-of-concept exploit demonstrating CSS injection and cross-site scripting (XSS) vulnerabilities in Roundcube Webmail, enabling email content…

Proof-of-concept exploit for CVE-2024-21413 (MonikerLink) enabling remote code execution and NTLM credential leakage via crafted email links,…

Proof-of-concept exploit for CVE-2024-21413, a Microsoft Outlook remote code execution vulnerability. Demonstrates NTLM credential leakage and RCE…

Insecure Direct Object Reference (IDOR vulnerability) in SOGo Webmail Allows a user to send emails on behalf of another user.

Horde IMP (through 6.2.27) vulnerability – obfuscation via HTML encoding – XSS payload

Proof-of-concept exploit for CVE-2024-42009, a stored XSS in Roundcube Webmail. Demonstrates email exfiltration via crafted HTML message with CSS…

Proof-of-concept exploit for CVE-2024-39929 targeting Exim mail servers. Sends crafted emails to bypass file extension blocking and test…

Python exploit for CVE-2024-21413, a Microsoft Outlook remote code execution vulnerability. Sends a crafted email via SMTP to trigger code execution…

Go-based PoC for CVE-2021-26855 (Exchange Server SSRF) enabling unauthenticated user enumeration, mail reading, and contact extraction via crafted…