
CVE-2026-10580
PoC exploit for CVE-2026-10580 - Authentication Bypass in Hippoo Mobile App for WooCommerce <= 1.9.4 leading to Admin Account Takeover

PoC exploit for CVE-2026-10580 - Authentication Bypass in Hippoo Mobile App for WooCommerce <= 1.9.4 leading to Admin Account Takeover

CVE-2024-4040 CrushFTP SSTI LFI & Auth Bypass | Full Server Takeover | Wordlist Support

Educational Proof of Concept exploit for CVE-2024-25723, demonstrating unauthorized account takeover in ZenML via API password reset, with version…

Proof of concept for a critical Monnit Cloud account takeover (CVE-2025-50433), exploiting missing token-email validation in password reset and…

A simple, educational proof-of-concept script demonstrating the zero-click account takeover vulnerability in the PrestaShop Checkout module…

Proof-of-concept exploit for CVE-2022-48429, a stored cross-site scripting vulnerability in JetBrains YouTrack dashboards enabling low-privileged…

CVE-2025-8517 proof-of-concept demonstrating session fixation in Vvveb CMS v1.0.6.1, enabling full administrative account takeover via arbitrary…

Proof-of-concept exploit for CVE-2024-53617: stored XSS in LibrePhotos enabling account takeover via malicious HTML file upload with IDOR bypass.

CVE-2026-19264 - Critical unauthenticated path traversal to full instance takeover in Postiz (< 2.22.1). Technical writeup: decode-order bypass,…

CVE-2025-5154: Proof-of-concept for unencrypted local storage of authentication tokens, PII, and KYC data in the PhonePe Android app, enabling…

Detailed disclosure of CVE-2025-63314: static, non-expiring password reset token in Acora CMS 10.7.1 enabling account takeover and privilege…

Automatic SQL injection and database takeover tool

Proof-of-concept exploit for CVE-2023-22515, a critical broken access control vulnerability in Confluence Server and Data Center, enabling…

Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…

Exploit the Redash weak secret key vulnerability (GHSA-g8xr-f424-h2rv) to generate password reset links for any user, enabling account takeover…

CVE-2026-8181: Burst Statistics Auth Bypass → REST API takeover & admin creation. Python 2.7. Educational use only.

Proof-of-concept exploit for CVE-2026-49757 demonstrating OAuth2/OIDC account takeover via email-based user matching in AshAuthentication, with…

Xboard / V2Board Unauth Account Takeover - Magic Link Token Leak (CVE-2026-39912)