
CVE-2024-7703
Proof-of-concept exploit for CVE-2024-7703, a Stored XSS vulnerability in the ARMember WordPress plugin via malicious SVG file uploads by…

Proof-of-concept exploit for CVE-2024-7703, a Stored XSS vulnerability in the ARMember WordPress plugin via malicious SVG file uploads by…

Fork of gogs/gogs for reachability benchmark testing (CVE-2024-45337)

Exploit script for CVE-2017-9841 targeting PHP unit test remote code execution. Includes a local test environment via Docker for educational security…

PoC for CVE-2025-48384

Exploit script for CVE-2024-4577, an argument injection vulnerability in PHP. Scans single or multiple targets to execute arbitrary PHP code via…

Exploit script for CVE-2023-27372 targeting SPIP CMS, enabling remote code execution for authorized security testing and educational purposes.

CVE-2022-39275 Setup and POC

Proof-of-concept exploit demonstrating remote code execution via a crafted git submodule during clone with --recurse-submodules. Targets…


CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection. CVSS 9.8 | CWE-94 | Gitea < 1.27.1

poc of git rce using cve-2024-32002

Proof-of-concept exploit for CVE-2021-22214, a server-side request forgery in GitLab webhooks, allowing unauthenticated attackers to make internal…

CVE-2026-60004 Pre-Auth RCE Exploit — Gitea <= 1.27.0 diffpatch git hook injection (CVSS 9.8)

A flaw in Gitea Open Source Git Server’s approval‑gate logic allows a pull request that originates from a permanent fork to merge without satisfying…

CVE-2026-25860 POC git

Detailed proof-of-concept and analysis of CVE-2021-28378, a stored XSS vulnerability in Gitea enabling arbitrary code injection, privilege…

Jenkins Git Client RCE CVE-2019-10392_Exp