
CVE-2025-61246
CVE-2025-61246: SQL Injection vulnerability PoC in Online Shopping System PHP

CVE-2025-61246: SQL Injection vulnerability PoC in Online Shopping System PHP

Blind SQL Injection to RCE in a PHP open source application

A Path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager Project's Tiny File Manager <= 2.4.6…

All versions of the Joomla! below 3.4.6 are known to be vulnerable. But exploitation is possible with PHP versions below 5.5.29, 5.6.13 and below 5.5.

iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and…

PoC for CVE-2026-3891 – Unauthenticated File Upload RCE in Pix for WooCommerce ≤ 1.5.0. Automated nonce retrieval, PHP upload, and command execution.

Arbitrary file write in /vfm-admin/index.php?section=translations&action=update in Veno File Manager Project 4.4.9 allows an authenticated user with…

SQL Injection in computer-laboratory-management-system-using-php-and-mysql - LMS - PHP v1.0

My Geo Posts Free <= 1.2 - Unauthenticated PHP Object Injection

Lis Video Gallery <= 0.2.1 - Unauthenticated PHP Object Injection

CVE-2020-12640: Local PHP File Inclusion via "Plugin Value" in Roundcube Webmail

Exploit for CVE-2025-6440: unauthenticated arbitrary file upload in WooCommerce Designer Pro WordPress plugin, enabling RCE via malicious PHP upload.

PoC exploit for PHPSpreadsheet's phar:// deserialization vulnerability, bypassing prohibitWrappers to achieve remote code execution on vulnerable PHP…

PanaceaSoft [all products] 0day exploit

CVE-2022-40348: Intern Record System - 'name' and 'email' Cross-site Scripting (Unauthenticated)

MDJM Event Management <= 1.7.8.3 - Authenticated (Administrator+) Arbitrary File Upload via 'mdjm_email_upload_file' Parameter

