
CVE-2026-56096
Proof of concept and technical write-up for CVE-2026-56096, a blind Solr query injection in TYPO3 EXT:solr enabling unauthenticated field enumeration…

Proof of concept and technical write-up for CVE-2026-56096, a blind Solr query injection in TYPO3 EXT:solr enabling unauthenticated field enumeration…

CVE-2026-65891 PoC — Joomla Content Editor file rename vulnerability (auth required, fixed in JCE 2.20.2)

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

The Joomla extension PhocaCommander is vulnerable to Path Traversal in the getSource function - CVSS 8.2

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

A Chrome/Firefox browser extension to show alerts for reflected query params, show Wayback archive links for the current path, show hidden elements…

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

Burp Suite extension for JavaScript static analysis: extracts API endpoints, URLs, secrets, and emails with noise filtering for web security testing.

Import To Sitemap is a Burp Suite Extension to import wstalker CSV file or ZAP export file into Burp Sitemap

A chromium extension exploitation toolkit

Burp Suite extension for decoding Web3 JSON-RPC traffic, including smart contract function calls, responses, and ABI resolution with proxy-aware and…

Burp Suite extension to extract and collect GraphQL API endpoints from HTTP request history for security testing and reconnaissance.

Burp extension for wordpress security scanning

rep+ — Burp-style HTTP Repeater for Chrome DevTools with built‑in AI to explain requests and suggest attacks

Burp Suite extension for detecting CVE-2025-55182 (React2Shell) unsafe deserialization vulnerability. Features safe digest check, PoC redirect mode,…

CVE-2025-55182-Exploiter Google Chrome Extension. nextjs vulnerability #nextjscve

A stored cross-site scripting (XSS) vulnerability exists in OpenKM version 7.1.40.

AdmirorFrames Joomla! Extension < 5.0 - Server-Side Request Forgery