
CVE-2026-5524-PoC
Python mass-exploit toolkit for CVE-2026-5524, an unauthenticated file upload RCE in the WordPress Divi Form Builder plugin, with webshell upload and…

Python mass-exploit toolkit for CVE-2026-5524, an unauthenticated file upload RCE in the WordPress Divi Form Builder plugin, with webshell upload and…

Automated vulnerability scanner for Oracle WebLogic Server, detecting historical CVEs including deserialization, SSRF, and arbitrary file upload with…

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

Unauthenticated File Upload → RCE PoC for CVE-2026-57827 (RSFiles! Joomla < 1.17.12). Authorized security research use only.

Extracts all S3 Buckets from CSP report headers and then tests for file upload vulns

POC - WordPress File Upload plugin, in the wfu_file_downloader.php file before version <= 4.24.11

Multiple exploits for Monitorr

CVE-2026-57827 — RSFiles! Joomla Component Unauthenticated File Upload RCE. Split-controller upload bypass. CVSS 9.8 | CWE-434 | com_rsfiles < 1.17.12

WPForms Pro <= 1.10.1.1 - Unauthenticated Arbitrary File Write via Chunked Upload Init/Finalize Ordering

Flowise Windows RCE exploit for CVE-2026-58057. Bypasses environment variable validation via case-sensitive flaw. Uses node_options to inject…

CLI client for bulk DIARIO API consumption: upload PDF/Office documents, query file hashes, and automate malware analysis workflows via command-line…

CVE-2025-52691 Scanner - Detects vulnerable SmarterMail installations (CVSS 10.0 RCE)

Proof-of-concept exploit for CVE-2022-32074 demonstrating stored XSS in osTicket via malicious SVG file upload in the file listing directory.

CVE-2023-40028 PoC Exploit

A tool that identifies writable web directories in Apache Tomcat via HTTP PUT method [CVE-2025-24813]

CVE-2026-0740

( Wordpress Exploit ) Wordpress Multiple themes - Unauthenticated Arbitrary File Upload

Super Forms Unauthenticated File Upload RCE | CVSS 9.8