
CVE-2025-11262-Lab
Docker lab for reproducing CVE-2025-11262, an unauthenticated stored blind XSS in Link Whisper Free WordPress plugin. Includes vulnerable and patched…

Docker lab for reproducing CVE-2025-11262, an unauthenticated stored blind XSS in Link Whisper Free WordPress plugin. Includes vulnerable and patched…

B2B software vendor evaluation skill for Claude Code — domain-expert questions, vendor AI agent conversations, evidence-based scoring

CVE-2026-9086 proof-of-concept for Keycloak client URI validation bypass using mixed-case javascript: and data: XSS payloads, with Docker-based…

Containerized lab environment to simulate and exploit a DOM-based XSS vulnerability (CVE-2021-24891) in the Elementor WordPress plugin for hands-on…

Educational CSRF vulnerability demonstration with a controlled lab environment, including a proof-of-concept exploit and a fixed version with proper…

Proof-of-concept for CVE-2025-69993: Cross-Site Scripting in Leaflet's bindPopup() method. Includes advisory, impact analysis, and a demo Angular…

based on [EQSTLab](https://github.com/EQSTLab)

Docker-based proof-of-concept for CVE-2024-42009, a stored XSS in Roundcube Webmail. Demonstrates exploitation via crafted HTML emails and includes…

Reproduce CVE-2019-1010054 CSRF vulnerability in Dolibarr 7.0.0 with a Vagrant-based lab environment. Includes detailed walkthrough for password…