
CVE-2025-2304-exploit
Python exploit script for CVE-2025-2304, a mass assignment privilege escalation in Camaleon CMS. Automates CSRF token parsing and role parameter…

Python exploit script for CVE-2025-2304, a mass assignment privilege escalation in Camaleon CMS. Automates CSRF token parsing and role parameter…

Safely demonstrates CVE-2026-16219 path traversal in Croogo CMS with a loopback-only PoC, technical analysis, remediation guidance, and standalone…

A comprehensive full-lifecycle penetration testing project on Joomla 4.2.5 exploiting CVE-2023-23752 inside a Dockerized lab environment

Analysis and Docker reproduction of CVE-2024-28116 - SSTI with sandbox bypass in Grav CMS

PoC didático em Python 3 para a CVE-2019-9053, uma SQL Injection time-based blind no CMS Made Simple <= 2.2.9. Esta versão foi adaptada para uso em…

Ghost CMS Content API Blind SQL Injection

Step-by-step walkthrough for exploiting Subrion CMS via CVE-2021-2220 on an OffSec lab machine, covering web application exploitation and flag…

Awesome list of step by step techniques to achieve Remote Code Execution on various apps!

Educational Docker lab demonstrating CVE-2026-3395, an unauthenticated RCE in MaxSite CMS via the run_php plugin, with vulnerable and patched…

Exploitation of a Remote Code Execution vulnerability- (CVE-2024-7954)

PoC exploit for CVE-2019-13086 targeting SQL injection and file upload vulnerabilities in CSZ CMS. Includes experimental setup and reproduction code…

A Proof-of-Concept (PoC) exploit for CVE-2018-16763 (Fuel CMS - Preauthenticated Remote Code Execution).

CVE-2026-26980 — Ghost CMS Content API SQL Injection Lab (unauthenticated blind SQLi via slug filter ordering)

Dockerized Typesetter CMS environment reproducing CVE-2020-25790 file upload vulnerability, with default admin credentials and a walkthrough for…

Ghost Content API SQL Injection

CVE-2019-6249 Hucart cms 复现环境

Safe PoC scanner and Docker lab for CVE-2023-27372, an RCE in SPIP CMS before 4.2.1. Verifies vulnerability via password recovery endpoint without…

Proof-of-concept scripts and Docker lab for reproducing CVE-2023-41892, a pre-authenticated remote code execution vulnerability in Craft CMS.…