
Joomla-CMS-Full-Lifecycle-Pentest
A comprehensive full-lifecycle penetration testing project on Joomla 4.2.5 exploiting CVE-2023-23752 inside a Dockerized lab environment

A comprehensive full-lifecycle penetration testing project on Joomla 4.2.5 exploiting CVE-2023-23752 inside a Dockerized lab environment

Local Docker lab demonstrating CVE-2026-8206 unauthenticated account takeover in Kirki WordPress plugin. Compares vulnerable 6.0.6 vs patched 6.0.7…

This repository provides a high-fidelity technical deconstruction and production-ready exploitation suite for CVE-2019-5736. It demonstrates how a…

PoC, Dockerfile playground and root cause from patch diff analysis.

🐶 A curated list of Web Security materials and resources.

Docker-based lab for reproducing Keycloak CVE-2026-18963, including vulnerable version setup, realm seeding, and source-level workflow analysis with…

Technical Reference to multiple relay techniques

Docker lab reproducing CVE-2026-71362 Magento/Adobe Commerce account takeover via customer-session identity switch, with PoC and official-patch A/B/A…

Pentest Report: Next.js 16.0.6 RCE (CVE-2025-66478)

Educational Telegram phishing simulation for cybersecurity training and awareness. Demonstrates credential harvesting via fake login pages in…

This repo is poc of cve-2026-18963. Please use it on legal products (lab, local,...).

Explot, Lab, Scanner - external and docker container, for SMongobleed-CVE-2025-14847 plus phoenix security uploader

Implementation and exploitation of CVE-2023-7028 account takeover vulnerability related to GO-TO CVE weekly articles of the 11th week.

Reproduces CVE-2019-3010 privilege escalation in Oracle Solaris 11 via XScreenSaver, with Vagrant-based lab environment and detailed walkthrough for…

Exploit for CVE-2023-7028 - GitLab CE/EE

Lab + writeup for CVE-2026-44166: PocketBase OAuth2 account pre-hijacking via unvalidated createData.email

Isolated lab research writeup for VMware vCenter Server CVE-2021-21972, covering unauthenticated arbitrary file upload to RCE, Nmap-based detection,…

Docker Compose setup to demonstrate the nginx-ui missing authentication vulnerability