
CVE-2023-25157-GeoServer-SQLi-Lab
Docker-based vulnerable lab and detailed PoC report for CVE-2023-25157/25158 SQL injection in GeoServer & GeoTools, with 4 verified attack vectors…

Docker-based vulnerable lab and detailed PoC report for CVE-2023-25157/25158 SQL injection in GeoServer & GeoTools, with 4 verified attack vectors…

Educational Python 3 proof-of-concept for CVE-2019-9053, a time-based blind SQL injection in CMS Made Simple <= 2.2.9. Adapted for CTF/lab use with…

Proof-of-concept exploit for CVE-2025-61246, a critical time-based blind SQL injection in Online Shopping System PHP. Includes automated exploitation…

Dual-mode SQL injection proof-of-concept for CVE-2025-13673 in Tutor LMS, with an automated Docker lab for unauthenticated blind and authenticated…

CVE-2022-23305 Log4J JDBCAppender SQl injection POC

Time-based SQL injection PoC for CVE-2024-51482 in ZoneMinder, with reproducible Docker lab and automated data extraction.

Blind noSQL injection case study lab based on CVE-2018-3783

Proof-of-concept exploit for CVE-2026-14669, a PostgreSQL to_char() timezone abbreviation heap buffer overflow enabling RCE through information leak…

CTF lab exploiting CVE-2024-53900: a MongoDB NoSQL injection and RCE vulnerability in Mongoose via the $where operator. Practice web exploitation to…

A collection of web pages vulnerable to SQL injection flaws

Proof-of-concept environment for CVE-2020-7471, demonstrating SQL injection via Django's StringAgg delimiter, with setup instructions for vulnerable…

Blind SQL injection exploit writeup for Exim 4.98 with SQLite DBM, including PoC, Docker lab, and remote testing script for CVE-2025-26794.

Proof-of-concept for CVE-2026-65761: unauthenticated SQL injection via filter_sortby in EasyStore Joomla, with Docker lab for testing and patching.

Security research project — SQL Injection vulnerability exploitation and mitigation

CVE-2026-52887 — NocoBase SQL injection -> PostgreSQL-superuser RCE (myInAppChannels:list filter, CVSS 10.0). Author PoC + source analysis + docker…

Proof-of-concept emulation and analysis of CVE-2025-1094, a critical PostgreSQL SQL injection vulnerability. Includes Docker-based lab setup, exploit…

Proof-of-concept exploit for CVE-2026-40083, a SQL injection in Cacti managers.php allowing authenticated users to extract MySQL databases, user…

Local practice app demonstrating CVE-2023-25813 SQL injection in Sequelize ORM with Express and MySQL. Includes vulnerable login route and…