
CVE-2025-12539
TNC Toolbox: Web Performance <= 1.4.2 - Unauthenticated Sensitive Information Exposure to Privilege Escalation/cPanel Account Takeover

TNC Toolbox: Web Performance <= 1.4.2 - Unauthenticated Sensitive Information Exposure to Privilege Escalation/cPanel Account Takeover


CVE-2025-14998 Wordpress Plugin - Branda – White Label & Branding, Free Login Page Customizer <= 3.4.24 - Unauthenticated Privilege Escalation via…

WordPress Frontend Login and Registration Blocks Plugin <= 1.0.7 is vulnerable to Privilege Escalation

Account takeover full PoC for CVE-2026-27886 in Strapi CMS

Unauthenticated Account Takeover via Weak Password Reset Validation via 'reset_user_id' Parameter | Unauthenticated Privilege Escalation via Weak…

🧨 CVE-2025-14783: Easy Digital Downloads Account Takeover PoC

User Profile Builder < 3.15.2 - Unauthenticated Arbitrary Password Reset

Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover

Possible Account Takeover | Brute Force Ability

Flynax Bridge <= 2.2.0 - Unauthenticated Privilege Escalation via Account Takeover

CVE-2026-8206: Kirki Customizer Framework - Unauthenticated Account Takeover (CVSS 9.8)

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account…

eventin <= 4.0.34 - privilege escalation via user email change / account takeover for authenticated contributor+

CVE-2026-8181 | Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover

CVE-2025-48932 - Unauthenticated SQL injection exploit for Invision Community ≤ 4.7.20. Fully automated exploitation with database enumeration,…