
CVE-2025-14783-POC
🧨 CVE-2025-14783: Easy Digital Downloads Account Takeover PoC

🧨 CVE-2025-14783: Easy Digital Downloads Account Takeover PoC

CVE-2026-8206: Kirki Customizer Framework - Unauthenticated Account Takeover (CVSS 9.8)

CVE-2025-14998 Wordpress Plugin - Branda – White Label & Branding, Free Login Page Customizer <= 3.4.24 - Unauthenticated Privilege Escalation via…

Python exploit script for CVE-2025-10658: brute-forces 6-digit OTP in WordPress SupportCandy guest login to achieve full account takeover via…

Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover

eventin <= 4.0.34 - privilege escalation via user email change / account takeover for authenticated contributor+

Automated exploit for Rocket.Chat NoSQL injection (CVE-2021-22911) that leaks password reset tokens and performs unauthenticated account takeover.

Flynax Bridge <= 2.2.0 - Unauthenticated Privilege Escalation via Account Takeover

CVE-2025-4322 – Unauthenticated Privilege Escalation via Password Update "Account Takeover" 🔥

Proof-of-concept exploit for CVE-2023-34732 demonstrating authenticated function abuse in Flytxt NEON-dX to brute-force and reset user passwords,…

PoC for the type confusion vulnerability in Mac's CMS that results in authentication bypass and administrator account takeover.

Possible Account Takeover | Brute Force Ability

Advisory detailing a pass-the-hash vulnerability in VeryFitPro app (<=3.3.7) where SHA-1 password hashes are used for authentication, enabling…

WordPress Frontend Login and Registration Blocks Plugin <= 1.0.7 is vulnerable to Privilege Escalation

Simulates a Matter commissioning code brute-force attack (CVE-2026-23005) using Python to demonstrate missing rate limiting and lockout on 8-digit…

Educational Telegram phishing simulation for cybersecurity training and awareness. Demonstrates credential harvesting via fake login pages in…

Python exploit for CVE-2023-7028, abusing GitLab password reset poisoning to take over accounts including administrators via crafted email requests.

User Profile Builder < 3.15.2 - Unauthenticated Arbitrary Password Reset