
wp2shell
CVE-2026-63030 (RCE) + CVE-2026-60137 (SQLi)

CVE-2026-63030 (RCE) + CVE-2026-60137 (SQLi)

There is a SQL injection vulnerability in the backend of Ruoyi v4.8.3

CVE-2021-43798 MiNi Exploitation Framework

HackTheBox — Facts (Easy/Linux) | CVE-2025-2304 + AWS S3 + SSH Key + Facter PrivEsc


Capture the Flag challenge: CVE-2025-29927 in combination with a command injection vulnerability

A technical case study and exploitation analysis of the Authentication Bypass vulnerability in TP-Link TL-WR840N firmware (CVE-2018-12633).


Laravel Crypto Killer Mass Scanner (CVE-2024-55555)

A Proof on Concept for CVE-2023-6063, a time-based blind SQL injection vulnerability in WP Fastest Cache ≤1.2.2.

CVE-2022-0169 - WordPress Photo Gallery SQLi PoC

This is an automated exploitation script for the Hack The Box machine *Titanic*. It extracts Gitea user hashes via LFI, assists in cracking them, and…

Unauthenticated SQL injection exploit for CVE-2019-9053 in CMS Made Simple <= 2.2.9. Extracts admin creds with time-based SQLi.

This exploit targets an unauthenticated SQL injection vulnerability in CMS Made Simple <= 2.2.9 (CVE-2019-9053). It uses a time-based blind SQL…

The exploit is edited to work with different text encodings and Python 3 and is compatible with CMSMS version 2.2.9 and below.

This repository details a SQL Injection vulnerability in Inventio Lite v4's, including exploitation steps and a Python script to automate the attack.…
