
CVE-2024-46986
Automated Python exploit for Camaleon CMS arbitrary file upload vulnerability (CVE-2024-46986). Supports reverse shell and command execution payloads…

Automated Python exploit for Camaleon CMS arbitrary file upload vulnerability (CVE-2024-46986). Supports reverse shell and command execution payloads…

halo cms plugin 1-request rce from a url, PoC + exploit chain

PoC exploit for Wolf CMS <= 0.8.3.1: authenticates to Admin, writes an arbitrary PHP file to /public via FileManagerController, and executes commands…

Proof-of-concept exploit for CVE-2026-48909: unauthenticated remote code execution via PHP object injection in JoomShaper SP LMS. Includes detection,…

Public PoC Disclosure for CVE-2020-23839 - GetSimple CMS v3.3.16 suffers from a Reflected XSS on the Admin Login Portal

Stored XSS in a CMS platform leads to remote code execution (CVE-2025-50754)

Authenticated RCE exploit for Grav CMS via plugin upload, demonstrating arbitrary PHP code execution and reverse shell.

Working PoC for CVE-2025-32432 - Craft CMS <= 5.6.16 unauthenticated RCE via Yii2 PhpManager gadget + nginx access.log poisoning

Proof of concept exploit for CVE-2019-10068.

Security Advisory: Camaleon CMS - Authenticated RCE via `select_eval` Custom Field

Command Execution PoC for OpenSSL Stack buffer overflow CVE-2025-15467

Remote OS Command Injection in TastyIgniter v3.0.7 Sendmail Path field

In Dolibarr 17.0.0 with the CMS Website plugin (core) enabled, an authenticated attacker can obtain remote command execution via php code injection…

PoC for CVE-2020-25042: automated Mara CMS 7.5 authenticated PHP upload to RCE, with login hash handling, shell reuse, custom payload support, and…

CVE-2023-41892 - Craft CMS Remote Code Execution (RCE)

Exploit, POC for CVE-2025-32432, CraftCMS2Shell

Exploitation of a Remote Code Execution vulnerability- (CVE-2024-7954)

A critical Remote Code Execution (RCE) vulnerability has been identified in PluXML CMS version 5.8.22. This vulnerability allows authenticated…