
Wildfire
CVE-2026-39154, Stored XSS in CometChat JS SDK

CVE-2026-39154, Stored XSS in CometChat JS SDK
Automating the exploitation of CVE-2026-7299 - Stored XSS via Database Table/Column Names in SQL Autocomplete within Appsmith =>1.99. Initial…

Ghost CMS Privilege Escalation PoC

Proof-of-concept exploit for CVE-2026-33229, an XWiki RCE via Apache Velocity sandbox bypass, with technical details and a working payload.

Chamilo-LMS (v2.0) CVE-2025-26153

SureForms <= 2.2.0 - Unauthenticated Stored Cross-Site Scripting

This repository contains a Proof of Concept (PoC) exploit for the Stored Cross-Site Scripting (XSS) vulnerability in Termix, which can lead to Local…

Repositorio de investigación de seguridad que contiene una Prueba de Concepto (PoC) para la vulnerabilidad CVE-2021-4034 (PwnKit) y utilidades de…

Proof-of-concept exploit for CVE-2024-39840, a remote code execution vulnerability in Factorio 1.1.86. Adapted from a detailed writeup, demonstrating…

Stored XSS in a CMS platform leads to remote code execution (CVE-2025-50754)

This vulnerability displays an XSS flaw in a WordPress popup plugin, allowing attackers to inject malicious JavaScript through a stored XSS

Wing FTP Server provides an administrative Lua scripting console accessible via its web interface. Authenticated administrators are able to execute…

The graph functionality of DeimosC2 v1.1.0-Beta is vulnerable to Stored Cross-Site Scripting (XSS), allowing the theft of session cookie and…

badger-builder is an AI-assisted tool for generating dynamic Brute Ratel C4 profiles

Proof of concept for CVE-2024-54756, a vulnerability I found in GZDoom's ZScript scripting engine.

The script exploits Mailcow vulnerabilities via XSS and RCE, emphasizing the need for robust security measures and responsible usage to enhance web…

PoC for Arbitrary Code Execution in Notable

Cross-Site Scripting Proof of Concepts