
CVE-2026-67206
PoC exploit for Wolf CMS <= 0.8.3.1: authenticates to Admin, writes an arbitrary PHP file to /public via FileManagerController, and executes commands…

PoC exploit for Wolf CMS <= 0.8.3.1: authenticates to Admin, writes an arbitrary PHP file to /public via FileManagerController, and executes commands…

halo cms plugin 1-request rce from a url, PoC + exploit chain

Security Advisory: Camaleon CMS - Authenticated RCE via `select_eval` Custom Field

Exploit, POC for CVE-2025-32432, CraftCMS2Shell

Proof-of-concept exploit for CVE-2026-48909: unauthenticated remote code execution via PHP object injection in JoomShaper SP LMS. Includes detection,…

PoC for CVE-2020-25042: automated Mara CMS 7.5 authenticated PHP upload to RCE, with login hash handling, shell reuse, custom payload support, and…

Working PoC for CVE-2025-32432 - Craft CMS <= 5.6.16 unauthenticated RCE via Yii2 PhpManager gadget + nginx access.log poisoning

Exploit for Craft CMS pre-authentication RCE (CVE-2025-32432) chaining session poisoning with insecure deserialization to execute arbitrary commands…

(RCE) vulnerability discovered in Ghost CMS (specifically affecting versions 0.7.2 through 6.19.0)

Ghost CMS Privilege Escalation PoC

Python exploit for Bludit CMS API unrestricted file upload leading to remote code execution, providing command execution and interactive shell for…

Proof-of-concept exploit for Ghost CMS remote code execution via prototype pollution in jsonpath and static-eval, with a vulnerable environment setup…

Proof of concept exploit for CVE-2019-10068.

PoC exploit for CVE-2018-11736 affecting Pluck CMS versions prior to 4.7.7-dev2 with a File Upload Vulnerability

Authenticated RCE exploit for Pluck CMS <= 4.7.13 via unvalidated file upload. Uploads a PHP webshell and provides an interactive command shell.

Command Execution PoC for OpenSSL Stack buffer overflow CVE-2025-15467

This is the PoC exploit for CVE-2022-41840, running Zenario

A Proof of Concept for CVE-2023-50564 vulnerability in Pluck CMS version 4.7.18