
GZDoom-Arbitrary-Code-Execution-via-ZScript-PoC
Proof of concept for CVE-2024-54756, a vulnerability I found in GZDoom's ZScript scripting engine.

Proof of concept for CVE-2024-54756, a vulnerability I found in GZDoom's ZScript scripting engine.

Wing FTP Server provides an administrative Lua scripting console accessible via its web interface. Authenticated administrators are able to execute…

SureForms <= 2.2.0 - Unauthenticated Stored Cross-Site Scripting

This repository contains a Proof of Concept (PoC) exploit for the Stored Cross-Site Scripting (XSS) vulnerability in Termix, which can lead to Local…

Repositorio de investigación de seguridad que contiene una Prueba de Concepto (PoC) para la vulnerabilidad CVE-2021-4034 (PwnKit) y utilidades de…

Proof-of-concept exploit for CVE-2024-39840, a remote code execution vulnerability in Factorio 1.1.86. Adapted from a detailed writeup, demonstrating…

Cross-Site Scripting Proof of Concepts

CVE-2022-29359 - School Application System Stored Cross-Site Scripting

Exploiting a Reflected Cross-Site Scripting (XSS) attack to create a privileged user through the Webmin's add users feature then getting a reverse…

Exploiting a Reflected Cross-Site Scripting (XSS) attack to get a Remote Command Execution (RCE) through the Webmin's Scheduled Cron Jobs feature

The graph functionality of DeimosC2 v1.1.0-Beta is vulnerable to Stored Cross-Site Scripting (XSS), allowing the theft of session cookie and…

Public PoC Disclosure for CVE-2020-23839 - GetSimple CMS v3.3.16 suffers from a Reflected XSS on the Admin Login Portal

CVE-2026-39154, Stored XSS in CometChat JS SDK

Proof-of-concept exploit for XSS vulnerability in Jamovi <=1.6.18. Demonstrates crafting malicious .omv documents with JavaScript payloads to achieve…

The script exploits Mailcow vulnerabilities via XSS and RCE, emphasizing the need for robust security measures and responsible usage to enhance web…

Automating the exploitation of CVE-2026-7299 - Stored XSS via Database Table/Column Names in SQL Autocomplete within Appsmith =>1.99. Initial…

PoC for Arbitrary Code Execution in Notable

Stored XSS in a CMS platform leads to remote code execution (CVE-2025-50754)