
CVE-2023-41425
Python exploit for Wonder CMS XSS-to-RCE (CVE-2023-41425) that serves malicious scripts locally, enabling remote code execution without external…

Python exploit for Wonder CMS XSS-to-RCE (CVE-2023-41425) that serves malicious scripts locally, enabling remote code execution without external…

Pluck-CMS v4.7.18 RCE exploit

Python exploit script for CVE-2025-2304, a mass assignment privilege escalation in Camaleon CMS. Automates CSRF token parsing and role parameter…

Python exploit for CVE-2018-7600 (Drupalgeddon2) targeting remote code execution in Drupal CMS. Designed for penetration testing and vulnerability…

Proof-of-concept exploit for CVE-2023-50564 targeting Pluck CMS, delivering a reverse shell via malicious module installation.

A Penetration Testing Framework, Information gathering tool & Website Vulnerability Scanner

Proof-of-concept for CVE-2025-2304 — critical (CVSS 9.4) mass-assignment privilege escalation in Camaleon CMS.

Exploit for Wonder CMS XSS to RCE (CVE-2023-41425) with theme upload and reverse shell payloads.

Python exploit script for CVE-2022-41544 in GetSimple CMS. Automates API key leakage, CSRF token extraction, PHP shell upload, and reverse shell…

A simple PoC on the Remote Code Execution (RCE) Vulnerability of CraftCMS designated as CVE-2025-32432 written in Go

WonderCMS Authenticated RCE - CVE-2023-41425

CMS Made Simple 2.2.7 RCE exploit

Remote Code Execution (RCE)

cve-2016-16113

pluck CMS 4.7.18 is affected by a Multiple Stored Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a…

Proof-of-concept exploit for CVE-2025-2304, a privilege escalation vulnerability in Camaleon CMS 2.9.0 via mass assignment on the password change…

Pluck v4.7.18 - Remote Code Execution (RCE)

Pre-auth RCE exploit for Craft CMS in Go. Grabs session/CSRF token, poisons PHP session, triggers deserialization for command execution or reverse…