
weaponised-XSS-payloads
XSS payloads designed to turn alert(1) into P1

XSS payloads designed to turn alert(1) into P1

A phased, evasive Path Traversal + LFI scanning & exploitation tool in Python

CVE-2021-2109 && Weblogic Server RCE via JNDI

A simple, educational proof-of-concept script demonstrating the zero-click account takeover vulnerability in the PrestaShop Checkout module…

Proof-of-concept for CVE-2025-2304 — critical (CVSS 9.4) mass-assignment privilege escalation in Camaleon CMS.

CVE-2019-12836

👾 CVE-2026-60206 - Oracle WebLogic SAML Auth Bypass Exploit Framework ⚡Bash & Python versions. Features: --detect safe check, --exploit…

WordPress CMP – Coming Soon & Maintenance plugin <= 4.1.13 - Remote Code Execution (RCE) vulnerability

WordPress ThemeEgg ToolKit plugin <= 1.2.9 - Arbitrary File Upload vulnerability

CVE-2026-48866 — Gravity Forms <= 2.10.0.1 Arbitrary File Deletion via Path Traversal (CVSS 9.6)


CVE-2025-6254 — Doctreat Core <= 1.6.8 — Unauthenticated Privilege Escalation

Takeover of Oracle WebLogic Server

CVE-2025-15495 - Arbitrary File Upload Leading to Remote Code Execution (RCE)

WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover

RestroPress – Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWT

PoC CVE-2026-8732 (WP Maps Pro <= 6.1.0)