
Blind-XSS-Manager
Never forget where you inject.

Never forget where you inject.

OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address

Burp Suite extension to generate Intruder payloads using Radamsa

Professional extension of sqlmap project

Firefox extension for detecting and exploiting CVE-2025-55182 — Prototype Pollution RCE in Next.js React Server Actions

(Wordpress) Ninja Forms File Uploads Extension <= 3.0.22 – Unauthenticated Arbitrary File Upload

Pre-auth arbitrary file upload RCE exploit for iCagenda Joomla extension < 4.0.8 (CVSS 10.0)

CVE-2026-48907 is a critical improper access control vulnerability in the JCE editor extension for Joomla. It allows unauthenticated attackers to…

CVE-2026-48907 – Joomla JCE Unauthenticated Remote Code Execution (RCE)

Shortcode Addons <= 3.2.5 - Authenticated (Admin+) Arbitrary File Upload

The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full…

The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to…

Responsive FileManager v.9.9.5 vulnerable to CVE-2022-46604.

Python exploit for RCE in Wordpress

ZIP File Raider - Burp Extension for ZIP File Payload Testing

SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens

A Burp Suite extension for identifying injection flaws (LFI, RCE, SQLi), authentication/authorization issues, and HTTP 403 access violations. It…

BurpSuite extension that converts HTTP requests into JavaScript XMLHttpRequest code for streamlined XSS proof-of-concept generation and web…