
MAGNOLIA-8348
MAGNOLIA-8348: FreeMarker Restriction Bypass 3 in Magnolia CMS

MAGNOLIA-8348: FreeMarker Restriction Bypass 3 in Magnolia CMS
Exploit against Grav CMS (versions below 1.7.45) that allows Remote Code Execution for an authenticated user - CVE-2024-28116

Python exploit for Wonder CMS XSS-to-RCE (CVE-2023-41425) that serves malicious scripts locally, enabling remote code execution without external…

Python3 exploit for Fuel CMS 1.4.1 Remote Code Execution (CVE-2018-16763) with Reverse Shell.

CVE-2018-17553 PoC

📦 Pluck CMS 4.7.18 - Authenticated RCE Exploit (CVE-2023-50564). Bypass de restricciones de subida y ejecución remota. 🎯

CMS Made Simple 2.2.7 RCE exploit

Exploit for CVE-2019-16113 targeting Bludit CMS via malicious image upload, enabling remote code execution through crafted PHP payloads.

Proof-of-concept exploit for CVE-2023-50564 targeting Pluck CMS, delivering a reverse shell via malicious module installation.

Proof of Concept script to exploit the authenticated SSTI+RCE in Grav CMS (CVE-2024-28116)

working exploit for the old cve-2021-21425 grav cms 1.7.10 vuln

Proof-of-concept for CVE-2025-2304 — critical (CVSS 9.4) mass-assignment privilege escalation in Camaleon CMS.

Pluck v4.7.18 - Remote Code Execution (RCE)

Proof-of-concept exploit for CVE-2026-70553, enabling unauthenticated RCE in MaxSite CMS via persistent PHP injection into database.php through the…

Bash exploit automating authenticated remote code execution in Pluck CMS 4.7.18 via malicious ZIP upload, triggering a PHP reverse shell for…

This exploit demonstrates a **path traversal vulnerability** in Xibo CMS (CVE-2023-33177) that allows remote code execution through malicious layout…

Exploit to trigger RCE for CVE-2018-16763 on FuelCMS <= 1.4.1 and interactive shell.

Proof-of-concept exploit for CVE-2025-2304, a privilege escalation vulnerability in Camaleon CMS 2.9.0 via mass assignment on the password change…