
CVE-2023-27372-POC
Python proof-of-concept for detecting CVE-2023-27372 in SPIP CMS. Scans single or multiple URLs for the vulnerability and outputs results to terminal…

Python proof-of-concept for detecting CVE-2023-27372 in SPIP CMS. Scans single or multiple URLs for the vulnerability and outputs results to terminal…

Pluck-CMS v4.7.18 RCE exploit

CVE-2021-46363: Formula Injection in Magnolia CMS

Python exploit script for CVE-2019-16113, an authenticated remote code execution vulnerability in Bludit CMS 3.9.2+, with reverse shell payload…

pluck CMS 4.7.18 is affected by a Multiple Stored Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a…

SPIP CVE-2023-27372 Unauthenticated RCE Exploit (Web Shell Upload)

WonderCMS v3.2.0 - v3.4.2 XSS to RCE exploit

GDidees CMS 3.9.2 is affected by a Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload to…

Exploit for CVE-2025-10353. Unauthenticated File Upload on Melis Platform Framework that leads to RCE

A simple PoC on the Remote Code Execution (RCE) Vulnerability of CraftCMS designated as CVE-2025-32432 written in Go

Remote Code Execution (RCE)

The first proof of concept of the Contao CMS RCE

WonderCMS Authenticated RCE - CVE-2023-41425

is a PoC Python script that exploits an authenticated Server-Side Template Injection (SSTI) vulnerability in Grav CMS versions <= 1.7.44…

A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the…

Statamic CMS versions <4.33.0 vulnerable to "Remote Code Execution"

CVE-2023-41425 - Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a…

Python PoC for unauthenticated remote code execution in Fuel CMS 1.4.1 via the `filter` parameter, providing an interactive shell for command…