
CVE-2025-56380
Frappe Framework v15.72.4 was discovered to contain a SQL injection vulnerability via the fieldname parameter in the frappe.client.get_value API…

Frappe Framework v15.72.4 was discovered to contain a SQL injection vulnerability via the fieldname parameter in the frappe.client.get_value API…

Automated proof-of-concept exploit for unauthenticated SQL injection in FortiWeb; abuses the Authorization header to write a webshell and execute…

Exploit for CVE-2020-9006 targeting WordPress Popup-Builder plugin via SQL injection and PHP deserialization, with payload generation and Nmap…

Ruby-based MySQL client for penetration testing with SQL shell, database management, file read/write, PHP command/reverse shells, and a Linux MySQL…

Proof-of-concept exploit framework for CVE-2026-57588, a SQL injection in Nessus XML import. Generates malicious .nessus files for database…

Blind SQL injection proof-of-concept exploit for RuoYi v4.7.9, bypassing CVE-2024-42900 filter to dump databases via authenticated boolean-based…

This script automates SQL injection testing using SQLMap with AI-powered decision making.

Exfiltrate blind Remote Code Execution and SQL injection output over DNS via Burp Collaborator.

Python PoC for CVE-2025-25257, a pre-auth SQL injection in FortiWeb leading to remote code execution via webshell deployment. Includes exploit…

Python exploit for CVE-2023-38646 targeting Metabase pre-auth RCE via SQL injection. Assesses vulnerability, extracts setup token, and executes…

Proof-of-concept exploit for SQL injection in BigAnt Office Messenger 5.6.06 enabling remote code execution via stacked queries and webshell upload.

YAML PoC rule for fscan that detects CVE-2024-27956, an automatic SQL injection in WordPress, and can create a user to confirm exploitation.

POC | GeoServer Unauthenticated SQL injection to complete RCE

Sql injection in itsourcecode Online Tour and Travel Management System 1.0.

A proof‑of‑concept command‑line tool in C for detecting the SQL injection vulnerability .

CLI tool for generating SQL injection PoC requests, automating sqlmap attacks, and managing modular exploit scripts with interactive menu and…

SQL injection exploit for Joomla JCK Editor 6.4.4 (CVE-2018-17254) that dumps admin credentials and optionally uploads a PHP RCE shell via stacked…

Multi-threaded Python exploit for CVE-2024-27956, performing SQL injection to achieve remote code execution on vulnerable WordPress instances.