
CVE-2026-55040-Mass-Exploit
Exploit for CVE-2026-55040 in Microsoft SharePoint, forging JWT tokens via algorithm none, weak HS256 secrets, and RS256 substitution to impersonate…

Exploit for CVE-2026-55040 in Microsoft SharePoint, forging JWT tokens via algorithm none, weak HS256 secrets, and RS256 substitution to impersonate…

CVE-2018-10933 very simple POC

Detects the algorithm of input JWT Token and provide options to generate the new JWT token based on the user selected algorithm.

Automate JWT Exploit (CVE-2018-0114)

automate CVE-2015-9235 exploitation

Strapi Framework, 3.0.0-beta.17.4

Simple python script to check against hypothetical JWT vulnerability.

Keycloak: Unauthorized organization registration via improper invitation token validation

Python proof-of-concept demonstrating an authentication bypass in pac4j JWT by crafting a JWE token with an unsigned inner JWT, allowing privilege…

Rust-based exploit generator for CVE-2026-29000, an authentication bypass in pac4j-jwt via alg:none JWT nested in JWE, automating JWKS retrieval and…

JSON Web Token Hack Toolkit

JWT Key Confusion PoC (CVE-2015-9235) Written for the Hack the Box challenge - Under Construction

python2.7 script for JWT generation

Exploitability PoC for CVE-2026-49352 (9router Hardcoded JWT Secret Authentication Bypass)

Exploit for CVE-2025-10294: authentication bypass via empty HMAC key in ownid_shared_secret, enabling JWT forgery and unauthorized WordPress admin…

RestroPress – Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWT

BeyondCart Connector <= 2.1.0 - Missing Configuration of JWT Secret to Unauthenticated Privilege Escalation

CVE-2026-29000 – pac4j-jwt Authentication Bypass (🔥 CVSS 10.0). One-click admin forge via public key JWE wrapping. Leaks configs, users, secrets.…