
CVE-2025-61246
CVE-2025-61246: SQL Injection vulnerability PoC in Online Shopping System PHP

CVE-2025-61246: SQL Injection vulnerability PoC in Online Shopping System PHP

Blind SQL Injection to RCE in a PHP open source application

A Path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager Project's Tiny File Manager <= 2.4.6…

All versions of the Joomla! below 3.4.6 are known to be vulnerable. But exploitation is possible with PHP versions below 5.5.29, 5.6.13 and below 5.5.

PoC for CVE-2026-3891 – Unauthenticated File Upload RCE in Pix for WooCommerce ≤ 1.5.0. Automated nonce retrieval, PHP upload, and command execution.

Arbitrary file write in /vfm-admin/index.php?section=translations&action=update in Veno File Manager Project 4.4.9 allows an authenticated user with…

SQL Injection in computer-laboratory-management-system-using-php-and-mysql - LMS - PHP v1.0

My Geo Posts Free <= 1.2 - Unauthenticated PHP Object Injection

Men Salon Management System Using PHP and MySQL

Lis Video Gallery <= 0.2.1 - Unauthenticated PHP Object Injection

CVE-2020-12640: Local PHP File Inclusion via "Plugin Value" in Roundcube Webmail

Exploit for CVE-2025-6440: unauthenticated arbitrary file upload in WooCommerce Designer Pro WordPress plugin, enabling RCE via malicious PHP upload.

PanaceaSoft [all products] 0day exploit

CVE-2022-40348: Intern Record System - 'name' and 'email' Cross-site Scripting (Unauthenticated)

MDJM Event Management <= 1.7.8.3 - Authenticated (Administrator+) Arbitrary File Upload via 'mdjm_email_upload_file' Parameter


