
CVE-2023-41425
WonderCMS Authenticated RCE - CVE-2023-41425

WonderCMS Authenticated RCE - CVE-2023-41425

Cross-Site Scripting vulnerability in Advanced REST Client v.17.0.9 exploit

Insecure Direct Object Reference (IDOR vulnerability) in SOGo Webmail Allows a user to send emails on behalf of another user.

A security vulnerability has been identified in Krayin CRM <=2.1.0 that allows a low-privileged user to escalate privileges by tricking an admin into…

WordPress Munk Sites plugin <= 1.0.7 - CSRF to Arbitrary Plugin Installation vulnerability

In LetterPress plugin <= 1.2.1 is vulnerable to Cookie Stealing Vulnerability. An attacker can able to steal the cookies by injecting the JavaScript…

CloudSchool v3.0.1 is vulnerable to Cross Site Scripting (XSS). A normal user can steal session cookies of the admin users through notification…


A PoC exploit for CVE-2022-0165 - Page Builder KingComposer WordPress Plugin - ID Parameter Validation Bypass

CVE-2021-46366: Credential Bruteforce Attack via CSRF + Open Redirect in Magnolia CMS

CVE-2020-12625: Cross-Site Scripting via Malicious HTML Attachment in Roundcube Webmail

CVE-2019-12949

Stored Cross-Site Scripting (XSS) in Xibo Signage's Xibo CMS v4.1.2, due to a lack of proper validation of user input.


HostHeaderInjection-Askey

PoC for CVE-2022-48429 - Youtrack stored XSS