
CVE-2026-64638
Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…
code-analysisexploitationpayload-development+4

Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…

This repository contains exploits for iTOP CVE-2024-52002, 52000, 31998, 31448 that involve CSRF+XSS chaining to get RCE

Post authenticated stored-xss in XenForo versions ≤ 2.2.7

Survey XSS combined with CSRF leads to Admin Account Takeover in Concrete5 8.5.4

Node.js command-and-control server with FUD payload generation, encrypted communication, session management, and modules for data exfiltration and…