
CVE-2026-64638
Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…

Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…

Simulates camera permission phishing attacks for security awareness training, featuring realistic templates, an admin dashboard, and real-time alerts…

This repository contains exploits for iTOP CVE-2024-52002, 52000, 31998, 31448 that involve CSRF+XSS chaining to get RCE

Proof-of-concept exploit for CVE-2025-26153: stored XSS in Chamilo LMS forum threads enabling privilege escalation from regular user to admin via…

Post authenticated stored-xss in XenForo versions ≤ 2.2.7

Survey XSS combined with CSRF leads to Admin Account Takeover in Concrete5 8.5.4

Node.js command-and-control server with FUD payload generation, encrypted communication, session management, and modules for data exfiltration and…