
CVE-2026-36214
Stored Cross-Site Scripting (XSS) in osTicket via Vulnerable Bootstrap Tooltip Component

Stored Cross-Site Scripting (XSS) in osTicket via Vulnerable Bootstrap Tooltip Component

In LetterPress plugin <= 1.2.1 is vulnerable to Html Injection Vulnerability which can futher leads to Open Redirection Vulnerabilty.

Proof-of-concept for a Self-XSS vulnerability in ChatGPTUtil, demonstrating cookie theft and account hijacking via crafted SVG payloads pasted into…

CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability PoC

Horde IMP (through 6.2.27) vulnerability – obfuscation via HTML encoding – XSS payload

This Proof of Concept (PoC) demonstrates an exploit for CVE-2024-42009, leveraging a cross-site scripting (XSS) vulnerability to extract emails from…

This repository presents a proof-of-concept of CVE-2024-50677

Roundcube mail server exploit for CVE-2024-37383 (Stored XSS)

【Teedy 1.11】Account Takeover via XSS

Read more at Medium

(DOM-based XSS) HTML Injection vulnerability in TOWeb v.12.05 and before allows an attacker to inject HTML/JS code via the _message.html component.

Persistent XSS on Comtrend AR-5387un router

CVE-2020-13965: Cross-Site Scripting via Malicious XML Attachment in Roundcube Webmail

Microsoft-Outlook-Remote-Code-Execution-Vulnerability

Proof-of-concept exploit for CVE-2024-21413, a Microsoft Outlook remote code execution vulnerability. Demonstrates NTLM credential leakage and RCE…

Repository for CVE-2023-4549 vulnerability.

RiteCMS 3.0 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed will…

WBCE 1.6.1 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed will launch…