
CVE-2018-8062
Persistent XSS on Comtrend AR-5387un router

Persistent XSS on Comtrend AR-5387un router

Swagger UI (CVE-2018-25031) POC, [HTMLi, XSS].

This Proof of Concept (PoC) demonstrates an exploit for CVE-2024-42009, leveraging a cross-site scripting (XSS) vulnerability to extract emails from…

Xss injection, WonderCMS 3.2.0 -3.4.2

Chamilo-LMS (v2.0) CVE-2025-26153

Secure Web Gateway 10.2.11 - Cross-Site Scripting (XSS)

In LetterPress plugin <= 1.2.1 is vulnerable to Html Injection Vulnerability which can futher leads to Open Redirection Vulnerabilty.

Roundcube mail server exploit for CVE-2024-37383 (Stored XSS)

Proof-of-concept exploit for CVE-2018-25031 (Swagger UI XSS) that exfiltrates authorization codes via crafted configUrl/url parameters.

Microweber version 2.0.4 vulnerable to "Uploading Malicious Files"

Read more at Medium

CMSmadesimple 2.2.18 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed…

ConcreteCMS v.9.2.1 is affected by Arbitrary File Upload vulnerability that allows Cross-Site Scriting (XSS) Stored.

WBCE 1.6.1 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed will launch…

mjml-app v3.0.4 & 3.1.0-beta RCE exploit

Survey XSS combined with CSRF leads to Admin Account Takeover in Concrete5 8.5.4

This repository contains exploits for iTOP CVE-2024-52002, 52000, 31998, 31448 that involve CSRF+XSS chaining to get RCE