
CVE-2026-64638
Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…
code-analysisexploitationpayload-development+4

Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…

Survey XSS combined with CSRF leads to Admin Account Takeover in Concrete5 8.5.4

Post authenticated stored-xss in XenForo versions ≤ 2.2.7

This repository contains exploits for iTOP CVE-2024-52002, 52000, 31998, 31448 that involve CSRF+XSS chaining to get RCE

Node.js command-and-control server with FUD payload generation, encrypted communication, session management, and modules for data exfiltration and…