
RedbloodC2
Node.js command-and-control server with FUD payload generation, encrypted communication, session management, and modules for data exfiltration and…

Node.js command-and-control server with FUD payload generation, encrypted communication, session management, and modules for data exfiltration and…

Post authenticated stored-xss in XenForo versions ≤ 2.2.7

Simulates camera permission phishing attacks for security awareness training, featuring realistic templates, an admin dashboard, and real-time alerts…

Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…

Proof-of-concept exploit for CVE-2025-26153: stored XSS in Chamilo LMS forum threads enabling privilege escalation from regular user to admin via…

Survey XSS combined with CSRF leads to Admin Account Takeover in Concrete5 8.5.4

This repository contains exploits for iTOP CVE-2024-52002, 52000, 31998, 31448 that involve CSRF+XSS chaining to get RCE