
CVE-2026-67206
PoC exploit for Wolf CMS <= 0.8.3.1: authenticates to Admin, writes an arbitrary PHP file to /public via FileManagerController, and executes commands…

PoC exploit for Wolf CMS <= 0.8.3.1: authenticates to Admin, writes an arbitrary PHP file to /public via FileManagerController, and executes commands…

Unauthenticated RCE exploit for Realtyna WPL < 5.3.0 that uploads a PHP webshell via hardcoded API key and executes arbitrary system commands.

Exploit for CVE-2026-17544: PHP bcmath OOB write converted into memory-only RCE, bypassing disable_functions and open_basedir with a runtime…

Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

Shadow Vault – Add shadow users with SHA-512 hash, auto aging match, multiple write fallbacks.

PHP poc, exploit for CVE-2025-9074

Proof-of-concept for authenticated remote code execution in ClipBucket via PHP code injection in update_launch.php. Includes web shell deployment and…

Full-chain exploit combining PHP filter chain injection with CVE-2024-2961 (CNEXT) for unauthenticated Remote Code Execution on vulnerable osTicket…

Casper@shell:~# is an enhanced, more user-friendly version of p0wny shell with many new features.

Intentionally vulnerable PHP app with Nginx/PHP-FPM setup for reproducing CVE-2019-11043, including Docker and Kubernetes deployment,…

PHP script that establishes a reverse shell from a target server to the attacker's machine, enabling remote command execution and post-exploitation…

Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor

Pentestmonkeys' PHP reverse shell with dynamic host and port passing through GET request parameters

PHP 7 and safe-build Update of the popular C99 variant of PHP Shell.

A PHP backdoor management and generation tool/C2 featuring end to end encrypted payload streaming designed to bypass WAF, IDS, SIEM systems.

Yet Another PHP Shell - The most complete PHP reverse shell

Simple PHP reverse shell script for establishing remote command execution on target systems. Ideal for penetration testing and security assessments.

PHP reverse shell script for establishing a remote TCP connection, enabling command execution on a target web server.