
Project-Project-Chimera-Exploiting-a-Modern-WordPress-XXE-to-Pillage-Secrets-
The objective is to conduct a full-scale security assessment of a WordPress-based web application, culminating in a complete server compromise. The…

The objective is to conduct a full-scale security assessment of a WordPress-based web application, culminating in a complete server compromise. The…


CVE-2025-62215 exploit development using Claude Code Agent Team

Capture the Flag challenge: CVE-2025-29927 in combination with a command injection vulnerability

RH - Real Estate WordPress Theme <= 4.4.0 - Authenticated (Subscriber+) Privilege Escalation

Divi Form Builder <= 5.1.2 — Unauthenticated Privilege Escalation via Role Injection

Hack The Box - Silentium machine writeup | CVE-2025-58434, CVE-2025-59528, CVE-2025-8110

Miraculous Core (kamleshyadav) ≤ 2.0.7 — Unauthenticated Privilege Escalation

Traducción al español de los CVE-2022-1015 y 1016 descubiertos y documentados por David.

MOVEit Transfer 2020 web application Stored Cross-Site Scripting (XSS)

Detailed disclosure of CVE-2024-34831: Stored XSS in GibbonEdu Core v26.0.00 leading to privilege escalation via crafted imageLink parameter and…

Stored Cross-Side Scripting (XSS) leads to privilege escalation in SilverPeas social-networking portal

Step-by-step CTF walkthrough demonstrating CVE-2019-9053 SQL injection exploitation and GTFOBins-based privilege escalation on a CMS Made Simple…

Scripts to verify and execute CVE-2019-14287 as part of Research

Structured HTB walkthrough demonstrating Shellshock (CVE-2014-6271) exploitation via CGI directory fuzzing and privilege escalation through…

Educational analysis of CVE-2026-31431, a Linux kernel local privilege escalation via AF_ALG AEAD in-place operation, including technical root cause,…

Hands-on reproduction of CVE-2024-28000 in LiteSpeed Cache using an isolated WordPress lab. Includes reconnaissance, vulnerable hash recovery,…