
CVE-2023-41425
Python exploit for Wonder CMS XSS-to-RCE (CVE-2023-41425) that serves malicious scripts locally, enabling remote code execution without external…

Python exploit for Wonder CMS XSS-to-RCE (CVE-2023-41425) that serves malicious scripts locally, enabling remote code execution without external…

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

halo cms plugin 1-request rce from a url, PoC + exploit chain

A simple PoC on the Remote Code Execution (RCE) Vulnerability of CraftCMS designated as CVE-2025-32432 written in Go

Public PoC Disclosure for CVE-2020-23839 - GetSimple CMS v3.3.16 suffers from a Reflected XSS on the Admin Login Portal

Proof-of-concept exploit for unauthenticated remote code execution in MaxSite CMS <= 109.1 via MarkItUp editor AJAX endpoints, with detection and…

cve-2016-16113

pluck CMS 4.7.18 is affected by a Multiple Stored Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a…

A Proof of Concept (PoC) exploit for CVE-2025-70886, a persistent denial-of-service vulnerability in Halo CMS (v2.22.4 and earlier) that allows…

Proof-of-concept exploit for CVE-2026-45332, a broken access control in Automad CMS allowing unauthenticated dump of admin bcrypt hashes and TOTP…

Maintained Python 3 port of the original FUEL CMS CVE-2018-16763 proof-of-concept.

Proof-of-concept exploit for CVE-2021-20837, a remote code execution vulnerability in MovableType CMS. Demonstrates exploitation technique for…

Python exploit for Craft CMS CVE-2023-41892 Remote Code Execution vulnerability, delivering a PHP reverse shell for authorized penetration testing.

PoC for CVE-2020-25042: automated Mara CMS 7.5 authenticated PHP upload to RCE, with login hash handling, shell reuse, custom payload support, and…

Exploit, POC for CVE-2025-32432, CraftCMS2Shell

working exploit for the old cve-2021-21425 grav cms 1.7.10 vuln

Bash exploit automating authenticated remote code execution in Pluck CMS 4.7.18 via malicious ZIP upload, triggering a PHP reverse shell for…

Exploitation of a Remote Code Execution vulnerability- (CVE-2024-7954)