
recon-skills
Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

halo cms plugin 1-request rce from a url, PoC + exploit chain

A simple PoC on the Remote Code Execution (RCE) Vulnerability of CraftCMS designated as CVE-2025-32432 written in Go

Maintained Python 3 port of the original FUEL CMS CVE-2018-16763 proof-of-concept.

Single-target proof of concept for CVE-2025-32432, a pre-authentication remote code execution in Craft CMS. Performs vulnerability confirmation via…

Exploit, POC for CVE-2025-32432, CraftCMS2Shell

Python exploit script for CVE-2021-21425 targeting Grav CMS admin panel, delivering a reverse shell via HTTP POST request with configurable LHOST and…

Proof-of-concept exploit for CVE-2026-45332, a broken access control in Automad CMS allowing unauthenticated dump of admin bcrypt hashes and TOTP…

PoC for CVE-2020-25042: automated Mara CMS 7.5 authenticated PHP upload to RCE, with login hash handling, shell reuse, custom payload support, and…

Python exploit for Bludit CMS API unrestricted file upload leading to remote code execution, providing command execution and interactive shell for…

PoC exploit for CVE-2018-11736 affecting Pluck CMS versions prior to 4.7.7-dev2 with a File Upload Vulnerability

Proof-of-concept exploit for unauthenticated remote code execution in MaxSite CMS <= 109.1 via MarkItUp editor AJAX endpoints, with detection and…

A Proof of Concept (PoC) exploit for CVE-2025-70886, a persistent denial-of-service vulnerability in Halo CMS (v2.22.4 and earlier) that allows…

cve-2016-16113

Exploitation of a Remote Code Execution vulnerability- (CVE-2024-7954)

This Python exploit targets a critical unauthenticated Remote Code Execution (RCE) vulnerability in the BigUp plugin of SPIP CMS (≤ 4.3.1, 4.2.15,…

Unauthenticated remote command execution exploit for SPIP CMS 4.2.8 (CVE-2024-7954) with proxy support and live output retrieval.

SPIP CVE-2023-27372 Unauthenticated RCE Exploit (Web Shell Upload)