
CVE-2025-32432-PoC
A simple PoC on the Remote Code Execution (RCE) Vulnerability of CraftCMS designated as CVE-2025-32432 written in Go

A simple PoC on the Remote Code Execution (RCE) Vulnerability of CraftCMS designated as CVE-2025-32432 written in Go

Python PoC for unauthenticated remote code execution in Fuel CMS 1.4.1 via the `filter` parameter, providing an interactive shell for command…

Python3 exploit for Fuel CMS 1.4.1 Remote Code Execution (CVE-2018-16763) with Reverse Shell.

Python-based remote code execution exploit targeting fuel CMS 1.4.1, enabling authenticated attackers to execute arbitrary commands on vulnerable web…

Python exploit for CVE-2023-45878, an unauthenticated arbitrary file upload in Gibbon CMS, enabling RCE via webshell upload and interactive shell…

CVE-2023-46818 Python3 Exploit for Backdrop CMS <= 1.22.0 Authenticated Remote Command Execution (RCE)

Authenticated RCE exploit for WBCE CMS <= 1.6.3 that creates a malicious module zip with a PHP reverse shell and netcat listener.

Bash exploit automating authenticated remote code execution in Pluck CMS 4.7.18 via malicious ZIP upload, triggering a PHP reverse shell for…

WonderCMS Authenticated RCE - CVE-2023-41425

This script exploits the file upload feature in Pluck CMS v4.7.18 to upload a malicious PHP file, enabling remote access via a reverse shell. Once…

Automated Python exploit for Camaleon CMS arbitrary file upload vulnerability (CVE-2024-46986). Supports reverse shell and command execution payloads…

Exploit for Wonder CMS XSS to RCE (CVE-2023-41425) with theme upload and reverse shell payloads.

Python script for CMS Made Simple 2.1.6 - Remote Code Execution.

Python exploit for Craft CMS CVE-2023-41892 Remote Code Execution vulnerability, delivering a PHP reverse shell for authorized penetration testing.

CVE-2022-40635: Groovy Sandbox Bypass in CrafterCMS

CVE-2019-18818/19606 Strapi RCE

Fuel CMS 1.4.1 - Remote Code Execution - Python 3.x

Python exploit script targeting unauthenticated remote code execution in Strapi CMS 3.0.0-beta.17.4 via CVE-2019-18818 and CVE-2019-19609, delivering…