
CVE-2019-19609
Python exploit script targeting unauthenticated remote code execution in Strapi CMS 3.0.0-beta.17.4 via CVE-2019-18818 and CVE-2019-19609, delivering…

Python exploit script targeting unauthenticated remote code execution in Strapi CMS 3.0.0-beta.17.4 via CVE-2019-18818 and CVE-2019-19609, delivering…

Python exploit for Craft CMS CVE-2023-41892 Remote Code Execution vulnerability, delivering a PHP reverse shell for authorized penetration testing.

Python-based remote code execution exploit targeting fuel CMS 1.4.1, enabling authenticated attackers to execute arbitrary commands on vulnerable web…

CVE-2023-46818 Python3 Exploit for Backdrop CMS <= 1.22.0 Authenticated Remote Command Execution (RCE)

Bludit 3.9.2 - Remote command execution - CVE-2019-16113

Fuel CMS 1.4.1 - Remote Code Execution - Python 3.x

Fuel CMS 1.4.1 - Remote Code Execution

Python script for CMS Made Simple 2.1.6 - Remote Code Execution.

CVE-2022-40635: Groovy Sandbox Bypass in CrafterCMS

Automated Python exploit for Camaleon CMS arbitrary file upload vulnerability (CVE-2024-46986). Supports reverse shell and command execution payloads…

Exploit for Wonder CMS XSS to RCE (CVE-2023-41425) with theme upload and reverse shell payloads.

Authenticated RCE exploit for WBCE CMS <= 1.6.3 that creates a malicious module zip with a PHP reverse shell and netcat listener.

Python exploit for CVE-2023-45878, an unauthenticated arbitrary file upload in Gibbon CMS, enabling RCE via webshell upload and interactive shell…

Python3 exploit for Fuel CMS 1.4.1 Remote Code Execution (CVE-2018-16763) with Reverse Shell.

CVE-2019-18818/19606 Strapi RCE

Bash exploit automating authenticated remote code execution in Pluck CMS 4.7.18 via malicious ZIP upload, triggering a PHP reverse shell for…

Python exploit script for CVE-2019-16113, an authenticated remote code execution vulnerability in Bludit CMS 3.9.2+, with reverse shell payload…

A simple PoC on the Remote Code Execution (RCE) Vulnerability of CraftCMS designated as CVE-2025-32432 written in Go