
CVE-2026-3395-Lab
Educational Docker lab demonstrating CVE-2026-3395, an unauthenticated RCE in MaxSite CMS via the run_php plugin, with vulnerable and patched…

Educational Docker lab demonstrating CVE-2026-3395, an unauthenticated RCE in MaxSite CMS via the run_php plugin, with vulnerable and patched…

A fuel CMS exploit based on Python for RCE mentioned in CVE-2018-16763.

Python exploit for Bludit CMS API unrestricted file upload leading to remote code execution, providing command execution and interactive shell for…

Proof-of-concept exploit for Ghost CMS remote code execution via prototype pollution in jsonpath and static-eval, with a vulnerable environment setup…

Proof-of-concept for a stored XSS vulnerability in cm3 Acora CMS 10.7.1, demonstrating script injection via user management endpoints.

Demonstrates an improper access control vulnerability in DDSN Interactive cm3 Acora CMS 10.7.1, allowing editor-privileged users to retrieve…

Proof-of-concept exploit for unauthenticated remote code execution in MaxSite CMS <= 109.1 via MarkItUp editor AJAX endpoints, with detection and…

Exploit for CVE-2025-10353. Unauthenticated File Upload on Melis Platform Framework that leads to RCE

SQL Injection in MongoLite Aggregation Optimizer via toJsonExtractRaw()

CVE-2026-26980 — Ghost CMS Content API SQL Injection Lab (unauthenticated blind SQLi via slug filter ordering)

Stored cross-site scripting (XSS) vulnerability in the edit profile feature at Nukegraphic CMS V3.1.2

CVE-2026-41177, a Blind SSRF vulnerability in Squidex CMS (prior to v7.23.0). Includes root cause analysis, reproduction steps, and impact assessment…

Reflected Cross-Site Scripting (XSS) in Xibo CMS v4.1.2 from Xibo Signage, due to a lack of proper validation of user input.

Proof-of-concept for SSRF in Xibo CMS via uploadUrl endpoint, demonstrating authenticated server-side request forgery to internal resources.

(RCE) vulnerability discovered in Ghost CMS (specifically affecting versions 0.7.2 through 6.19.0)

Proof-of-concept demonstrating a combined CORS misconfiguration and CSRF protection bypass in Halo CMS, enabling cross-site request forgery attacks…

Proof-of-concept exploit for an arbitrary file write vulnerability in Halo CMS backup restoration, enabling RCE via plugin JAR replacement or…

Technical analysis of CVE-2026-63072, a heap buffer overflow in OpenSSL CMS key unwrapping, covering root cause, affected versions, detection, and…