
CVE-2026-70376
Advisory and Python PoC for Pluck CMS CSRF: fail-open Referer check plus double-extension upload enables webshell deployment and remote code…

Advisory and Python PoC for Pluck CMS CSRF: fail-open Referer check plus double-extension upload enables webshell deployment and remote code…

Exploit for CVE-2026-17544: PHP bcmath OOB write converted into memory-only RCE, bypassing disable_functions and open_basedir with a runtime…

CVE-2026-53767 + CVE-2026-53768 - Authenticated RCE in Chyrp Lite ≤ 2026.01 via uploads_path blocklist bypass and missing extension validation

CVE-2026-65891 PoC — Joomla Content Editor file rename vulnerability (auth required, fixed in JCE 2.20.2)

A Burp Suite Extension for Application Penetration Testing to map flows and vulnerabilities

The Joomla extension PhocaCommander is vulnerable to Path Traversal in the file upload action - CVSS 6.1

The Joomla extension PhocaCommander is vulnerable to Path Traversal in delete, copy, move actions - CVSS 6.4

The Joomla extension PhocaCommander is vulnerable to Path Traversal in the getSource function - CVSS 8.2

This extension will help you to detect GET/POST based XSS vulnerability in any website easily

Automated HTTP Request Repeating With Burp Suite

A Chrome/Firefox browser extension to show alerts for reflected query params, show Wayback archive links for the current path, show hidden elements…

PoC exploit for CVE-2026-17543: SQL injection in PHP ext/pgsql via backslash breakout, with data exfiltration and admin privilege-escalation payloads…

Reproduces CVE-2026-4040: Flask upload server with TOCTOU race condition and exploit script demonstrating arbitrary remote code execution.

A Burp Suite extension to help pentesters to bypass WAFs or test their effectiveness using a number of techniques

SAML2 Burp Extension

Burp Suite extension for decoding Web3 JSON-RPC traffic, including smart contract function calls, responses, and ABI resolution with proxy-aware and…

Proof of Concept for CVE-2026-65761 - EasyStore Pro Unauthenticated SQL Injection via `filter_sortby`

OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address