
CVE-2026-63072
Technical analysis of CVE-2026-63072, a heap buffer overflow in OpenSSL CMS key unwrapping, covering root cause, affected versions, detection, and…

Technical analysis of CVE-2026-63072, a heap buffer overflow in OpenSSL CMS key unwrapping, covering root cause, affected versions, detection, and…

A fuel CMS exploit based on Python for RCE mentioned in CVE-2018-16763.

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

Exploit Title: Unauthenticated SQL Injection on CMS Made Simple <= 2.2.9

渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor…

Analysis and Docker reproduction of CVE-2024-28116 - SSTI with sandbox bypass in Grav CMS

Unauthenticated SQL injection exploit for Ghost CMS Content API (CVE-2026-26980); dumps database tables from SQLite/MySQL with active/passive checks…

Advisory and Python PoC for Pluck CMS CSRF: fail-open Referer check plus double-extension upload enables webshell deployment and remote code…

Persistent XSS in Typemill CMS: the Markdown parser lets javascript: URIs through unfiltered. Writeup + PoC.

Proof-of-concept demonstrating a combined CORS misconfiguration and CSRF protection bypass in Halo CMS, enabling cross-site request forgery attacks…

Maintained Python 3 port of the original FUEL CMS CVE-2018-16763 proof-of-concept.

Technical write-up for CVE-2026-8337, an IDOR in Concrete CMS Survey that lets unauthenticated attackers influence private survey results by…

In-depth IDOR write-up for Concrete CMS, covering the message_detail endpoint, missing authorization root cause, attack scenarios, impact, and fix.

Security write-up for an IDOR in Concrete CMS exposing conversation ratings through missing authorization on the get_rating endpoint, with root…

Security Advisory: Camaleon CMS - Authenticated RCE via `select_eval` Custom Field


PoC for CVE-2026-65694 — Microweber CMS (<=2.0.20) unauthenticated path traversal → arbitrary file read (.env / secrets)

Single-target proof of concept for CVE-2025-32432, a pre-authentication remote code execution in Craft CMS. Performs vulnerability confirmation via…