
CVE-2019-9053-working-
CMS Made Simple < 2.2.10 - SQL Injection . Actual working version

CMS Made Simple < 2.2.10 - SQL Injection . Actual working version

This script exploits the file upload feature in Pluck CMS v4.7.18 to upload a malicious PHP file, enabling remote access via a reverse shell. Once…

Security Advisory: Camaleon CMS - Authenticated RCE via `select_eval` Custom Field

CVE-2025-8517 proof-of-concept demonstrating session fixation in Vvveb CMS v1.0.6.1, enabling full administrative account takeover via arbitrary…

CMS Made Simple < 2.2.10 - SQL Injection python3

Proof-of-concept for a stored XSS vulnerability in Anchor CMS v0.12.7, demonstrating arbitrary JavaScript execution via the page description field.

This Rust PoC exploits CVE-2024-46987, a Path Traversal bug in Camaleon CMS 2.8.0 < 2.8.2 (work on 2.9.0).

Craft CMS 3.0.25 - Cross-Site Scripting Vulnerability

Ektron Content Management System (CMS) 9.20 SP2, remote re-enabling users (CVE-2018–12596)

CVE-2019-9053 rewritten in python3 to fix broken syntax. Affects CMS made simple <2.2.10

Frog CMS 0.9.5 has an Upload > vulnerability that can create files via > /admin/?/plugin/file_manager/save

Wagtail CMS 6.4.1 Stored XSS

Survey XSS combined with CSRF leads to Admin Account Takeover in Concrete5 8.5.4

File upload to Remote Code Execution on Zenario CMS 9.0.54156

CSZ CMS 1.3.0 is affected by a Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload to the…

A Craft CMS vulnerability that allows Remote Code Execution (RCE).

An access control flaw was identified, potentially leading to unauthorized access to critical webservice endpoints within Joomla! CMS versions 4.0.0…

CVE-2023-40028 is a security vulnerability affecting Ghost CMS versions prior to 5.59.1.