
Ghost-5.58-Arbitrary-File-Read-CVE-2023-40028
CVE-2023-40028 affects Ghost, an open source content management system, where versions prior to 5.59.1 allow authenticated users to upload files that…

CVE-2023-40028 affects Ghost, an open source content management system, where versions prior to 5.59.1 allow authenticated users to upload files that…

CVE-2018-19422 Authenticated Remote Code Execution

Remote OS Command Injection in TastyIgniter v3.0.7 Sendmail Path field

Ghost Content API SQL Injection

CVE-2023-50564 - An arbitrary file upload vulnerability in the component /inc/modules_install.php of Pluck-CMS v4.7.18 allows attackers to execute…


BlackCat-CMS-Bundle-v1.2 Cross Site Scripting(XSS) Assigned CVE Number: CVE-2017-9609

HackTheBox — Facts (Easy/Linux) | CVE-2025-2304 + AWS S3 + SSH Key + Facter PrivEsc

A comprehensive full-lifecycle penetration testing project on Joomla 4.2.5 exploiting CVE-2023-23752 inside a Dockerized lab environment

A writeup investigating the full extent of CVE-2019-25137

Exploitation of a Remote Code Execution vulnerability- (CVE-2024-7954)

PoC for CVE-2025-65271 | Found by me

CVE-2022-37210 POC

I couldn’t find a PoC for CVE-2023-30253, so I developed an effective one

Hotel Druid 3.0.4 Stored Cross Site Scripting Vulnerability

Manual poc for CVE-2025-2304

FuelCMS 1.4.1 Command Injection/Remote Code Execution.

CVE-2025-15495 - Arbitrary File Upload Leading to Remote Code Execution (RCE)