
kentico-xperience13-AuthBypass-wt-2025-0011
Python script for checking authentication bypass vulnerability (WT-2025-0011) in Kentico Xperience 13 CMS Staging Service via POST request analysis.

Python script for checking authentication bypass vulnerability (WT-2025-0011) in Kentico Xperience 13 CMS Staging Service via POST request analysis.

Authentication bypass detection script for Kentico Xperience 13 CMS Staging Service using a single POST request to verify vulnerability.

This Python script exploits a critical mass assignment vulnerability in Camaleon CMS version 2.9.0, allowing any registered user to escalate their…

Security research on Craft CMS authentication mechanism

Python script for CMS Made Simple 2.1.6 - Remote Code Execution.

CVE-2022-40635: Groovy Sandbox Bypass in CrafterCMS

Python3-converted exploit and research notes for CMS Made Simple (CVE-2019-9053) — Unauthenticated SQL Injection vulnerability. Includes original…

Security research repository detailing CVE-2024-46209 (authenticated RCE) and CVE-2024-46210 (stored XSS via file upload) in Redaxo CMS v5.17.1, with…

Exploit for CVE-2025-2304 | Camaleon CMS versions < 2.9.1

Python exploit for CVE-2023-40028 enabling authenticated arbitrary file read on Ghost CMS, designed for educational use and HTB machines.

Perl-based remote code execution exploit targeting CVE-2018-7600 in Drupal CMS, enabling payload upload and server compromise.

Unauthenticated remote command execution exploit for SPIP CMS 4.2.8 (CVE-2024-7954) with proxy support and live output retrieval.

Unauthenticated time-based blind SQL injection exploit for CMS Made Simple <= 2.2.9. Extracts admin credentials and optionally cracks password hashes…

Exploit scripts for CVE-2015-1397 in Magento CMS, including a pre-auth exploit to gain admin credentials and a post-auth RCE module for reverse shell…

Remote code execution exploit targeting Bolt CMS versions 3.7.0, leveraging CVEs 2020-4040 and 4041 for penetration testing and vulnerability…

RedDot CMS versions 7.5 Build 7.5.0.48 and below full database enumeration exploit that takes advantage of a remote SQL injection vulnerability in…

Python exploit script for CVE-2019-9053 targeting CMS Simple. Automates vulnerability exploitation and information gathering for penetration testing…

Exploit for CVE-2026-5203 in CMS Made Simple, leveraging path traversal and arbitrary file upload to achieve remote code execution with an…