
CVE-2026-8206
CVE-2026-8206 Kirki Plugin Unauthenticated Account Takeover Exploit

CVE-2026-8206 Kirki Plugin Unauthenticated Account Takeover Exploit
CVE-2026-7459 Simple History Missing Authorization Account Takeover Exploit

Proof-of-concept exploit for CVE-2025-6264 in Velociraptor, demonstrating privilege escalation via missing permission checks to redirect clients to a…

Proof-of-concept exploit for CVE-2026-5076 demonstrating unauthenticated admin account takeover in ARMember Premium via SQL injection and plaintext…

ARMember Premium <= 7.3.1 Full Admin Account Takeover

CVE-2026-11551: Branda Plugin - Unauthenticated Privilege Escalation via Account Takeover

PoC exploit for CVE-2026-10580 - Authentication Bypass in Hippoo Mobile App for WooCommerce <= 1.9.4 leading to Admin Account Takeover

Account takeover full PoC for CVE-2026-27886 in Strapi CMS

Xboard / V2Board Unauth Account Takeover - Magic Link Token Leak (CVE-2026-39912)

Hippoo Mobile App for WooCommerce <= 1.9.4 - Unauthenticated Authentication Bypass to Administrator Account Takeover

PoC exploit for CVE-2026-2991 — authentication bypass in KiviCare WordPress plugin (≤4.1.2) allowing unauthenticated patient account takeover and…

🧨 CVE-2025-14783: Easy Digital Downloads Account Takeover PoC

Exploit for CVE-2022-22845 - Unauthenticated Admin Takeover On QXIP SIPCAPTURE Homer-App up to 1.4.27

PoC of Full Account Takeover on RAD SecFlow-1v

Patch for CVE-2025-54236(a.k.a Session Reaper) which allows customer account takeover and RCE under certain conditions. This patch is actually a…

Full-chain CVE-2025-57819 PoC for FreePBX 15, 16, and 17: unauthenticated SQLi to RCE and root takeover.

Unauthenticated Privilege Escalation via Account Takeover

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account…