
WP2Shell
Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

Burp extension to evade TLS fingerprinting. Bypass WAF, spoof any browser.

Burp Plugin to Bypass WAFs through the insertion of Junk Data

This script automates SQL injection testing using SQLMap with AI-powered decision making.

A next-generation HTTP stealth proxy which perfectly cloaks requests as the Chrome browser across all layers of the stack.

CF-Hero is a reconnaissance tool that uses multiple data sources to discover the origin IP addresses of Cloudflare-protected web applications

A cheat sheet that contains advanced queries for SQL Injection of all types.

woodpecker-plugins

A Burp Suite extension to help pentesters to bypass WAFs or test their effectiveness using a number of techniques


CVE-2026-61511 – vBulletin Pre-Auth RCE (CVSS 9.8). Vuln 5.x/6.x (unpatched). Multi-exploit via Endpoint Pool, AJAX, PHPFuck WAF bypass. Full…

Next.js RSC RCE Exploit Tool (CVE-2025-55182)


Like curl, but it gets past Anubis and Cloudflare bot-walls.

Flex QR Code Generator <= 1.2.5 - Unauthenticated Arbitrary File Upload

StoreKeeper for WooCommerce <= 14.4.4 - Unauthenticated Arbitrary File Upload