
CVE-2025-67906
MISP <= 2.5.27 - Stored Cross-Site Scripting via Workflow Engine (doT.js Template Injection).
data-exfiltrationexploitationinformation-gathering+5
2

MISP <= 2.5.27 - Stored Cross-Site Scripting via Workflow Engine (doT.js Template Injection).

Automated exploit tool for CVE-2026-1357, an unauthenticated RCE in WPvivid Backup & Migration. Scans WordPress targets, bypasses WAF/403, uploads a…

CVE-2025-55182 & CVE-2025-66478 proof of concepts

Quickjack is a point-and-click tool for intuitively producing advanced clickjacking and frame slicing attacks.