
WP2Shell
Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

Scans for CVE-2025-55182, a critical RCE in React Server Components, with safe-check mode, WAF bypass, and multi-target scanning.

Automated exploit tool for CVE-2025-55182 in Next.js React Server Components. Enables remote command execution with built-in WAF bypass, custom…

CVE-2025-55182 & CVE-2025-66478 Detection Tool for Next.js RSC RCE

a critical Remote Code Execution (RCE) vulnerability in React Server Components (RSC). It also includes a realistic "Lab Environment" to safely test…

🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast. Precise.…

Advanced security testing tool for CVE-2025-55182 vulnerability assessment in Next.js applications. Features interactive shell, batch scanning, WAF…

Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!

Security Tool for Reconnaissance and Information Gathering on a website. (python 3.x)

Automated exploit tool for CVE-2026-1357, an unauthenticated RCE in WPvivid Backup & Migration. Scans WordPress targets, bypasses WAF/403, uploads a…

A penetration testing tool for bypassing HTTP 401/403 responses using various header manipulation techniques and path fuzzing.

Go-based scanner and exploitation tool for CVE-2025-55182 (Next.js RCE). Supports batch scanning, command execution, Godzilla memory shell injection,…

Quickjack is a point-and-click tool for intuitively producing advanced clickjacking and frame slicing attacks.

High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

Local file inclusion exploitation tool

Black-box regex fuzzing tool that generates payloads to bypass input validations, discover normalizations, and evade WAFs in web applications.

Mass Hunting & Exploitation PoC for CVE-2025-55182 & CVE-2025-66478