
wpscan
WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…

WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.


Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Root-cause analysis, vulnerable Docker lab, and PoC scripts for CVE-2026-85706, an unauthenticated arbitrary file read in GitLab via a Workhorse/Puma…

Demonstrates CVE-2025-55182 RCE exploit in React Server Functions to highlight insecure prototype references in Next.js, with educational simulation…

Python PoC and Docker lab for CVE-2026-61500: recovers Rejetto HFS V8 PRNG state to forge an admin session cookie and achieve RCE via server_code.

Proof-of-concept exploit for CVE-2025-3248, a remote code execution vulnerability in Langflow, demonstrating exploitation of the vulnerable endpoint.

Docker-based lab reproducing CVE-2026-29057 Next.js request smuggling, comparing vulnerable 15.5.12 against patched 15.5.13 with a raw chunked HTTP…

Original CVEs, exploit PoCs, and security advisories with detailed vulnerability chains, privilege escalation, and container escape techniques for…

Security training for the apps you actually ship. Open your browser and start hacking.

Docker-based cybersecurity lab for studying and reproducing CVE-2021-41773 in an isolated environment.

Isolated Docker lab and non-destructive Python scanner reproducing CVE-2026-94545, the Next.js next/og ImageResponse SVG injection, with vulnerable…

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

Verified proof-of-concept exploiting the EthPress <= 2.3.5 unauthenticated authentication bypass, granting a WordPress administrator session via a…

WordPress Core <= 7.1.1 unauthenticated LFI to RCE - validation lab, PoC, nuclei template (GHSA-7hp8-65ch-5whp)

Reproduction lab + URL-list scanner + PoC for CVE-2026-87902 / GHSA-7hp8-65ch-5whp — WordPress get_page_template() unauthenticated LFI to conditional…