
Sitadel
Web Application Security Scanner

Web Application Security Scanner

Scans WordPress Forminator for CVE-2026-15748 unauthenticated RCE. Detects vulnerable sites, crawls forms, extracts nonces, runs safe upload tests.

Proof-of-concept exploit for unauthenticated remote code injection in GitLab's GraphQL API, using crafted queries to modify or delete public projects…

Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator

CVE-2023-22047 is a critical unauthenticated Local File Inclusion (LFI) vulnerability in Oracle PeopleSoft Enterprise PeopleTools. This exploit…

Username Enumeration via Authentication Timing Side-Channel in PaperCut NG

CVE-2026-56292 - AcyMailing for Joomla unauthenticated SQL injection scanner


Passive security checker for CVE-2026-48908 affecting SP Page Builder.


Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

Exploit for pgAdmin4 Remote Code Execution (RCE) vulnerability affecting versions 8.10 to 9.1.

CVE-2026-65891 PoC — Joomla Content Editor file rename vulnerability (auth required, fixed in JCE 2.20.2)

Validates pre-authentication reflected XSS in WordPress, fingerprints vulnerable versions, checks payload reflection and JSONP, and generates…

The Joomla extension PhocaCommander is vulnerable to Path Traversal in the getSource function

CVE-2026-64638: WordPress Pre-auth XSS → RCE (XSS2Shell) PoC

CVE-2025-61638 PoC

CVE-2026-11961 — UserRegistration: WordPress User Registration <= 5.2.2 Privilege Escalation. Misconfigured Membership Roles → Unauthenticated Admin…