

CVE-2023-5561-PoC

Cross Site Scripting vulnerability in mooSocial mooSocial Software v.3.1.6 allows a remote attacker to execute arbitrary code via a crafted script to…

RiteCMS 3.0 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed will…

CMSmadesimple 2.2.18 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed…

WBCE 1.6.1 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed will launch…

HTML/CSS/JS templates for Browser-In-The-Browser phishing attacks, embedding fake login windows with customizable titles, domains, and phishing links…

Microsoft-Outlook-Remote-Code-Execution-Vulnerability

The Outlook HTML Leak Test Project

CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability PoC

Post authenticated stored-xss in XenForo versions ≤ 2.2.7


【Teedy 1.11】Account Takeover via XSS

All-in-One WP Migration < 7.63 - Unauthenticated Reflected XSS + CSRF

A simple POC (CVE-2018-25031

Public writeup, PoC, and emulation materials for CVE-2026-8508 affecting Zyxel captive-portal social login.

Configurable Python PoC for CVE-2026-54433, a stored XSS in Roundcube's plain-text email renderer. Generates crafted .eml, sends via SMTP, and…

Template Injection in Email Templates leads to code execution on Jira Service Management Server