
CVE-2025-69212-Exploit
Automated exploit for CVE-2025-69212 command injection in OpenSTAManager, featuring admin authentication, malicious ZIP upload, and reverse shell or…

Automated exploit for CVE-2025-69212 command injection in OpenSTAManager, featuring admin authentication, malicious ZIP upload, and reverse shell or…

PoC for CVE-2026-73847 - emlog AI Assistant CSRF to SQL execution to admin takeover (CVSS 6.8)

WordPress Pie Register ≤ 3.7.1.4 - Admin Privilege Escalation (Unauthenticated)

WordPress Plugin MasterStudy LMS 2.7.5 - Unauthenticated Admin Account Creation

Exploit for CVE-2023-41362, a remote code execution vulnerability in MyBB Admin Control Panel, allowing authenticated attackers to execute arbitrary…

Python exploit script for CVE-2024-4040 CrushFTP file read vulnerability with file reading, admin session token retrieval, and vulnerability check…

Proof-of-concept exploit for Apache ShenYu Admin JWT authentication bypass (CVE-2021-37580). Includes a scanning script to detect vulnerable…

CVE-2026-29000 – pac4j-jwt Authentication Bypass (🔥 CVSS 10.0). One-click admin forge via public key JWE wrapping. Leaks configs, users, secrets.…

Dockerized Typesetter CMS environment reproducing CVE-2020-25790 file upload vulnerability, with default admin credentials and a walkthrough for…

Proof-of-concept exploit for an authentication bypass in Hotel and Tourism Reservation System 1.0, allowing unauthenticated admin access via inverted…

Proof-of-concept exploit for CVE-2026-54807 demonstrating unauthenticated privilege escalation via WooCommerce registration form, enabling admin role…

Librebooking Admin RCE PoC CVE-2026-61343

Unauthenticated time-based blind SQL injection exploit for NotificationX WordPress plugin (CVE-2024-1698) that extracts admin username and password…

PoC exploit for Wolf CMS <= 0.8.3.1: authenticates to Admin, writes an arbitrary PHP file to /public via FileManagerController, and executes commands…

Proof-of-concept exploit for CVE-2023-25690 HTTP Request Smuggling in Apache mod_proxy. Includes lab environment with Docker, BurpSuite walkthrough,…

Automated SQL injection exploit for CVE-2024-6043 targeting SourceCodester Best House Rental Management System. Detects vulnerable endpoint and…

POC for TP-Link Archer C9 - Admin Password Reset and RCE (CVE-2017-11519)

Custom Proof-of-Concept on XSS to Unauthorized Admin Account Creation via WordPress Plugin Shield Security < 20.0.6