



This repository contains a Spring Boot web application vulnerable to CVE-2021-44228, known as log4shell.

Research on Next.js middleware vulnerability (CVE-2025-29927) allowing authorization bypass and potential exploits.

Docker-based lab environment to simulate and exploit CVE-2019-9978, a remote code execution vulnerability in WordPress Social Warfare plugin versions…

CVE-2023-50164 An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a…

WordPress Plugin HTML Author Bio description XSS

Challenge based on CVE-2021-22204 where users send a malicious file to a web application to gain RCE

Docker-based lab to reproduce CVE-2017-9841, a remote code execution vulnerability in PHPUnit's eval-stdin.php when installed under a web root.

YISF 2024 CTF-Web (Directory Traversal via ".tar" file, CVE-2007-4559), easy

This lab demonstrates the exploitation of CVE-2024-24945, a heap corruption vulnerability affecting NGINX. The objective was to understand how memory…

Educational lab demonstrating CVE-2025-55182: Critical RCE in React Server Components via prototype pollution in the Flight protocol


CVE-2026-63030: WordPress REST batch-endpoint array desync. Mechanism, detection, mitigation, and a safe reproduction lab.