
CVE-2026-55579
CVE-2026-55579 – Unauthenticated RCE in Pheditor via hardcoded default password "admin". Full Python exploit with file upload & terminal execution.…

CVE-2026-55579 – Unauthenticated RCE in Pheditor via hardcoded default password "admin". Full Python exploit with file upload & terminal execution.…

Exploit for CVE-2026-15013: unauthenticated SAML auth bypass via algorithm confusion. Forges SAML responses to gain admin access and deploy…

Proofpoint Email Gateway: Low level authenticated user to admin RCE

Poc for Unauthenticated Admin Session Hijack - Pie Register Plugin (≤ 3.7.1.4)

VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

Proof-of-concept exploit for CVE-2025-48932, a SQL injection in Invision Community <= 4.7.20. Extracts admin credentials and resets passwords via…

Shell-based exploit for CVE-2025-31161, an authentication bypass in CrushFTP that allows unauthenticated attackers to forge CrushAuth tokens and…

Proof-of-concept for CVE-2025-65094: privilege escalation via IDOR in WBCE CMS. Demonstrates group ID manipulation to gain admin access, with…

Proof-of-concept exploit for stored XSS (CWE-79) in a PHP coaching management system, demonstrating session hijacking and privilege escalation from…

Exploit for CVE-2025-10294: authentication bypass via empty HMAC key in ownid_shared_secret, enabling JWT forgery and unauthorized WordPress admin…

maccms admin+ xss attacks

PoC for CVE-2025-14340: Admin account takeover in Payara Server

Proof-of-concept exploit for an authentication bypass in HP 1920 Series switches, allowing unauthenticated admin password change via crafted HTTP…

Exploit for CVE-2021-26855 (ProxyLogon) targeting Microsoft Exchange. Creates a new admin user and establishes a reverse shell for post-exploitation…

ARMember < 3.4.8 - Unauthenticated Admin Account Takeover

The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated…

This repository includes two PoC scripts for CVE-2025-57819 in FreePBX: one to create a new admin user (poc_admin.py), and another to extract…

Proof-of-concept exploit for a mass assignment privilege escalation vulnerability in Camaleon CMS < 2.9.1. Authenticated low-privilege users can…