
XSS2Shell
Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

Python exploit for CVE-2017-7921 in Hikvision IP cameras, performing unauthenticated user enumeration, snapshot capture, and configuration file…

Username Enumeration via Authentication Timing Side-Channel in PaperCut NG

CVE-2023-22047 is a critical unauthenticated Local File Inclusion (LFI) vulnerability in Oracle PeopleSoft Enterprise PeopleTools. This exploit…

This Repositories contains list of One Liners with Descriptions and Installation requirements

CVE-2026-56292 - AcyMailing for Joomla unauthenticated SQL injection scanner

Proof-of-concept exploit for unauthenticated remote code injection in GitLab's GraphQL API, using crafted queries to modify or delete public projects…

WordpressPingbackPortScanner

(Deprecated) HQLmap, Automatic tool to exploit HQL injections

Repository contains description for CVE-2023-31445


Exploit for CVE-2022-1609 WordPress Weblizar Backdoor.

a standalone C-based SQL Injection exploit targeting the CVE‑2025‑6907 vulnerability in the CODE_PROJECT service.

Proof‑of‑Concept exploits the Full Path Disclosure bug in the “Birth Chart Compatibility” WordPress plugin (<=v2.0)

C PoC language for emulating path traversal vulnerability (CVE-2025-5964) in M-Files25.6.14925.0

Exploit blind SQL Injection in (Online Learning Management System)

💣 Wordpress WooCommerce users dump exploit.