
CVE-2024-21378
This repository contains an exploit for targeting Microsoft Outlook through Exchange Online, leveraging a vulnerability to execute arbitrary code via…

This repository contains an exploit for targeting Microsoft Outlook through Exchange Online, leveraging a vulnerability to execute arbitrary code via…

Caderno Temático NotebookLM: análise de vulnerabilidades SQL Injection (CVE-2024-42327, CVE-2026-23921) no Zabbix, com engenharia de prompts, cadeia…

PoC didático em Python 3 para a CVE-2019-9053, uma SQL Injection time-based blind no CMS Made Simple <= 2.2.9. Esta versão foi adaptada para uso em…

com_media allowed paths that are not intended for image uploads to RCE

Proof-of-concept exploit for CVE-2026-48909: unauthenticated remote code execution via PHP object injection in JoomShaper SP LMS. Includes detection,…

The Joomanager component through 2.0.0 for Joomla! has an Arbitrary File Download issue, resulting in exposing the Credentials of the DataBase.

CVE-2020-10238: Incorrect Access Control in com_templates PoC

Stored XSS in J2Commerce Guest Checkout via Cookie Filter Bypass

PoC for J2Store CVE-2026-67358–67362 (J2Commerce security advisory Aug 2026)

CVE-2026-48908 — PoC exploit for unauthenticated RCE in SP Page Builder (Joomla) via arbitrary file upload. Multi‑threaded, case‑bypass, shell…

Unauthenticated Arbitrary File/Folder Deletion in Joomla Helix Ultimate (JoomShaper) <= 2.2.6 — CVE-2026-57830

📤 Mass exploitation framework for CVE-2026-56290 — Page Builder CK Joomla unauthenticated file upload to RCE

Directory traversal in com_media to RCE

Graphical exploit for CVE-2025-3102 in WordPress SureTriggers plugin, enabling unauthenticated admin user creation via API. Includes vulnerable site…

CVE-2026-49048 — JoomCCK 6.4.0 Unauthenticated SQL Injection (CVSS 9.8)

Proof of Concept exploit for the Joomla 3.7.0 com_fields SQL injection vulnerability (CVE-2017-8917), demonstrating detection, enumeration, and data…

Automated Python script with GUI for testing login endpoint responses with configurable payload sizes, designed for educational security testing and…

Python script with GUI for automated payload testing against login endpoints, designed for educational exploitation simulation and vulnerability…