
CVE-2019-9053
Python exploit for CVE-2019-9053 targeting a SQL injection vulnerability in CMS Made Simple. Automates time-based blind SQLi to extract admin…

Python exploit for CVE-2019-9053 targeting a SQL injection vulnerability in CMS Made Simple. Automates time-based blind SQLi to extract admin…

CVE-2024-57429: PHPJabbers Cinema Booking System v2.0 is vulnerable to CSRF, allowing attackers to escalate privileges by forging requests on behalf…

simple urls < 115 - Reflected XSS

It is possible to view the MD5 hash of the admin password and other attributes without authentication, even after initial setup and password change.…

WPBF - a multithreaded WP brute forcer

Proof-of-concept for unauthenticated stored XSS in SourceCodester Inventory System, demonstrating admin session hijacking via crafted registration…

Proof-of-concept CSRF exploit targeting Qloapps HotelCommerce 1.5.1 that allows unauthorized admin email changes via crafted HTML documents.

PoC for CVE-2026-73847 - emlog AI Assistant CSRF to SQL execution to admin takeover (CVSS 6.8)

The OSINT project, the main idea of which is to collect all the possible Google dorks search combinations and to find the information about the…

An advanced multithreaded admin panel finder written in python.

CVE-2026-72898 PoC : Metabase Unauthenticated SQL Injection

CVE-2023-39144 disclosure: cleartext password exposure in Element55 Maketime appliance admin pages, enabling privilege escalation via…

Passive Laravel middleware that detects and logs SQL injection, XSS, RCE, bot scanners, and 175+ attack patterns. Features a built-in dashboard,…

Proof-of-concept exploit for CVE-2024-53617: stored XSS in LibrePhotos enabling account takeover via malicious HTML file upload with IDOR bypass.

Detection artifact generator that verifies cPanel/WHM authentication bypass (CVE-2026-41940) and demonstrates RCE via CRLF injection, targeting WHM…

Optiva-Framework 🔎 Web Application Scanner🕵️

Curated collection of Google dork queries for advanced search engine reconnaissance, uncovering exposed databases, configuration files, admin panels,…

PoC exploit for CVE-2026-2991 — authentication bypass in KiviCare WordPress plugin (≤4.1.2) allowing unauthenticated patient account takeover and…