


cve-2026-48907 scanner

GutenKit <= 2.1.0 - Unauthenticated Arbitrary File Upload

Unauthenticated 0-click RCE exploit for CVE-2024-9932. Exploits an arbitrary file upload vulnerability in the Wux Blog Editor WordPress plugin to…

Authenticated stored XSS priv esc PoC. Affects Genealogy versions prior to 4.4.0


Repository for CVE-2023-43263 vulnerability.

Stored XSS in MicroStrategy Web prior to 10.4.6

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Profile in…

CVE-2016-4999

AI Engine for WordPress: ChatGPT, GPT Content Generator <= 1.0.1 - Authenticated (Contributor+) Arbitrary File Read

Repository for CVE-2023-42426 vulnerability.

StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More <= 1.4.0 - Authenticated (Subscriber+)…

CVE-2026-65891 PoC — Joomla Content Editor file rename vulnerability (auth required, fixed in JCE 2.20.2)

Penpot's remote image import let an authenticated file editor turn a normal media convenience feature into backend-origin SSRF because…

The Joomla extension PhocaCommander is vulnerable to Path Traversal in the getSource function