
CVE-2025-6440
Exploit for CVE-2025-6440: unauthenticated arbitrary file upload in WooCommerce Designer Pro WordPress plugin, enabling RCE via malicious PHP upload.

Exploit for CVE-2025-6440: unauthenticated arbitrary file upload in WooCommerce Designer Pro WordPress plugin, enabling RCE via malicious PHP upload.

PanaceaSoft [all products] 0day exploit





My Geo Posts Free <= 1.2 - Unauthenticated PHP Object Injection

Dolibarr 11.0.3 - Persistent Cross-Site Scripting

CVE-2020-12640: Local PHP File Inclusion via "Plugin Value" in Roundcube Webmail

CVE-2022-40348: Intern Record System - 'name' and 'email' Cross-site Scripting (Unauthenticated)




Men Salon Management System Using PHP and MySQL



All versions of the Joomla! below 3.4.6 are known to be vulnerable. But exploitation is possible with PHP versions below 5.5.29, 5.6.13 and below 5.5.

Arbitrary file write in /vfm-admin/index.php?section=translations&action=update in Veno File Manager Project 4.4.9 allows an authenticated user with…