
CVE-2026-23921
Proof-of-concept exploit for CVE-2026-23921, a time-based blind SQL injection in Zabbix API via the sortfield parameter, enabling data extraction…

Proof-of-concept exploit for CVE-2026-23921, a time-based blind SQL injection in Zabbix API via the sortfield parameter, enabling data extraction…

The action responsible for setting the per-warehouse stock alert threshold (`seuil_stock_alerte`) accepts user-controlled input and later…

Proof-of-concept exploit for a time-based blind SQL injection in the LearnPress WordPress plugin, allowing unauthenticated attackers to extract…

This Burpsuite plugin allows for multiple web app testers to share their proxy history with each other in real time. Requests that comes through your…

Detects time-based SQL injection by sending crafted GET requests to multiple URLs and measuring delayed responses; includes cookie support for…

Small Python library that makes it easy to exploit race conditions in web apps with Requests.

CVE-2026-49048 — JoomCCK 6.4.0 Unauthenticated SQL Injection (CVSS 9.8)

Proof-of-concept exploit for CVE-2025-22964, a time-based blind SQL injection vulnerability in DDSN Interactive cm3 Acora CMS 10.1.1, enabling…

WordPress WP Time Capsule Plugin Arbitrary File Upload Vulnerability

Stored XSS proof-of-concept exploit for open-xchange OX App Suite webmail, demonstrating unescaped HTML time tag event attributes leading to…

Unauthenticated SQL Injection (Time-Based Blind)

WordPress security scanner with AI-powered analysis, ethical compliance framework, and professional reporting.

Exploit for Apache 2.4.49

Time-based SQL injection detection template for SMM Panel targeting the service_detail parameter via crafted POST requests to /ajax_data, using…

Burp plugin able to find reflected XSS on page in real-time while browsing on site

SQLi scanner to detect SQL vulns

A python library to automate time-based blind SQL injection

Python-based XSS vulnerability scanner with support for POST/GET requests, parameter injection in cookies/referer/user-agent, and multiple encoding…