
CVE-2026-19598
Custom Content Types and Fields plugin for WordPress

Custom Content Types and Fields plugin for WordPress

Proof-of-concept for CVE-2026-22005 showing OAuth 2.0 device code phishing via too-short polling interval, with vulnerable Flask server and exploit…

Python PoC for CVE-2026-3456 demonstrating OAuth2 PKCE race-condition account takeover, with a vulnerable auth server and concurrent code-verifier…

The full repo of all the labs available as part of the benchmark

Exploit tool for CVE-2023-27524, an authentication bypass vulnerability in Apache Superset. Enables unauthorized access to vulnerable instances for…

The AdForest theme for WordPress is vulnerable to authentication bypass in all versions including, 6.0.12. This is due to the plugin not properly…

Java-based wiki platform with detailed access control and JAAS security integration, provided as a vulnerable version for security testing and CVE…

Wordpress REST API | Custom API Generator For Cross Platform And Import Export In WP 1.0.0 - 2.0.3 - Missing Authorization to Unauthenticated…

Repository for CVE-2023-4800 vulnerability.

Proof of Concept for vulnerability CVE-2023-2986 in 'Abandoned Cart Lite for WooCommerce' Plugin in WordPress

Internal network scanner through Gluu IAM blind ssrf

Automated checker-exploit for CVE-2017-5689, scanning Intel AMT panels for authentication bypass and reporting vulnerable IPs.