
CVE-2026-78071
Stored XSS via Location Title in DPCalendar Free

Stored XSS via Location Title in DPCalendar Free

Proof-of-concept for unauthenticated CSV formula injection in SureForms, showing crafted form submissions trigger spreadsheet formulas when exported…

Security Advisory for CVE-2026-51565

CVE-2026-5513 — Bookly ≤ 27.2 Stored XSS via Cookie

CVE-2025-12163: Stored Cross-Site Scripting in Omnipress WordPress Plugin

Tests bypasses for CVE-2026-3854 patch, providing a proof-of-concept to validate security fixes.

Proof-of-concept exploit for CVE-2026-2600, a stored XSS in ElementsKit Elementor Addons <= 3.7.9, allowing authenticated Contributors to inject…

Detection scripts for Pi-hole FTLDNS RCE (CVE-2026-35517) via newline injection, including Python scanner and Nmap NSE script for version-based…

A Stored Cross-Site Scripting (XSS) vulnerability exists in Issabel PBX version 4.0.0-6. This allows an authenticated attacker to inject arbitrary…

Proof-of-concept exploit for CVE-2025-64095 targeting DNN CMS, enabling unauthenticated file upload and overwrite to deface sites or inject XSS…

A public disclourse of CVE-2025-67730 in Frape lms By dharan ragunathan

PoC of CVE-2025-45805

Stored XSS proof-of-concept for SOGo groupware, exploiting the 'Remember Username' cookie to inject JavaScript payloads via the login endpoint.

An authenticated Stored Cross-site Scripting (XSS) vulnerability in laravel-file-manager v3.3.1 and below allows attackers with access to the file…

Proof of concept for CVE-2025-55903, a stored HTML injection in PerfexCRM allowing authenticated users to inject malicious HTML into invoices and…

Proof of concept for stored HTML injection in RISE CRM, demonstrating how authenticated users can inject malicious HTML into invoices and messages,…

Never forget where you inject.

During analysis of the ecodotempo.com.br website, a Stored Cross-Site Scripting (XSS) vulnerability was discovered. This vulnerability allows an…