
Multi-Stage-Exploitation-and-Detection-Engineering-Analysis-of-CVE-2023-34362-in-MOVEit-Transfer
This repository contains an academic and technical analysis of CVE-2023-34362, a critical SQL injection vulnerability affecting the MOVEit Transfer…

This repository contains an academic and technical analysis of CVE-2023-34362, a critical SQL injection vulnerability affecting the MOVEit Transfer…

Identified a Stored Cross-Site Scripting (XSS) vulnerability in CKFinder v1.4.3 via malicious SVG file upload leading to script execution upon file…

WP SuperBackup <= 2.3.3 - Missing Authorization to Unauthenticated Back-Up File Download

Proof-of-concept exploit for CVE-2026-3844, an unauthenticated arbitrary file upload leading to remote code execution in Breeze Cache <= 2.4.4.…

Unauthenticated arbitrary file upload exploit for Realtyna WPL/Organic IDX WordPress plugin, chains PHP webshell upload to RCE, with command…

Proof-of-concept exploit for CVE-2026-37068: arbitrary file write in Veno File Manager 4.4.9 via authenticated POST request to /vfm-admin/index.php.

Proof-of-concept for CVE-2026-39292: arbitrary file upload vulnerability in Falco Solutions PHPPageBuilder v0.31.0 enabling remote code execution via…

CVE-2020-5398 - RFD(Reflected File Download) Attack for Spring MVC

https://medium.com/@mansoorr/exploiting-cve-2020-25213-wp-file-manager-wordpress-plugin-6-9-3f79241f0cd8

Apache RewriteRule to mitigate potential DoS attack via Wordpress wp-admin/load-scripts.php file

Advisory: CVE-2026-38360 path traversal (CWE-22) in dash-uploader (Python/PyPI)

Proof-of-concept exploit for CVE-2025-64095 targeting DNN CMS, enabling unauthenticated file upload and overwrite to deface sites or inject XSS…

Import To Sitemap is a Burp Suite Extension to import wstalker CSV file or ZAP export file into Burp Sitemap

Script to detect CVE-2025-20393 for Cisco Secure Email Gateway And Cisco Secure Email and Web Manager

WordPress TI WooCommerce Wishlist Plugin <= 2.9.2 Arbitrary File Upload

Proof-of-concept for CVE-2021-3395: authenticated stored XSS in Pryaniki 6.44.3 via arbitrary file upload, triggering JavaScript on attachment view.

WordPress Online Booking & Scheduling Calendar for WordPress by vcita Plugin <= 4.5.3 is vulnerable to a medium priority Arbitrary File Upload

PHPMyAdmin v4.8.0 and v.4.8.1 LFI exploit