
vuln-chain-lab
PoC Docker lab: chaining file upload bypass + stored XSS to create admin accounts. Educational resource for pen testers.

PoC Docker lab: chaining file upload bypass + stored XSS to create admin accounts. Educational resource for pen testers.

Automated XSS scanner and proof-of-concept exploit for CVE-2026-50229 in Apache Tomcat examples. Detects and exploits reflected cross-site scripting…

Proof of Concept for CVE-2025-56762

CVE on FlagForge on versions 2.0.0 to 2.3.0. Upgrade to version 2.3.1 to fix the issue.

code-projects Online Medicine Guide 1.0 is vulnerable to SQL Injection

CVE-2022-23861: Multiple Stored Cross-Site Scripting in YSoft SafeQ

Zimbra Collaboration Suite Username Enumeration

Proof-of-concept for a reflected XSS vulnerability in AIBOX's chat component, demonstrating JWT token theft and account hijacking via crafted…

SQL Injection vulnerability discovered in Grocery Store Management System 1.0

Demonstrates an IDOR vulnerability in TelegAI's chat API allowing unauthorized conversation tampering, leading to phishing and XSS-based account…

Detailed analysis of a Stored XSS vulnerability in TelegAI, including attack vectors, impact, and proof-of-concept for session token theft and…

Student Management System using PHP and MySQL

Analysing parameters with all payloads' bypass methods, aiming at benchmarking security solutions like WAF.

TInjA is a CLI tool for testing web pages for template injection vulnerabilities and supports 44 of the most relevant template engines for eight…

Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573,…

GUI Burp Plugin to ease discovering of security holes in web applications

Small Python library that makes it easy to exploit race conditions in web apps with Requests.

Burp Suite extension to encode an IP address focused to bypass application IP / domain blacklist.