
waymore
Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal, GhostArchive & Intelligence X!

Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal, GhostArchive & Intelligence X!

The Joomla extension PhocaCommander is vulnerable to Path Traversal in the file upload action - CVSS 6.1

Exploit for CVE-2026-3300, an unauthenticated stored XSS leading to RCE in Everest Forms Pro WordPress plugin, with a Python script to generate a…

CVE-2026-23499 - Saleor vulnerable to stored XSS via Unrestricted File Upload

PoC Docker lab: chaining file upload bypass + stored XSS to create admin accounts. Educational resource for pen testers.

Order Attachments for WooCommerce 2.0 - 2.4.1 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary File Upload

Easy peasy file uploads

Educational CVE PoC for a TOCTOU file-permission race in Flask; uses symlink replacement during the check-open window to disclose sensitive files.

YARPP <= 5.30.10 - Missing Authorization

Searching for virtual hosts among non-resolvable domains

Detection scripts for CVE-2023-50164 in Apache Struts2, providing PowerShell and Bash tools to scan for vulnerable versions across file systems and…

Python exploit script for CVE-2018-1306 in Apache Pluto 3.0.0, enabling malicious file upload via HTTP method tampering to achieve remote code…

Proof-of-concept exploit for CVE-2026-40487, demonstrating arbitrary file upload via MIME spoofing leading to stored XSS and account takeover in…

Exploit for WordPress File Upload Plugin - All versions up to 4.24.11 are vulnerable.

A PoC for the CVE-2022-44268 - ImageMagick arbitrary file read

Automated blind-xss search for Burp Suite

Proof-of-concept exploit for CVE-2022-39253 demonstrating Docker container escape via malicious Git repository build, enabling host file system read…

BurpSuite插件,用于自动化执行blind-xss盲搜索。它能够执行主动和被动检查。