
W3TotalChache
Testing for CVE-2019-6715 (Arbitrary File Read)/ CVE-2024-12365 (SSRF/Info Disclosure)

Testing for CVE-2019-6715 (Arbitrary File Read)/ CVE-2024-12365 (SSRF/Info Disclosure)

Woocommerce Product Design <= 1.0.0 - Unauthenticated Arbitrary File Deletion

Python proof-of-concept for CVE-2026-3844, an unauthenticated arbitrary file upload in WordPress Breeze Cache plugin, enabling remote code execution.…

Exploit for Grafana directory traversal (CVE-2021-43798) allowing local file read via crafted plugin path. Includes usage instructions and references.

Proof of concept and technical write-up for CVE-2026-31802, a symlink path traversal in npm tar allowing arbitrary file overwrite outside extraction…

WordPress - Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload

CVE-2020-13671 - Drupal RCE via File Upload Vulnerability Analysis and PoC

Mass scanner for Grafana CVE-2021-43798 unauthorized file read, supporting single targets, hostname lists, and IP ranges with PoC verification.

Proof-of-concept exploit for CVE-2026-25964, an authenticated local file disclosure in Tandoor Recipes via path traversal in recipe import, allowing…

Demonstrates CVE-2026-31431 by poisoning the cache for a target file with attacker-controlled payload bytes, illustrating a web cache poisoning…

Snow Monkey Forms <= 12.0.3 - Unauthenticated Arbitrary File Deletion via Path Traversal (CVE-2026-1056)

Proof-of-concept and detailed writeups for CVE-2024-57487 (authenticated RCE via file upload) and CVE-2024-57488 (stored XSS) in Online Car Rental…

Exploit for CVE-2026-1657, an unauthenticated image upload vulnerability via the 'ep_upload_file_media' AJAX endpoint, allowing remote file upload.

Exploit by Chirag Artani for CVE-2024-11613 in WordPress File Upload

Proof-of-concept exploit for Grafana 8.x arbitrary file read vulnerability (CVE-2021-43798), allowing retrieval of sensitive files via crafted URL.

Detailed analysis and proof-of-concept for CVE-2020-13671, a Drupal core remote code execution vulnerability via file upload, including root cause,…

Exploit and proof-of-concept for arbitrary file deletion in Perfmatters WordPress plugin (CVE-2026-4350), with Python exploit and bash POC scripts…

Exploit for CVE-2026-21858, a critical unauthenticated content-type parsing flaw in n8n allowing arbitrary file read, credential theft, and remote…