
wp2shell-Hestia-Scanner
Read-only WordPress security scanner for HestiaCP servers. Detects wp2shell compromise indicators (CVE-2026-63030 / CVE-2026-60137) across all hosted…

Read-only WordPress security scanner for HestiaCP servers. Detects wp2shell compromise indicators (CVE-2026-63030 / CVE-2026-60137) across all hosted…

WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email…

CVE-2022-40348: Intern Record System - 'name' and 'email' Cross-site Scripting (Unauthenticated)

Proof-of-concept exploit for CVE-2024-2876, a critical SQL injection in Email Subscribers by Icegram Express WordPress plugin, allowing…

Documentation of CVE-2026-31283: an email bombing vulnerability in Totara LMS's forgot password API due to missing rate limiting, allowing…

Proof-of-concept exploit for CVE-2026-37073: unauthenticated SMTP email abuse via incorrect access control in Veno File Manager 4.4.9.

CVE-2025-9728: Reflected XSS in Login Form (Email & Password Fields) Vvveb CMS v1.0.7.2

Insecure Access Control in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote attackers to access and execute…

Documentation of CVE-2025-54321: an email bombing vulnerability in Ascertia SigningHub's reset password function due to missing rate limiting,…

Proof-of-concept CSRF exploit targeting Qloapps HotelCommerce 1.5.1 that allows unauthorized admin email changes via crafted HTML documents.

Proof-of-concept exploit for CVE-2024-4295, an unauthenticated SQL injection in Email Subscribers by Icegram Express <= 5.7.20 via the hash parameter.

Customer Support System 1.0 - SQL Injection Vulnerability in the "email" Parameter During "save_staff" Operation

CVE-2025-25965 is a newly discovered CSRF vulnerability in the Phpgurukul Online Banquet Booking System v1.2, allowing remote attackers to change a…

A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected…

I contacted the monica development team via email on 11/20/2024. I also contacted them via LinkedIn, and other platforms in the weeks that followed.…

Proof-of-concept exploit demonstrating HTML injection in SOGo Web Client before 5.9.1, enabling phishing attacks via malicious forms in email bodies.

Proof-of-concept exploit demonstrating SQL injection in a login system with email verification, targeting CVE-2024-24139 for security testing and…

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing…