
vuln-chain-lab
PoC Docker lab: chaining file upload bypass + stored XSS to create admin accounts. Educational resource for pen testers.

PoC Docker lab: chaining file upload bypass + stored XSS to create admin accounts. Educational resource for pen testers.

Proof-of-concept for reflected XSS in Cudy LT400 web interface, demonstrating session cookie theft and admin takeover via crafted requests.

Proof of concept demonstrating Cross-Site Request Forgery (CSRF) on Avaya SCOPIA XT Desktop, allowing admin password change without anti-CSRF token.

Proof-of-concept for a stored XSS vulnerability in Bagisto admin panel, demonstrating SVG upload with malicious JavaScript and providing mitigation…

Proof-of-concept for CVE-2025-63420: stored HTML injection in CrushFTP Admin Panel Reports. Includes reproduction steps, CVSS scoring, and payload…

Proof-of-concept exploit for CVE-2024-0566, a post-authenticated time-based SQL injection in Smart Manager 8.27.0 WordPress plugin. Demonstrates…

Proof-of-concept exploit for CVE-2024-0399, a post-authenticated time-based SQL injection in WooCommerce Customers Manager 29.4, targeting…

Cross-Site Request Forgery (CSRF) vulnerability in the password change function, which allows remote attackers to change the admin password without…

CTF challenge replicating CVE-2025-31137 in Remix/React Router Express. Learn to exploit a server-side vulnerability to find the admin flag.

The AdForest theme for WordPress is vulnerable to authentication bypass in all versions including, 6.0.12. This is due to the plugin not properly…

CVE-2026-27174 - An unauthenticated remote code execution via the admin panel's PHP console feature

Exploit for CVE-2022-23131 targeting Zabbix SAML SSO authentication bypass vulnerability. Enables session hijacking and unauthorized admin access.

A stored cross-site scripting (XSS) vulnerability exists in Decap CMS up to version 3.8.3. The issue affects multiple input fields in the **admin…

Proof-of-concept exploit for CVE-2025-57310: CSRF vulnerability in Simple-Faucet-Script v1.07 enabling stored XSS via crafted POST requests to the…

Proof-of-concept exploit for CVE-2018-17081, a Cross-Site Request Forgery vulnerability in e107 CMS 2.1.9, demonstrating unauthorized admin actions…

Proof of Concept and Security Advisory for XSS vulnerability in the FD602GW-DX-R410 fiber router’s admin console (firmware V2.2.14). Includes…

Yetishare SQL Injection in sSortDir_0 parameter - v3.5.2 - v4.5.4. Apart from an admin being able to exploit this, it could also be used in a CSRF…

Proof-of-concept for a stored/reflected XSS vulnerability in Bludit's admin panel showAlert() function, demonstrating unsanitized user input leading…