
CVE-2021-41074
Proof-of-concept CSRF exploit targeting Qloapps HotelCommerce 1.5.1 that allows unauthorized admin email changes via crafted HTML documents.

Proof-of-concept CSRF exploit targeting Qloapps HotelCommerce 1.5.1 that allows unauthorized admin email changes via crafted HTML documents.

mooSocial v3.1.8 is vulnerable to Cross Site Request Forgery (CSRF) which allows attacker to change admin password.

Proof-of-concept for CVE-2023-29983: stored cross-site scripting via unsanitized token parameter in cmaps auditlog, enabling admin cookie theft.

Proof-of-concept exploit for CVE-2023-45992: Stored Cross-Site Scripting and CSRF in Ruckus CloudPath 5.12 enabling unauthenticated full admin…

Proof-of-concept CSRF exploit targeting CVE-2025-50364 in PHPGurukul Maid Hiring Management System v1.0 that adds arbitrary admin categories via a…

CVE-2024-57429: PHPJabbers Cinema Booking System v2.0 is vulnerable to CSRF, allowing attackers to escalate privileges by forging requests on behalf…

Trudesk version 1.2.6 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the tickets `Create/Modify Ticket Tags` on…

Survey XSS combined with CSRF leads to Admin Account Takeover in Concrete5 8.5.4

Proof-of-concept exploit for SQL injection vulnerability in SourceCodester Human Resource Management System 1.0, enabling unauthenticated admin login…

Proof-of-concept for CVE-2025-44108: stored cross-site scripting (XSS) vulnerability in FlatPress CMS 1.3.1 admin panel via gallery captions, with…

Proof-of-concept exploit for CVE-2023-42362: unrestricted file upload leading to stored XSS and admin account takeover in NCR Teller web app 4.4.0.

CloudSchool v3.0.1 is vulnerable to Cross Site Scripting (XSS). A normal user can steal session cookies of the admin users through notification…

MAL-012: Reflected Cross-Site Scripting in Admin Console leading to Remote Code Execution in Payara Server

Proof-of-concept for reflected XSS in Cudy LT400 web interface, demonstrating session cookie theft and admin takeover via crafted requests.

Proof-of-concept for reflected XSS in Cudy LT400 web interface, demonstrating session cookie theft and admin takeover via crafted requests.

Docker lab demonstrating CVE-2026-17532, an unauthenticated reflected XSS in Seraphinite Accelerator that chains to RCE via admin session, with…

Proof-of-concept demonstrating stored XSS in Appsmith Table Widget leading to vertical privilege escalation and full admin takeover via XSS-to-CSRF…

Python script to discover admin panel URLs of websites, aiding in security reconnaissance and penetration testing.