
CVE-2026-12793
Python PoC for CVE-2026-12793 in JetFormBuilder <= 3.6.2: unauthenticated privilege escalation leading to plugin upload and remote code execution,…

Python PoC for CVE-2026-12793 in JetFormBuilder <= 3.6.2: unauthenticated privilege escalation leading to plugin upload and remote code execution,…

simple urls < 115 - Reflected XSS

Mass scanner and exploit for CVE-2026-15989, the unauthenticated privilege escalation in Super Forms <= 6.3.316 that creates administrator accounts…

Microsoft Exchange ProxyLogon PoC (CVE-2021-26855)

Proof-of-concept exploit script for CVE-2024-24919 that scans target URLs via HTTP POST requests, analyzes responses for unauthorized access or data…

HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. <= 2.2.1 - Unauthenticated Arbitrary File Upload

WordPress TI WooCommerce Wishlist Plugin <= 2.9.2 Arbitrary File Upload

CVE-2019-11223 - Arbitrary File Upload in Wordpress Support Candy Plugin Version 2.0 Below

Schema & Structured Data for WP & AMP < 1.60 - Unauthenticated Arbitrary Media Upload [POC & Xploit]

WordPress FEUP Arbitrary File Upload Exploit (CVE-2025-2005)

CVE-2026-74945, Uninitialized heap disclosure via a crafted web font (sec-high)

Mass vulnerability scanner for CVE-2026-49049 – Unauthenticated Remote Code Execution in Joomla Helix3 plugin. Multi‑threaded, detects both executed…

EncryptInterceptor fail-open bypass in Apache Tomcat Tribes clustering leading to unauthenticated RCE via Java deserialization.

Microsoft SharePoint CVE-2026-50522

thinkphp5.0.1自动getshell脚本

Proof-of-concept for unauthenticated CSV formula injection in SureForms, showing crafted form submissions trigger spreadsheet formulas when exported…

Demonstrates XXE via SVG upload with a vulnerable Flask/lxml parser and an exploit script for arbitrary file read, SSRF, and denial-of-service…

Picsmize plugin for WordPress is vulnerable to arbitrary file uploads.