
CVE-2026-7401-XSS
Proof-of-concept for stored XSS in SourceCodester CET Automated Grading System 1.0, demonstrating unauthenticated payload injection via student…

Proof-of-concept for stored XSS in SourceCodester CET Automated Grading System 1.0, demonstrating unauthenticated payload injection via student…

Proof-of-concept for a stored XSS vulnerability in Hotel and Tourism Reservation System 1.0, demonstrating unauthenticated injection and admin…

CVE-2026-23550 - Modular DS WordPress Plugin **Unauthenticated Admin Access**

Scans and exploits CVE-2026-3228, a stored XSS in NextScripts WordPress plugin, with pre-auth detection, authenticated checks, and payload injection…

Proof-of-concept for CVE-2026-7089, a stored XSS in Home Service System PHP 1.0 allowing unauthenticated admin session hijacking via booking form.

Optiva-Framework 🔎 Web Application Scanner🕵️

CVE-2026-72898 PoC : Metabase Unauthenticated SQL Injection

simple urls < 115 - Reflected XSS

Multiple Reflected XSS in TastyIgniter v3.0.7 Restaurtant CMS

Post authenticated stored-xss in XenForo versions ≤ 2.2.7

Modern Events Calendar Lite <= 7.33.0 — Unauthenticated SQL Injection

This is a recurrence of cve-2019-9787 on Wordpress and a hash-based defense.

Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM (HTML Injection)

CVE-2024-46879 - Tiki CMS Reflected Cross-Site Scripting (XSS) Vulnerability

CVE-2025-10377

XSS in Simple Cashiering System

All details about CVE-2022-43097

Wordpress Video Gallery - YouTube Gallery and Vimeo Gallery Plugin SQL Injection