
CVE-2026-0740
Automated mass exploiter for CVE-2026-0740, an unauthenticated arbitrary file upload in Ninja Forms File Uploads plugin, enabling remote code…

Automated mass exploiter for CVE-2026-0740, an unauthenticated arbitrary file upload in Ninja Forms File Uploads plugin, enabling remote code…

CVE-2020-7693: SockJS 0.3.19 Denial of Service POC

POC for PDF JS' CVE-2024-4367 vuln

Proof-of-Concept script for WordPress plugin Bit File Manager version <= 6.5.7 Authenticated (Subscriber+) Limited JavaScript File Upload…

This is POC for CVE-2024-2667 (InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.22 - Unauthenticated Arbitrary File Upload)

WordPress iSpring Embedder plugin <= 1.0 - CSRF to Arbitrary File Upload vulnerability

Pexels: Free Stock Photos <= 1.2.2 - Authenticated (Contributor+) Arbitrary File Upload

Multi-target PoC runner for CVE-2026-1306 in WordPress midi-Synth plugin: fetches nonce, sends export AJAX request to upload files, and verifies…

Exploit for CVE-2026-27597, a critical RCE in Agentfront Enclave before 2.11.1, allowing sandbox escape and remote code execution.

Proof-of-concept exploit for CVE-2026-6960: unauthenticated arbitrary file upload in BookingPress Pro ≤ 5.6. Automates a 3-step chain to upload a PHP…

Wordpress Plugin AI Engine 2.9.3 - 2.9.4 Proof Of Concept

Remote Code Execution (RCE) Vulnerability in Krayin CRM v2.1.5

WordPress WPMasterToolKit plugin <= 1.13.1 - Arbitrary File Upload vulnerability

User Registration Advanced Fields <= 1.6.20 - Unauthenticated Arbitrary File Upload

CVE-2026-48866 — Gravity Forms <= 2.10.0.1 Arbitrary File Deletion via Path Traversal (CVSS 9.6)

Nginx CVE-2019-20372 PoC, Unauthenticated File Upload Exploit

CVE‑2025‑3515 — Drag and Drop Multiple File Upload for Contact Form 7

File upload vulnerability in machsol machpanel 8 allows attacker gain a webshell.