
CVE-2022-23378
Authenticated reflected XSS in TastyIgniter version v3.2.2.

Authenticated reflected XSS in TastyIgniter version v3.2.2.

Zoo Management System 1.0 - Stored Cross-Site-Scripting (XSS)

Proof-of-concept exploit for CVE-2024-53617: stored XSS in LibrePhotos enabling account takeover via malicious HTML file upload with IDOR bypass.

Let's Snatch The Admin Panel Of Any Website In Seconds.

An advanced multithreaded admin panel finder written in python.

The OSINT project, the main idea of which is to collect all the possible Google dorks search combinations and to find the information about the…

A fast and powerfull dashboard (admin) finder

This tool is design to find admin panel of any website by using custom wordlist or default wordlist easily and allow you to find admin panel trough a…

Comprehensive guide for hardening WordPress installations: covers admin user changes, HTTPS enforcement, plugin security, file permissions, and…

Curated collection of Google dork queries for advanced search engine reconnaissance, uncovering exposed databases, configuration files, admin panels,…

An all in one admin panel crawler for pentesters.

Proof-of-concept for CVE-2026-37197: Server-Side Request Forgery (SSRF) in NukeViet CMS v4.5.07 admin remote upload, enabling internal network…

CVE-2020-5148 - Forced Authentication in the SonicWall UTM SSO Agent. The agent probes unvalidated workstations as Domain Admin, so one outbound web…

Python exploit for CVE-2019-9053 targeting a SQL injection vulnerability in CMS Made Simple. Automates time-based blind SQLi to extract admin…

CVE-2026-28767: Missing Authentication on Admin Notifications Endpoint — Gardyn Home Kit (ICSA-26-055-03)

CVE-2026-54477: Admin Panel Missing Security Headers (clickjacking/XSS) - Gardyn (ICSA-26-183-03)

Automated reconnaissance and exploitation framework for misconfigured Supabase instances. Features schema enumeration, Selenium-based key extraction,…

Proof-of-concept exploit for CVE-2019-19550, a remote authentication bypass in Senior Rubiweb 6.2.34.28/37, enabling unauthorized admin access to…