
CVE-2026-66492
The Joomla extension PhocaCommander is vulnerable to Path Traversal in the file upload action - CVSS 6.1

The Joomla extension PhocaCommander is vulnerable to Path Traversal in the file upload action - CVSS 6.1

The Joomla extension PhocaCommander is vulnerable to Path Traversal in the getSource function - CVSS 8.2

Patch for CVE-2025-54236(a.k.a Session Reaper) which allows customer account takeover and RCE under certain conditions. This patch is actually a…

CVE-2026-49049 - Unauthenticated File Deletion, Arbitrary Write & XSS Injection for Helix3 Joomla Extension

Zap Extension for collaboration in Faraday

CVE-2026-53767 + CVE-2026-53768 - Authenticated RCE in Chyrp Lite ≤ 2026.01 via uploads_path blocklist bypass and missing extension validation

AdmirorFrames Joomla! Extension < 5.0 - Server-Side Request Forgery

AdmirorFrames Joomla! Extension < 5.0 - HTML Injection

Never forget where you inject.

Proof of concept and technical write-up for CVE-2026-56096, a blind Solr query injection in TYPO3 EXT:solr enabling unauthenticated field enumeration…

my poc for CVE-2026-53787

CVE-2026-65891 PoC — Joomla Content Editor file rename vulnerability (auth required, fixed in JCE 2.20.2)

Advisory and Python PoC for Pluck CMS CSRF: fail-open Referer check plus double-extension upload enables webshell deployment and remote code…


Proof-of-concept exploit for CVE-2019-11358, a prototype pollution vulnerability in jQuery's extend method (versions <3.4.0). Demonstrates the attack…

Persists BurpSuite proxy history, Repeater requests, and Intruder payloads across sessions; exports and imports .log files for web pentesting context.

Remote code execution in Mediawiki Score

Minimal security backport for CVE-2026-8726 in georgringer/news 8.6.0