
CVE-2026-27541-Analysis-Lab
Docker lab for reproducing CVE-2026-27541, an authenticated privilege escalation in WooCommerce Wholesale Prices. Compares vulnerable and patched…

Docker lab for reproducing CVE-2026-27541, an authenticated privilege escalation in WooCommerce Wholesale Prices. Compares vulnerable and patched…

Detailed write-up of CVE-2026-26416, an authorization bypass vulnerability in TCS Cognix Recon Client v3.0 allowing privilege escalation via crafted…

Detailed disclosure of CVE-2025-63314: static, non-expiring password reset token in Acora CMS 10.7.1 enabling account takeover and privilege…

An attacker can execute arbitrary JavaScript in the victim's browser, potentially leading to session hijacking or privilege escalation.

An attacker can execute arbitrary JavaScript in the victim's browser, potentially leading to session hijacking or privilege escalation.

CVE-2023-39144 disclosure: cleartext password exposure in Element55 Maketime appliance admin pages, enabling privilege escalation via…

Documentation for CVE-2024-56116: a Cross-Site Request Forgery vulnerability in Amiro.CMS before 7.8.4 allowing remote attackers to create an…

Authenticated Privilege Escalation to Admin exploiting Uncanny Groups for LearnDash.

Proof-of-concept for CVE-2020-24030: weak token expiration in ForLogic Qualiex v1/v3 enabling remote unauthenticated privilege escalation and…

Proof-of-concept for CVE-2020-24029: unauthenticated password change vulnerability in ForLogic Qualiex v1 and v3, enabling remote privilege…

Security advisory detailing a critical authentication vulnerability (CVE-2025-4162030) in Copilot, involving user ID switching that could lead to…

Proof-of-concept exploit for CVE-2023-45992: Stored Cross-Site Scripting and CSRF in Ruckus CloudPath 5.12 enabling unauthenticated full admin…

Security advisory for CVE-2025-4172025: an authentication bypass vulnerability in Copilot enabling unauthorized account access, session hijacking,…

SOC case analysis walkthrough demonstrating detection and response to CVE-2023-29357 privilege escalation in Microsoft SharePoint Server, including…

Educational lab demonstrating detection and mitigation of CVE-2023-32243 privilege escalation in WordPress Essential Addons for Elementor, using…

Burp plugin which supports in finding privilege escalation vulnerabilities

Mass scanner and exploit for CVE-2026-15989, the unauthenticated privilege escalation in Super Forms <= 6.3.316 that creates administrator accounts…

CTF Cheat Sheet + Writeups / Files for some of the Security CTFs that I've done