
CVE-2026-11551-PoC
Proof-of-concept exploit for CVE-2026-11551, an unauthenticated privilege escalation vulnerability in the Branda White Label plugin for WordPress,…

Proof-of-concept exploit for CVE-2026-11551, an unauthenticated privilege escalation vulnerability in the Branda White Label plugin for WordPress,…

CVE disclosure for stored cross-site scripting (XSS) in SWISH Prolog up to v2.2.0, enabling arbitrary code execution and account takeover via crafted…

Bug bounty and vulnerability research reports by Desai Vinayak — includes CVE-2023-50290 (Apache Solr) and Zscaler subdomain takeover findings.

Proof-of-concept exploit for CVE-2025-22963, a CSRF vulnerability in Teedy v1.11 allowing account takeover via user information change endpoint.

Survey XSS combined with CSRF leads to Admin Account Takeover in Concrete5 8.5.4

1-Click Login: Passwordless Authentication 1.4.5 - Authentication Bypass via Account Takeover

Proof-of-concept exploit for CVE-2023-42362: unrestricted file upload leading to stored XSS and admin account takeover in NCR Teller web app 4.4.0.

Proof-of-concept for stored XSS in Unifiedtransform v2.0's Create Assignment function, demonstrating remote code execution via malicious PDF upload…

Detects subdomain takeover vulnerabilities by analyzing DNS records and HTTP responses. Automatically identifies takeover-prone subdomains for…

Exploit and analysis for CVE-2026-5465, an IDOR in Amelia WordPress plugin allowing authenticated Provider role to escalate privileges and achieve…

Proof-of-concept exploit for CVE-2026-40487, demonstrating arbitrary file upload via MIME spoofing leading to stored XSS and account takeover in…

Exploit tool targeting CVE-2023-7028 in GitLab, enabling account takeover through password reset vulnerability.

Exploit for CVE-2026-18963, a critical unauthenticated account takeover in Keycloak's reset-credentials flow, chaining two bugs to bypass email…

PoC for CVE-2026-19632 - TranslatePress – Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure

One-day proof-of-concept exploit for CVE-2026-19632, a critical unauthenticated account takeover in TranslatePress WordPress plugin, demonstrating…

Automated Recon for Pentesting & Bug Bounty

Tips and Tutorials for Bug Bounty and also Penetration Tests.

XSS payloads designed to turn alert(1) into P1