
CVE-2024-48591
Disclosure of a Cross-Site Scripting (XSS) vulnerability in Inflectra SpiraTeam 7.2.00 via malicious SVG file upload, with impact analysis and…

Disclosure of a Cross-Site Scripting (XSS) vulnerability in Inflectra SpiraTeam 7.2.00 via malicious SVG file upload, with impact analysis and…

CVE-2026-32475 The Elementor Pro Forms File Upload field handles validation and file processing in two separate loops with different handling of…

Exploit tool for CVE-2025-55182 and CVE-2025-66478 in React Server Components and Next.js, featuring RCE gadgets, file read/write, OOB callbacks, and…

📬 Simple, private file sharing. Mirror of https://gitlab.com/timvisee/send

Exploit for Arbitrary File Read on Pulse Secure SSL VPN (CVE-2019-11510)

WooCommerce Designer Pro <= 1.9.28 - Unauthenticated Arbitrary File Read

Demonstrates XXE via SVG upload with a vulnerable Flask/lxml parser and an exploit script for arbitrary file read, SSRF, and denial-of-service…

StoryChief <= 1.0.42 - Unauthenticated Arbitrary File Upload

A security-hardened fork of the abandoned "PostGallery" WordPress plugin. Fixes critical Arbitrary File Upload (CVE-2025-13543) and Guest Access…

AI Engine for WordPress: ChatGPT, GPT Content Generator <= 1.0.1 - Authenticated (Contributor+) Arbitrary File Read

Proof-of-concept for CVE-2021-21311, a server-side request forgery in Adminer before 4.7.9, demonstrating SSRF exploitation in PHP database…

Proof-of-concept exploit for CVE-2025-45955 demonstrating Server-Side Request Forgery (SSRF) in DonWeb Ferozo hosting platform, enabling internal…

MailMasta wordpress plugin Local File Inclusion vulnerability (CVE-2016-10956)

Node.js library for streaming files as HTTP responses with support for partial content, conditional requests, and configurable caching headers.…

Security Advisory: Unauthenticated Path Traversal Allows Arbitrary File Read (TinyWeb)

CVE-2026-66066 (KindaRails2Shell) PoC - Rails Active Storage/libvips arbitrary file read to RCE; for authorized security testing

Proof-of-concept exploit and technical advisory for an Admin+ arbitrary file upload to remote code execution vulnerability in Everest Toolkit…

Frontend File Manager Plugin (WordPress) <= 23.6 - Unauthenticated Arbitrary File Deletion to RCE