
CVE-2025-55287-POC
Authenticated stored XSS priv esc PoC. Affects Genealogy versions prior to 4.4.0

Authenticated stored XSS priv esc PoC. Affects Genealogy versions prior to 4.4.0

GutenKit <= 2.1.0 - Unauthenticated Arbitrary File Upload

Single-file Python scanner for CVE-2026-48907 (Joomla JCE Editor RCE). Detects Joomla/JCE, performs intrusive math-verified payload test, supports…

Stored XSS in MicroStrategy Web prior to 10.4.6

Unauthenticated 0-click RCE exploit for CVE-2024-9932. Exploits an arbitrary file upload vulnerability in the Wux Blog Editor WordPress plugin to…

Automated RCE exploit for Joomla JCE (CVE-2026-48907) with interactive shell, batch command execution, file download, and proxy support for…

CVE-2016-4999

Advisory: Cute Editor 6.4 reflected XSS via 'Theme' parameter in colorpicker_more.aspx

Proof-of-concept exploit for CVE-2026-21721 that escalates privileges to admin on affected dashboards, requiring a valid Editor account.

Penpot's remote image import let an authenticated file editor turn a normal media convenience feature into backend-origin SSRF because…

Froala Persistent XSS


Repository for CVE-2023-43263 vulnerability.

Repository for CVE-2023-42426 vulnerability.

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Profile in…

CVE-2026-65891 PoC — Joomla Content Editor file rename vulnerability (auth required, fixed in JCE 2.20.2)

The Joomla extension PhocaCommander is vulnerable to Path Traversal in the getSource function - CVSS 8.2

AI Engine for WordPress: ChatGPT, GPT Content Generator <= 1.0.1 - Authenticated (Contributor+) Arbitrary File Read