
CVE-2026-27541-Analysis-Lab
Docker lab for reproducing CVE-2026-27541, an authenticated privilege escalation in WooCommerce Wholesale Prices. Compares vulnerable and patched…

Docker lab for reproducing CVE-2026-27541, an authenticated privilege escalation in WooCommerce Wholesale Prices. Compares vulnerable and patched…

Docker lab demonstrating CVE-2026-17532, an unauthenticated reflected XSS in Seraphinite Accelerator that chains to RCE via admin session, with…

CVE-2026-79752 disclosure pack for CakePHP 5.2.13 SQL injection via FunctionsBuilder::cast, with a Python PoC script and Docker lab for authorized…

A script to exploit a vulnerability in xmlsec1 where xmlsec ignores loaded public keys

Sets up a Docker-based Palo Alto firewall test environment and provides an exploit script to test CVE-2024-3400, enabling safe vulnerability…

Local isolated reproduction lab for CVE-2026-35037, an unauthenticated SSRF vulnerability in Ech0's GET /api/website/title endpoint. Includes Docker…

Exploit for CVE-2021-25735 demonstrating Kubernetes Validating Admission Webhook bypass via node label manipulation, with deployable Docker container…

Disclosure pack and PoC script for CVE-2026-45140, an unauthenticated path traversal and RCE in Chamilo LMS CStudio upload, with a loopback Docker…

Reproduction pack and PoC script for CVE-2026-87796, an unauthenticated arbitrary file upload RCE in Multi Uploader for Gravity Forms <= 1.1.9, with…

Docker-based lab and exploit script for CVE-2024-23897, a critical arbitrary file read in Jenkins CLI via args4j expandAtFiles, with steps to chain…

Proof-of-concept and lab for CVE-2026-75827, a Grav arbitrary file write via Blueprint dynamic-data error_log, with reproduction script and Docker…

Containerized three-tier lab reproducing CVE-2023-43804 urllib3 cookie leak via cross-origin redirects, with exploit script and patch verification.

Demonstration of the WP Visitor Statistics plugin exploit

Cross-site scripting labs for web application security enthusiasts

Proof-of-concept exploit for CVE-2026-3844, an unauthenticated arbitrary file upload leading to remote code execution in Breeze Cache <= 2.4.4.…

Proof-of-concept exploit for CVE-2026-27607, a missing post-policy validation in RustFS, demonstrating the vulnerability with a Node.js script and…

Proof-of-concept exploit for CVE-2025-54352, a WordPress vulnerability that leaks titles of private and draft posts. Demonstrates the attack and…

PoC exploit for Nginx integer overflow vulnerability (CVE-2017-7529) enabling out-of-bounds cache read. Includes Docker-based lab environment and…