
CVE-2026-34200
Proof-of-concept demonstrating unauthenticated cross-origin takeover of Nhost MCP Server, enabling database exfiltration, table drops, and permission…

Proof-of-concept demonstrating unauthenticated cross-origin takeover of Nhost MCP Server, enabling database exfiltration, table drops, and permission…

Demonstration of the SQL injection vulnerability in wordpress 5.8.2

WordPress PPOM for WooCommerce Plugin <= 33.0.15 is vulnerable to SQL Injection

Proof-of-concept exploit for CVE-2024-32136, a post-authenticated SQL injection in BWL Advanced FAQ Manager 2.0.3, demonstrating time-based database…

Proof-of-concept demonstrating SQL injection in HotelDruid v3.0.5, with steps to exploit vulnerable parameters for data retrieval and remote code…

Unauthenticated SQL injection exploit for Ghost CMS Content API (CVE-2026-26980); dumps database tables from SQLite/MySQL with active/passive checks…

Read-only WordPress plugin that scans for artifacts of the wp2shell exploit chain (CVE-2026-63030 / CVE-2026-60137)

Proof-of-concept exploit for CVE-2026-2413, a time-based blind SQL injection in the Ally WordPress plugin, allowing unauthenticated attackers to…

Proof-of-concept exploit for CVE-2024-10400, a time-based blind SQL injection in Tutor LMS WordPress plugin, allowing unauthenticated attackers to…

Proof-of-concept exploit for CVE-2026-38812, a SQL injection vulnerability in RuoYi v4.8.2 via the /tool/gen/createTable endpoint, enabling…

Authenticated SQL injection exploit for Royal Event Management System 1.0 via the 'todate' parameter, with proof-of-concept payloads and SQLmap…

Proof-of-concept exploit for CVE-2024-2879: unauthenticated SQL injection in LayerSlider WordPress plugin (7.9.11-7.10.0). Includes scanner script…

Remote attacker can access sensitive data exposed on the URL

CVE-2021-45744 - A Stored Cross Site Scripting (XSS) vulnerability exists in bludit 3.13.1 via the TAGS section in login panel. Application stores…

CVE-2021-45745 - A Stored Cross Site Scripting (XSS) vulnerability exists in Bludit 3.13.1 via the About Plugin in login panel. Application stores…

A Stored Cross-Site Scripting (XSS) vulnerability exists in Issabel-PBX version 4.0.0-6. The application fails to properly sanitize and encode…

CVE-2021-45744 - A Stored Cross Site Scripting (XSS) vulnerability exists in bludit 3.13.1 via the TAGS section in login panel. Application stores…

CVE-2021-45745 - A Stored Cross Site Scripting (XSS) vulnerability exists in Bludit 3.13.1 via the About Plugin in login panel. Application stores…