
CVE-2021-24741
Proof-of-concept exploit demonstrating multiple unauthenticated SQL injection vulnerabilities in Support Board 3.3.3, with error-based and time-based…

Proof-of-concept exploit demonstrating multiple unauthenticated SQL injection vulnerabilities in Support Board 3.3.3, with error-based and time-based…

Proof-of-concept exploit for CVE-2026-40487, demonstrating arbitrary file upload via MIME spoofing leading to stored XSS and account takeover in…

Small Python library that makes it easy to exploit race conditions in web apps with Requests.

WordPress File Upload RCE Exploit

Proof-of-concept exploit demonstrating OAuth2 authorization code reuse in XenForo before 2.3.13, allowing token replay and multiple token families.

Exploit for CVE-2026-25890, a path-based authorization bypass in FileBrowser <= v2.57.0, allowing authenticated low-privileged users to read, upload,…

Proof-of-concept exploit for CVE-2022-43117, a stored XSS vulnerability in Sourcecodester Password Storage Application 1.0, demonstrating JavaScript…

SecurityExplained is a new series after the previous learning challenge series #Learn365. The aim of #SecurityExplained series is to create…

Tool for check the cookie flag in multiple sites

Proof-of-concept for a reflected cross-site scripting (XSS) vulnerability in Hotel Druid 3.0.2, demonstrating arbitrary JavaScript execution via…

mooSocial v3.1.8 is vulnerable to cross-site scripting on Multiple URLs.

CVE-2019-14678: XML External Entity in SAS XML Mapper

Analyzes CVE-2021-42948, a session token exposure vulnerability in HotelDruid, demonstrating how GET parameters leak session IDs and enable session…

XSS vulnerability in Online Student Rate System1.0

WSO2-2020-0731: XXE and XSS vulnerabilities in WSO2 Carbon

TastyIgniter 3.0.7 allows XSS via the name field during user-account creation

Chikitsa Patient Management System Stored Cross-Site Scripting (XSS)

Hotel Druid 3.0.4 Stored Cross Site Scripting Vulnerability