
cve-2026-15748
Scans WordPress Forminator for CVE-2026-15748 unauthenticated RCE. Detects vulnerable sites, crawls forms, extracts nonces, runs safe upload tests.

Scans WordPress Forminator for CVE-2026-15748 unauthenticated RCE. Detects vulnerable sites, crawls forms, extracts nonces, runs safe upload tests.

Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator

Non-destructive detector for CVE-2026-64638 (XSS2Shell) — WordPress pre-auth XSS reflection primitive

Fast Python scanner detects vulnerable Laravel Livewire v3 sites (CVE-2025-54068, CVSS 9.2). Separates risky sites into vuln.txt, safe sites into…

CVE-2026-56292 - AcyMailing for Joomla unauthenticated SQL injection scanner

Passive security checker for CVE-2026-48908 affecting SP Page Builder.

CVE-2026-64638: WordPress Pre-auth XSS → RCE (XSS2Shell) PoC

Modern tactical exploitation toolkit.


A Chrome/Firefox browser extension to show alerts for reflected query params, show Wayback archive links for the current path, show hidden elements…

Adobe Experience Manager (AEM) hacking toolkit

Collection of scripts and tools used during bug bounty work. This will be the location of my automation scripts created for my own personal use, and…

Safe PowerShell validator for PHP CVE-2026-17543 exposure via HTTP headers and non-destructive login-form probes.

Finds CSP report urls and tests to see if they are vulnerable to log4j

A web app scanner

Web Filter External Enumeration Tool (WebFEET)

Appspec YML and YAML leaks

BeHat Configuration file leaking