
CVE-2026-48939
Pre-auth arbitrary file upload RCE exploit for iCagenda Joomla extension < 4.0.8 (CVSS 10.0)

Pre-auth arbitrary file upload RCE exploit for iCagenda Joomla extension < 4.0.8 (CVSS 10.0)

Burp Suite extension for detecting and testing CVE-2024-34102, a critical web vulnerability, enabling automated security assessment and exploitation…

Podlove Podcast Publisher Unauthenticated File Upload RCE via is_image() vs extract_file_extension() Mismatch | CVSS 9.8

CVE-2026-49049 - Unauthenticated File Deletion, Arbitrary Write & XSS Injection for Helix3 Joomla Extension

Demonstrates a local code execution exploit for Foxit PDF Reader via XFA-based PDFs, with step-by-step attack reproduction and extension to related…

CVE-2026-53767 + CVE-2026-53768 - Authenticated RCE in Chyrp Lite ≤ 2026.01 via uploads_path blocklist bypass and missing extension validation

Shortcode Addons <= 3.2.5 - Authenticated (Admin+) Arbitrary File Upload

POC exploit for CVE-2015-10141

SQL Injection POC for CVE-2024-21514: Divido payment extension for OpenCart

Docker-based lab environment demonstrating CVE-2018-19518 RCE exploit via PHP IMAP extension, with step-by-step usage and WAF integration for…

Fixed proof-of-concept exploit for CVE-2024-9264, a critical Grafana RCE via DuckDB SQL expressions. Executes reverse shell using corrected shellfs…

AdmirorFrames Joomla! Extension < 5.0 - Server-Side Request Forgery

A stored cross-site scripting (XSS) vulnerability exists in OpenKM version 7.1.40.

Python Interactive Exploit for WP File Manager Vulnerability. The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote…

Exploit for XSS via BBCode on Kunena extension before 5.1.14 for Joomla!