
Vulnerable-Web-Application
OWASP Vulnerable Web Application Project https://github.com/hummingbirdscyber

OWASP Vulnerable Web Application Project https://github.com/hummingbirdscyber

PHP static application security testing (SAST) tool that performs taint analysis to detect XSS, SQL injection, and other vulnerabilities using…

A Path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager Project's Tiny File Manager <= 2.4.6…

All versions of the Joomla! below 3.4.6 are known to be vulnerable. But exploitation is possible with PHP versions below 5.5.29, 5.6.13 and below 5.5.

PanaceaSoft [all products] 0day exploit

CVE-2022-40348: Intern Record System - 'name' and 'email' Cross-site Scripting (Unauthenticated)


PoC for CVE-2026-3891 – Unauthenticated File Upload RCE in Pix for WooCommerce ≤ 1.5.0. Automated nonce retrieval, PHP upload, and command execution.


Lis Video Gallery <= 0.2.1 - Unauthenticated PHP Object Injection



MDJM Event Management <= 1.7.8.3 - Authenticated (Administrator+) Arbitrary File Upload via 'mdjm_email_upload_file' Parameter

Arbitrary file write in /vfm-admin/index.php?section=translations&action=update in Veno File Manager Project 4.4.9 allows an authenticated user with…


Men Salon Management System Using PHP and MySQL

My Geo Posts Free <= 1.2 - Unauthenticated PHP Object Injection

Blind SQL Injection to RCE in a PHP open source application