
CVE-2019-9053
Python exploit for CVE-2019-9053 targeting SQL injection in CMS Made Simple, enabling automated time-based blind injection and credential extraction.

Python exploit for CVE-2019-9053 targeting SQL injection in CMS Made Simple, enabling automated time-based blind injection and credential extraction.

cve-2019-5420 POC simple ruby script

Unauthenticated time-based blind SQL injection exploit for CMS Made Simple ≤ 2.2.9 (CVE-2019-9053), ported to Python 3.

Unauthenticated remote code execution exploit for Simple Image Gallery 1.0, with a detailed write-up and ExploitDB reference.

Simple exploit

Exploit for CVE-2026-5203 in CMS Made Simple, leveraging path traversal and arbitrary file upload to achieve remote code execution with an…

PoC of CVE-2021-26814

Python 3 exploit for CVE-2019-9053, an unauthenticated SQL injection in CMS Made Simple 2.2.9, that extracts admin credentials and optionally cracks…

CVE-2025-15495 - Arbitrary File Upload Leading to Remote Code Execution (RCE)

CVE-2019-9053 rewritten in python3 to fix broken syntax. Affects CMS made simple <2.2.10

A quick python exploit for the Nostromo 1.9.6 remote code execution vulnerability. Simply takes a host and port that the web server is running on.

Simple hash cracker for Apache Shiro hashes written in Golang. Useful for exploiting CVE-2024-4956.

A simple bash script to exploit Joomla! < 4.2.8 - Unauthenticated information disclosure

CVE-2019-9054 exploit added support for python3 + bug fixes

Minimal Next.js 12.2 application containerized with Docker, providing a simple Hello World web app and local development instructions.

Reproduces CVE-2025-29927 middleware authorization bypass in Next.js 14.2.24 and demonstrates exploitation with curl to bypass authentication and…

Exploit for CVE-2025-34085

A proof of concept to exploit the reflected XSS vulnerability in the oVirt web interface (RedHat). In this PoC a VM in the oVirt IaaS environment is…