
CVE-2021-44217
Proof-of-concept for a stored XSS vulnerability (CVE-2021-44217) in Ericsson CodeChecker's comments component, enabling cookie theft and sensitive…

Proof-of-concept for a stored XSS vulnerability (CVE-2021-44217) in Ericsson CodeChecker's comments component, enabling cookie theft and sensitive…

POC of CVE-2014-0166 (WordPress cookie forgery vulnerability)

a small utility to generate a cookie in order to exploit a grafana vulnerability (CVE-2018-15727)

Apahce-Superset身份认证绕过漏洞(CVE-2023-27524)检测工具

Proof-of-concept exploit for PrivateBin Local File Inclusion (CVE-2025-64714) via template cookie path traversal, with detection and RCE chaining…

Proof-of-concept exploit for CVE-2025-63708, a stored XSS vulnerability in AI Font Matcher. Demonstrates session cookie theft via unsanitized font…

Tenda AC15 cookie exposure

Stored XSS proof-of-concept for SOGo groupware, exploiting the 'Remember Username' cookie to inject JavaScript payloads via the login endpoint.

CVE-2025-45250 POC

The graph functionality of DeimosC2 v1.1.0-Beta is vulnerable to Stored Cross-Site Scripting (XSS), allowing the theft of session cookie and…

JAY Login & Register <= 2.4.01 - Authentication Bypass via Cookie

Proof-of-concept exploit for an authentication bypass vulnerability (CWE-565) in WP Private Content Plus v3.6.2, allowing unauthenticated access to…

Automated auth bypass exploit for CVE-2025-0316 targeting WordPress WP Directorybox Manager. Features user enumeration, proxy support,…

Cookie-based authentication vulnerability on Tk-Rt-Wr135G

Proof-of-concept for CVE-2024-51031: Stored Cross-Site Scripting (XSS) in Sourcecodester Cab Management System 1.0 via manage_account.php fields.…

In LetterPress plugin <= 1.2.1 is vulnerable to Cookie Stealing Vulnerability. An attacker can able to steal the cookies by injecting the JavaScript…

Python exploit for CVE-2024-10924 that bypasses Two-Factor Authentication in the Really Simple SSL WordPress plugin, enabling unauthorized…

Proof-of-concept for CVE-2023-29983: stored cross-site scripting via unsanitized token parameter in cmaps auditlog, enabling admin cookie theft.