
CVE-2026-84753
Proof-of-concept exploit and lab for CVE-2026-84753, an unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 via the mint-form-submit REST…

Proof-of-concept exploit and lab for CVE-2026-84753, an unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 via the mint-form-submit REST…

Python proof-of-concept for CVE-2026-67401, an authenticated SQL injection in cPanel EmailTrack that allows arbitrary file write as root via SQLite…

Open-source email filtering framework that detects spam and phishing using content analysis, header checks, Bayesian scoring, and DNS blocklists.

Mail-in-a-Box helps individuals take back control of their email by defining a one-click, easy-to-deploy SMTP+everything else server: a mail server…

A script that helps you understand why your E-Mail ended up in Spam

Proof-of-concept exploit for CVE-2026-11113, demonstrating SMTP header injection in a Flask contact form via unsanitized email input; includes…

Simulated Python demonstration of CVE-2026-8080 DKIM verification bypass, showing how non-compliant header canonicalization lets attackers inject…

Python script for enumerating SMTP users by leveraging VRFY and EXPN commands to identify valid email accounts on a target mail server.

SEt framework

Most Powerful Send Fake Mail Using Any Mail I'd undetectable

MailMasta wordpress plugin Local File Inclusion vulnerability (CVE-2016-10956)

Buffer Overflow in Seattle Lab Mail (SLmail) 5.5 - POP3

Zimbra <9.0.0.p27 RCE

Exploit script for WordPress Plugin Mail Masta 1.0 - CVE-2016-10956

nginx 1.15.10 patch against cve-2021-23017 (ingress version)

The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads.

Roundcube 1.0.0 <= 1.2.2 Remote Code Execution exploit and vulnerable container

Local Docker lab demonstrating CVE-2026-8206 unauthenticated account takeover in Kirki WordPress plugin. Compares vulnerable 6.0.6 vs patched 6.0.7…