
By-Poloss..-..CVE-2026-11551-PoC
Unauthenticated Privilege Escalation via Account Takeover

Unauthenticated Privilege Escalation via Account Takeover

Full-chain CVE-2025-57819 PoC for FreePBX 15, 16, and 17: unauthenticated SQLi to RCE and root takeover.

CVE-2025-6254 — Doctreat Core <= 1.6.8 — Unauthenticated Privilege Escalation

TCP Port Forwarding Utility on C

CVE-2026-7459 Simple History Missing Authorization Account Takeover Exploit

CVE-2026-8206 Kirki Plugin Unauthenticated Account Takeover Exploit


CVE-2026-40791: Unauthenticated stored XSS in WP Time Slots Booking Form <= 1.2.46

Python proof-of-concept exploit for CVE-2026-7458, an unauthenticated authentication bypass in PickPlugins User Verification WordPress plugin via…

Lab + writeup for CVE-2026-44166: PocketBase OAuth2 account pre-hijacking via unvalidated createData.email

Account takeover full PoC for CVE-2026-27886 in Strapi CMS

PoC & Write-up for CVE-2025-68434: Critical CSRF in OpenSourcePOS. Exploits a disabled filter configuration to allow unauthenticated attackers to…

Hippoo Mobile App for WooCommerce <= 1.9.4 - Unauthenticated Authentication Bypass to Administrator Account Takeover

CVE-2026-48866 — Gravity Forms <= 2.10.0.1 Arbitrary File Deletion via Path Traversal (CVSS 9.6)

ARMember Premium <= 7.3.1 Full Admin Account Takeover

Public advisory for CVE-2025-65640: Stored XSS vulnerability in Globe Document Intelligence.

PoC CVE-2026-8732 (WP Maps Pro <= 6.1.0)