
CVE-2026-48907
POC for CVE-2026-48907
educationexploitationlabs-practice+5
11 month ago

POC for CVE-2026-48907

Podlove Podcast Publisher Unauthenticated File Upload RCE via is_image() vs extract_file_extension() Mismatch | CVSS 9.8

Proof-of-concept exploit for CVE-2019-11358, a prototype pollution vulnerability in jQuery's extend method (versions <3.4.0). Demonstrates the attack…

CVE-2025-24893 tool

CVE-2023-38831 - WinRAR

Vuln lab: MainWP Dashboard <= 3.1.2 Unauthenticated Stored XSS

Remote code execution in Mediawiki Score

Shortcode Addons <= 3.2.5 - Authenticated (Admin+) Arbitrary File Upload

Persists BurpSuite proxy history, Repeater requests, and Intruder payloads across sessions; exports and imports .log files for web pentesting context.