
CVE-2025-69459
Proof-of-concept exploit for CVE-2025-69459, demonstrating broken access control in Movie Rating System 1.0 that allows unauthenticated admin account…

Proof-of-concept exploit for CVE-2025-69459, demonstrating broken access control in Movie Rating System 1.0 that allows unauthenticated admin account…

AdForest <= 6.0.9 - Authentication Bypass to Admin

Exploit for CVE-2022-23131 targeting Zabbix SAML SSO authentication bypass vulnerability. Enables session hijacking and unauthorized admin access.

Python 3 exploit for Pluck CMS 4.7.13 file upload restriction bypass, enabling authenticated admin to upload a PHP webshell and achieve remote code…

A stored XSS in the project delete flow allows execution of attacker-controlled JavaScript in an administrator’s browser when the admin attempts to…

A stored cross-site scripting (XSS) vulnerability exists in Decap CMS up to version 3.8.3. The issue affects multiple input fields in the **admin…

Proof-of-concept exploit for CVE-2025-57310: CSRF vulnerability in Simple-Faucet-Script v1.07 enabling stored XSS via crafted POST requests to the…

A critical vulnerability in the Intelbras NVD 9032 R Ftd IP CFTV device allows an attacker to bypass the multi-factor authentication during password…

Alex Reservations: Smart Restaurant Booking <= 2.2.3 - Authenticated (Admin+) Arbitrary File Upload

Exploit script for CVE-2025-68860 targeting WordPress Mobile Builder plugin. Generates forged JWT tokens using a hardcoded secret to authenticate as…

Proof-of-concept exploit for CVE-2018-17081, a Cross-Site Request Forgery vulnerability in e107 CMS 2.1.9, demonstrating unauthorized admin actions…

CVE-2025-60375 — Authentication bypass / incorrect access control in PerfexCRM < 3.3.1 (admin login)

Exploit for CVE-2020-29204 targeting XXL-JOB distributed task scheduling framework, demonstrating remote code execution via unauthenticated access to…

Online Bus Booking System 1.0, there is Authentication bypass on the Admin Login screen in admin.php via username or password SQL injection.

Proof-of-concept exploit demonstrating unauthenticated CSRF-based account takeover via reflected DOM-XSS in BigTreeCMS v4.4.14 admin panel.

Unauthenticated time-based blind SQL injection exploit for CMS Made Simple <= 2.2.9. Extracts admin credentials and optionally cracks password hashes…

Proof of Concept and Security Advisory for XSS vulnerability in the FD602GW-DX-R410 fiber router’s admin console (firmware V2.2.14). Includes…

Yetishare SQL Injection in sSortDir_0 parameter - v3.5.2 - v4.5.4. Apart from an admin being able to exploit this, it could also be used in a CSRF…