
CVE-2026-45034
PoC exploit for PHPSpreadsheet's phar:// deserialization vulnerability, bypassing prohibitWrappers to achieve remote code execution on vulnerable PHP…

PoC exploit for PHPSpreadsheet's phar:// deserialization vulnerability, bypassing prohibitWrappers to achieve remote code execution on vulnerable PHP…

Exploit for CVE-2025-6440: unauthenticated arbitrary file upload in WooCommerce Designer Pro WordPress plugin, enabling RCE via malicious PHP upload.

Proof-of-concept exploit for unauthenticated reflected XSS in MapTiler Tileserver-php v2.0 via the 'layer' GET parameter, enabling arbitrary HTML/JS…

Proof-of-concept for CVE-2026-7089, a stored XSS in Home Service System PHP 1.0 allowing unauthenticated admin session hijacking via booking form.

Proof-of-concept for a stored XSS vulnerability in Simple Content Management System PHP, demonstrating session cookie theft via unsanitized News…

SQL Injection in computer-laboratory-management-system-using-php-and-mysql - LMS - PHP v1.0

Proof-of-concept exploit for CVE-2023-47014 demonstrating CSRF-to-CORS vulnerability in Sticky Notes App v1.0. Includes crafted payload for…

Pre-authentication remote code execution exploit for vBulletin 5.x (versions 5.0.0 to 5.5.4). Provides a shell via widget_php widget. Use for…

CVE-2020-12640: Local PHP File Inclusion via "Plugin Value" in Roundcube Webmail

Proof-of-concept exploit for reflected cross-site scripting (XSS) in Code-Projects Blood Bank V1.0 via the 'msg' parameter in index.php, with payload…

Proof-of-concept for CVE-2023-50596: a stored XSS vulnerability in Simple Image Stack Website (PHP/API v1.0) triggered via a crafted URL payload.

Proof-of-concept exploit for reflected cross-site scripting (XSS) in Code-Projects Blood Bank V1.0 via the 'error' parameter in abs.php, with a…

Proof-of-concept exploit for CVE-2024-56278, a remote code execution vulnerability in the WP Ultimate Exporter WordPress plugin, demonstrating file…

Men Salon Management System Using PHP and MySQL

My Geo Posts Free <= 1.2 - Unauthenticated PHP Object Injection

Proof-of-concept exploit for CVE-2023-48858, a reflected XSS vulnerability in Armex ABO.CMS 5.9 login page, demonstrating injection of arbitrary web…

Automated exploit for CVE-2023-51409, an unauthenticated arbitrary file upload vulnerability in the AI Engine ChatGPT Chatbot WordPress plugin,…

Lis Video Gallery <= 0.2.1 - Unauthenticated PHP Object Injection