
CVE-2023-3460
Exploit and scanner for CVE-2023-3460, a WordPress Ultimate Member plugin privilege escalation vulnerability allowing unauthenticated admin account…

Exploit and scanner for CVE-2023-3460, a WordPress Ultimate Member plugin privilege escalation vulnerability allowing unauthenticated admin account…

Stored XSS via User-Agent in Admin Order View in PhocaCart

Exploit PoC for WordPress Burst Statistics authentication bypass allowing unauthenticated admin impersonation via crafted Authorization header.

Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…

Exploit for Apache Airflow FAB OAuth authentication bypass (CVE-2026-59243) that achieves admin access and remote code execution by triggering a…

PoC exploit for unauthenticated RCE in EITS Admin Dashboard v2.4.0 via command injection in /api/v1/debug, allowing arbitrary OS command execution on…

Automated exploit for CVE-2025-69212 command injection in OpenSTAManager, featuring admin authentication, malicious ZIP upload, and reverse shell or…

PoC for CVE-2026-73847 - emlog AI Assistant CSRF to SQL execution to admin takeover (CVSS 6.8)

WordPress Pie Register ≤ 3.7.1.4 - Admin Privilege Escalation (Unauthenticated)

WordPress Plugin MasterStudy LMS 2.7.5 - Unauthenticated Admin Account Creation

Exploit for CVE-2023-41362, a remote code execution vulnerability in MyBB Admin Control Panel, allowing authenticated attackers to execute arbitrary…

Python exploit script for CVE-2024-4040 CrushFTP file read vulnerability with file reading, admin session token retrieval, and vulnerability check…

Proof-of-concept exploit for Apache ShenYu Admin JWT authentication bypass (CVE-2021-37580). Includes a scanning script to detect vulnerable…

CVE-2026-29000 – pac4j-jwt Authentication Bypass (🔥 CVSS 10.0). One-click admin forge via public key JWE wrapping. Leaks configs, users, secrets.…

Dockerized Typesetter CMS environment reproducing CVE-2020-25790 file upload vulnerability, with default admin credentials and a walkthrough for…

Proof-of-concept exploit for an authentication bypass in Hotel and Tourism Reservation System 1.0, allowing unauthenticated admin access via inverted…

Proof-of-concept exploit for CVE-2026-54807 demonstrating unauthenticated privilege escalation via WooCommerce registration form, enabling admin role…

Librebooking Admin RCE PoC CVE-2026-61343