
Blind-XSS-Manager
Never forget where you inject.

Never forget where you inject.

ImaegMagick Code Execution (CVE-2016-3714)

POC exploit for CVE-2015-10141

Advisory and Python PoC for Pluck CMS CSRF: fail-open Referer check plus double-extension upload enables webshell deployment and remote code…

my poc for CVE-2026-53787

Exploit for CVE-2026-17544: PHP bcmath OOB write converted into memory-only RCE, bypassing disable_functions and open_basedir with a runtime…

Proof of Concept for CVE-2026-65761 - EasyStore Pro Unauthenticated SQL Injection via `filter_sortby`

CVE-2026-65891 PoC — Joomla Content Editor file rename vulnerability (auth required, fixed in JCE 2.20.2)

Reproduces CVE-2026-4040: Flask upload server with TOCTOU race condition and exploit script demonstrating arbitrary remote code execution.

PoC exploit for CVE-2026-17543: SQL injection in PHP ext/pgsql via backslash breakout, with data exfiltration and admin privilege-escalation payloads…

Python exploit for RCE in Wordpress

Responsive FileManager v.9.9.5 vulnerable to CVE-2022-46604.

📤 Mass exploitation framework for CVE-2026-56290 — Page Builder CK Joomla unauthenticated file upload to RCE

CVE-2026-48907 – Joomla JCE Unauthenticated Remote Code Execution (RCE)

A stored cross-site scripting (XSS) vulnerability exists in OpenKM version 7.1.40.

Mautic < 5.2.3 Authenticated RCE

This tool is a Proof of Concept (PoC) intended for security research and educational purposes only. Using this tool on systems without explicit…

CVE-2026-45247 - Mirasvit Full Page Cache Warmer for Magento 2 Unauthenticated PHP Object Injection -> Remote Code Execution