Publicly Disclosed
PoC Exploits
đź”´ Alway take caution when working with PoC Exploits đź”´
Discovered 3 hours ago
PoC for CVE-2026-78115
A security issue has been identified in the SourceCodester Class and Exam Timetabling System version 1.0, specifically within the User Account Update functionality located in /admin/edit_user_account.php. This vulnerability allows attackers to manipulate the 'id' or 'username' parameters, leading...
PoC for CVE-2026-78112
A vulnerability has been identified in the itsourcecode Hospital Management System Project in PHP version 1.0, specifically within the /viewservicetype.php file. This weakness allows for SQL injection attacks through the manipulation of the 'delid' argument, potentially exposing sensitive data an...
Discovered 7 hours ago
PoC for CVE-2026-77115
The Brave Popup Builder plugin allows for the reflection of UTM query parameters into the popup form HTML without proper escaping. This vulnerability can be exploited by attackers to execute malicious scripts in the context of the user's browser, potentially leading to unauthorized actions or dat...
PoC for CVE-2026-77116
The Brave Popup Builder plugin suffers from a broken access control vulnerability that affects versions up to 0.8.5. This flaw allows any logged-in user, including those with Subscriber or WooCommerce Customer roles, to access popup content by manipulating the post ID in the URL. Such unauthorize...
PoC for CVE-2026-77003
The Content Mask plugin for WordPress prior to version 1.8.5.5 contains a vulnerability that fails to validate user permissions when creating post types. This oversight permits users with minimal roles, such as Contributor, to publish posts and pages without possessing the required publish capabi...
PoC for CVE-2026-13598
The RestrictMate plugin for WordPress prior to version 1.3.0 contains a flaw that fails to properly restrict the user role during the account registration process. This oversight permits unauthenticated attackers to create a new account with administrative privileges, enabling them to gain unauth...
PoC for CVE-2026-14853
The WooCommerce Bookings plugin for WordPress prior to version 3.9.0 contains an improper access control vulnerability. It lacks adequate checks on an AJAX action, enabling users with Subscriber-level roles or higher to create draft bookable products by bypassing the nonce verification process. T...
Discovered 8 hours ago
PoC for CVE-2026-78063
A command injection vulnerability exists in the Tenda CH22 router, specifically in the formeditFileName function located in the /goform/editFileName file. This flaw allows an attacker to manipulate the editNameMit argument, enabling the execution of arbitrary commands remotely. The exploit has be...
Discovered 9 hours ago
PoC for CVE-2026-78060
A significant cross-site scripting vulnerability has been detected in the SourceCodester Stock Management System, specifically affecting the file /php_action/getOrderReport.php. This flaw allows attackers to manipulate the parameters clientName and clientContact to inject malicious scripts. The v...
PoC for CVE-2026-78059
A cross site scripting vulnerability exists in the SourceCodester Stock Management System v1.0, specifically within the /php_action/printOrder.php file. Attackers can manipulate parameters such as clientName and clientContact, allowing them to inject malicious scripts remotely. This potential exp...
Discovered 10 hours ago
PoC for CVE-2026-78057
A vulnerability has been identified in the sambitraj Student-Management System that allows for SQL injection via manipulation of the argument fields including roll_no, name, father_name, class, mobile, email, password, and remark. This flaw could enable remote attackers to execute unauthorized SQ...
PoC for CVE-2026-78056
A SQL injection vulnerability exists in the Dashboard component of the sambitraj Student-Management-System. The flaw arises from improper handling of user input via the roll_no or teacher_name arguments, allowing an attacker to execute malicious SQL commands remotely. As this exploit is now publi...
Discovered 12 hours ago
PoC for CVE-2026-78055
A cross-site scripting vulnerability has been discovered in the SourceCodester Class and Exam Timetabling System version 1.0. The vulnerability lies in the manipulation of an unspecified argument within the file /BSIT2.php, which allows attackers to execute arbitrary JavaScript in the context of ...
PoC for CVE-2026-78054
A security flaw has been detected in the SourceCodester Class and Exam Timetabling System version 1.0. This vulnerability resides in the BSIS1.php file, where an improper handling of the 'course' argument allows for cross-site scripting (XSS) attacks. Malicious users can exploit this weakness rem...
Discovered 13 hours ago
PoC for CVE-2026-78051
A vulnerability exists in the alexta69 MeTube application due to an issue in the Cookie File Handler component. This flaw affects the cookies.txt file located at /download/.metube/cookies.txt, which may allow an attacker to gain unauthorized access to files or directories. The potential for explo...
PoC for CVE-2026-78050
A stack-based buffer overflow vulnerability has been identified in the Web Management component of Comfast CF-N1-S 2.6.0.1. The issue occurs within the function sub_41AD7C located in the mbox-config endpoint when handling user input parameters such as timestr and ntp_client_enabled. This vulnerab...
PoC for CVE-2026-78122
The docker-socket-proxy has a security flaw that allows unauthorized access to sensitive information through the Docker API. When the CONTAINERS environment variable is set, attackers can exploit this weakness to perform GET requests on specific API endpoints, such as /containers/{id}/logs and /c...
Discovered 14 hours ago
PoC for CVE-2026-78049
A vulnerability exists in the Systerel S2OPC software, particularly affecting the AddNodes Service. The flaw is located in the SOPC_NodeMgtHelperInternal_AddVariableNodeAttributes function, where improper handling of the UserAccessLevel argument can result in an out-of-bounds read. This issue can...
Discovered 1 day ago
PoC for CVE-2026-77988
A vulnerability has been found in the TRENDnet TEW-823DRU router's CLI Configuration Tool, specifically within the nvram_get function. This flaw allows for command injection, which can be exploited remotely. The potential for unauthorized access and manipulation of system commands poses significa...
PoC for CVE-2026-77946
A vulnerability exists in the TRENDnet TEW-821DAP product version 2.2.01b05, specifically within the uci_safe_get function of the /cgi-bin/apply_time.cgi script related to the NTP Timezone Configuration. An attacker can exploit this vulnerability by manipulating specific arguments, leading to a s...
PoC for CVE-2026-77945
A command injection vulnerability exists in the TRENDnet TEW-821DAP version 2.2.01b05, specifically in the functionality of the /cgi-bin/upload.cgi file related to the ssi component. By manipulating the filename parameter, an attacker can execute arbitrary commands remotely, posing a significant ...
PoC for CVE-2026-77001
The Social Login & Sharing buttons with Analytics plugin by SoClever, prior to version 1.2.0, contains a significant security flaw that lacks essential authentication, authorization, and nonce checks in its publicly accessible login handlers. This oversight enables unauthenticated attackers to ex...
PoC for CVE-2026-76793
The Firebase Authentication plugin for WordPress has a security vulnerability that permits unauthenticated attackers to log in as any user, including those with administrative privileges. This issue arises because the plugin fails to verify the email address in the authentication token prior to m...
PoC for CVE-2026-19222
The Forminator Forms plugin for WordPress, prior to version 1.57.0.7, has a security flaw in its role restriction enforcement for registration forms. This vulnerability permits users who are authorized to create forms to set configurations that allow any visitor registering through the form to be...
PoC for CVE-2026-76789
The Slider Hero with Video Background, Animation WordPress plugin prior to version 9.1.3 is susceptible to a critical security flaw that permits unauthenticated users to exploit the plugin's request handlers. This exploit bypasses essential authorization and nonce checks, enabling the injection o...
PoC for CVE-2026-77002
The SmilePass Selfie Login plugin for WordPress, up to version 1.0.2, is susceptible to an authentication bypass vulnerability. This flaw allows attackers to impersonate any registered user, including administrators, by circumventing the necessary server-side identity verification. Consequently, ...
PoC for CVE-2026-77000
The WP Social Media Login plugin for WordPress, up to version 1.0.6, contains a vulnerability where it fails to properly verify social logins from identity providers. This flaw permits unauthorized users to bypass authentication and log in as any existing user by merely providing the email addres...
PoC for CVE-2026-16738
The Conekta Payment Gateway plugin for WordPress versions prior to 6.2.2 contains a serious security flaw where it fails to authenticate incoming webhook notifications from the payment gateway. This oversight allows attackers to manipulate order statuses by marking any order as paid without prope...
PoC for CVE-2026-19221
The Forminator Forms plugin for WordPress, prior to version 1.57.0.5, exposes a critical weakness that allows any site administrator within a multisite network to execute arbitrary code. This occurs due to the improper restriction of a network-wide setting, thereby enabling potential malicious ac...
PoC for CVE-2026-16612
The FiboSearch plugin for WordPress prior to version 1.34.1 allows unauthorized users to access sensitive information on password-protected products through its unauthenticated AJAX endpoints. Specifically, the autocomplete search and details panel endpoints do not enforce adequate authentication...
PoC for CVE-2026-19093
The Tutor LMS WordPress plugin, prior to version 4.0.6, has a significant security issue due to the lack of validation for stored file paths when streaming media. This oversight allows users with instructor permissions to read arbitrary files stored on the server. As a result, sensitive informati...
PoC for CVE-2026-18052
The ManageWP Worker plugin for WordPress has a vulnerability that allows attackers to bypass authentication processes. This is due to the plugin failing to bind the account being logged into with the authorization signature, which can lead to session hijacking. If an attacker gains access to a pr...
PoC for CVE-2026-14187
The Tutor LMS WordPress plugin versions prior to 4.0.6 are susceptible to an insecure access control vulnerability. This flaw allows users with the instructor role to access private course content owned by other instructors. Consequently, an unauthorized user can view sensitive course materials, ...
PoC for CVE-2026-16260
The Post Grid, Slider & Carousel Ultimate plugin for WordPress prior to version 1.8.1 is susceptible to a JavaScript injection vulnerability. This flaw arises from the plugin's failure to properly sanitize and escape specific custom post type settings prior to rendering them in HTML attributes on...
Discovered 2 days ago
PoC for CVE-2026-49114
In ONNX versions prior to 1.21.0, a vulnerability exists in the 'save_external_data' function that allows a local attacker to exploit symlinks when writing external data. This issue arises because the function constructs the file path from the model's external_data location field and opens it wit...
PoC for CVE-2026-19848
The ProfilePress plugin for WordPress, prior to version 4.17.1, is susceptible to a vulnerability that fails to adequately sanitize input in profile fields before rendering. This flaw enables unauthenticated attackers to inject shortcodes, which are executed when the affected profile page is view...
PoC for CVE-2026-18356
The Limit Login Attempts Reloaded plugin for WordPress is susceptible to an authentication bypass due to its failure to perform case-insensitive comparisons on its username denylist. Furthermore, the plugin does not consider the account's associated email address, which allows blocked accounts to...
PoC for CVE-2026-16650
The Charitable WordPress plugin prior to version 1.8.12 contains a critical flaw that allows unauthenticated attackers to forge payment webhook notifications. This occurs due to the plugin's failure to verify the authenticity of incoming Square payment webhooks, enabling attackers to mark donatio...
PoC for CVE-2026-17559
The Passster plugin for WordPress prior to version 4.3.9 contains a flaw that allows unauthenticated attackers to bypass globally set password protections due to improper comparison of REST API endpoint paths. Instead of accurately matching resolved routes, the plugin evaluates paths as unanchore...
PoC for CVE-2026-15150
The myCred plugin for WordPress prior to version 3.2.5 contains a security flaw that allows attackers to manipulate the in-site currency system. Specifically, the plugin fails to validate whether the payment notification received corresponds to a legitimate merchant account configured by the site...
PoC for CVE-2026-15046
The LitExtension WordPress plugin, up to version 1.2.5, is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability. This issue stems from the plugin's failure to verify nonce tokens before allowing administrative actions. An attacker can exploit this oversight by tricking an authenticate...
PoC for CVE-2026-13176
The Eventin WordPress plugin prior to version 4.1.21 has a significant vulnerability where it fails to validate user-provided webhook URLs associated with events. This oversight allows users with contributor-level access or higher to send concealed server-side requests to any external server, pot...
PoC for CVE-2026-77686
A vulnerability exists in Dolibarr versions up to 23.0.4, specifically within the Account Handler component located in htdocs/user/card.php. The issue arises from improper handling of the argument ID, allowing unauthenticated users to gain access to functionalities they should not be permitted to...
PoC for CVE-2026-77683
A security flaw has been identified in the Comfast CF-N1-S, specifically in version 2.6.0.1. The vulnerability affects the /cgi-bin/mbox-config?method=SET§ion=ntp_timezone file, where manipulation of the 'timestr' argument can lead to command injection attacks. This vulnerability can be explo...
PoC for CVE-2026-77681
A vulnerability exists within the CodeAstro Online Job Portal 1.0 that allows attackers to exploit the file '/users/update-profile.php'. This security flaw enables remote attackers to manipulate the 'Name' argument, leading to unrestricted file uploads. The exploitation does not require any speci...
PoC for CVE-2026-19435
The Duplicate Post plugin for WordPress prior to version 1.5.6 has a serious access control flaw that fails to properly verify user capabilities when retrieving post data. This oversight allows users with delegated roles to access sensitive content, including metadata and passwords associated wit...
PoC for CVE-2026-19085
The Duplicate Post plugin for WordPress before version 1.5.6 fails to properly validate user permissions, allowing users with limited roles to duplicate posts that are password-protected. This oversight enables unauthorized users to republish sensitive content without permission, posing a signifi...
PoC for CVE-2026-75796
The AI Engine plugin for WordPress, prior to version 3.6.1, contains a vulnerability that fails to properly validate user permissions for privileged management actions. This allows unauthorized users with Administrator roles on Multisite sub-sites to gain control over any account within the netwo...
PoC for CVE-2026-16959
The Media Library Assistant plugin for WordPress is susceptible to SQL injection due to improper validation of search parameters used in media-library query handlers. This vulnerability enables users with the Author role to inject malicious SQL code into queries, potentially compromising the data...
PoC for CVE-2026-16575
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin for WordPress, prior to version 5.0.14, suffers from an access control vulnerability. This flaw arises from the plugin's failure to adequately restrict access to commission configuration data available through unauthenticat...