Publicly Disclosed
PoC Exploits
đź”´ Alway take caution when working with PoC Exploits đź”´
Discovered 4 hours ago
PoC for CVE-2026-24423
SmarterMail versions earlier than build 9511 are susceptible to an unauthenticated remote code execution vulnerability via the ConnectToHub API method. An attacker can exploit this weakness by directing the application to a malicious HTTP server that delivers harmful OS commands, which are then e...
Discovered 5 hours ago
PoC for CVE-2026-84888
A vulnerability has been identified in RightNow-AI OpenFang, specifically affecting the shell_exec function within the tool_runner.rs file. This flaw leads to uncontrolled memory allocation, enabling remote attackers to exploit the system. The vulnerability has been public since its disclosure, a...
PoC for CVE-2026-84887
A denial of service vulnerability exists in the simular-ai Agent-S, specifically linked to the file grounding.py within the Model-generated GUI Action Execution Workflow. This flaw can be exploited remotely, allowing attackers to disrupt service functionality. Publicly available exploit methods i...
PoC for CVE-2026-84886
A resource consumption vulnerability has been identified in simular-ai's Agent-S product, specifically in the OCR HTTP API's ImageData function within the gui_agents/s1/utils/ocr_server.py file. This vulnerability allows an attacker to manipulate the img_bytes argument, potentially leading to sig...
Discovered 6 hours ago
PoC for CVE-2026-84885
A security flaw has been identified in the Agent-S product, specifically located in the code_agent.py file of the CodeAgent component. Exploiting this vulnerability allows attackers to cause a denial of service, potentially disrupting the functionality of the affected system. This issue can be ex...
PoC for CVE-2026-84857
A significant flaw has been identified in the Sigoden Aichat API Endpoint, specifically within the src/serve.rs component. This vulnerability allows for uncontrolled memory allocation, which can be exploited remotely by attackers. The exploit has been publicly disclosed, posing a risk of a Denial...
PoC for CVE-2026-84856
A vulnerability has been identified in Rowboat Labs’ Rowboat, specifically in the Composio Webhook Endpoint. This issue arises from a flaw in the request handling function located in the code that can lead to denial of service. Attackers can exploit this vulnerability remotely, which could disrup...
Discovered 7 hours ago
PoC for CVE-2026-82524
UnoPim, prior to version 2.1.5, suffers from an authenticated file upload vulnerability that allows administrators to upload arbitrary PHP files through the TinyMCE image upload endpoint. This weakness arises from inadequate validation of file extensions and MIME types. As a consequence, attacker...
PoC for CVE-2022-25765
The package pdfkit from 0.0.0 are vulnerable to Command Injection where the URL is not properly sanitized.
PoC for CVE-2026-75134
The SEOWriting plugin for WordPress, up to version 1.12.5, contains a stored cross-site scripting vulnerability. Authenticated contributors can exploit this issue by injecting malicious JavaScript into post content. The vulnerability arises from an overly permissive KSES allowlist that allows the...
PoC for CVE-2026-84852
A vulnerability has been uncovered in the Reader Tools PDF Reader App version 98.8 for Android that allows local attackers to exploit the function ActSplashNew.handleDeeplink. By manipulating the argument _display_name, attackers can execute a path traversal attack, potentially allowing unauthori...
PoC for CVE-2026-84841
A security flaw exists in TSI Coop's TSI-DPDP-CMS software that enables client-side enforcement of server-side security protocols. This vulnerability can be exploited remotely, potentially leading to unauthorized access or manipulation of server-side functionalities. Users are strongly encouraged...
Discovered 8 hours ago
PoC for CVE-2026-84840
A vulnerability affecting TSI Coop's TSI DPDP CMS allows unauthorized access due to missing authentication in the Bootstrap Setup Endpoint component (specifically in the InterceptingFilter.java file). This flaw can be exploited remotely, potentially allowing attackers to manipulate the system wit...
PoC for CVE-2026-84839
A vulnerability exists in the TSI Coop TSI DPDP CMS Admin Console related to the web.xml file that may allow remote attackers to exploit missing authentication functionalities. This flaw could lead to unauthorized access and manipulation of sensitive information through the Admin Console and DPO ...
PoC for CVE-2026-7899
A vulnerability in the V8 JavaScript engine within Google Chrome allows remote attackers to execute arbitrary code within a sandbox environment. This is achieved through an out of bounds read and write technique facilitated by specially crafted HTML content, posing significant security risks to u...
Discovered 9 hours ago
PoC for CVE-2026-84833
A vulnerability exists in ntegrals OpenBrowser, specifically within the Browser Agent Message Construction component. This issue allows attackers to exploit specific functionalities within the agent.ts file, leading to excessive resource consumption. The exploit can be triggered remotely, potenti...
Discovered 10 hours ago
PoC for CVE-2026-9586
An unauthenticated SQL injection vulnerability has been identified in Sangoma Switchvox SMB Edition 8.3. The vulnerability resides in the /pa endpoint, which processes XML content starting with <PolycomIPPhone>. This endpoint improperly concatenates the user-controlled PhoneIP value into PostgreS...
Discovered 12 hours ago
PoC for CVE-2026-2811
The Ajaxify Comments WordPress plugin prior to version 3.2 is susceptible to HTTP Header Injection. This vulnerability arises from inadequate input sanitization and output escaping of data provided by users. As a result, unauthenticated attackers could potentially inject arbitrary HTTP headers, w...
PoC for CVE-2025-9314
The Developer Tools plugin for WordPress versions up to 1.1.3 is susceptible to an unauthenticated arbitrary file upload vulnerability due to a flaw in the bundled SWFUpload component. This security issue allows malicious actors to upload harmful files without proper authentication, which could p...
PoC for CVE-2025-15490
The Passster plugin for WordPress, prior to version 4.2.26, contains a security vulnerability related to inadequate global protection checks. This flaw permits unauthenticated users to bypass intended protection mechanisms through specially crafted URLs, potentially compromising site security and...
PoC for CVE-2025-8945
The Wp Edit Password Protected plugin for WordPress, prior to version 1.3.5, contains a security flaw that enables unauthorized users to bypass content protection measures implemented via the plugin. This vulnerability allows attackers to access restricted page content through the REST API, under...
PoC for CVE-2025-15489
The Passster WordPress plugin prior to version 4.2.24 has a significant input handling issue within its AJAX action operations. This flaw permits unauthenticated users to access and retrieve sensitive information from password-protected content, potentially exposing private data to unauthorized i...
PoC for CVE-2025-15485
The Auto x LINE plugin for WordPress, up to version 1.0.0, contains a critical vulnerability where several REST endpoints lack proper authorization checks. This oversight allows unauthenticated users to interact with the plugin's functionalities, including updating settings and clearing logs, whi...
PoC for CVE-2025-15481
The Notification Bar plugin for WordPress, up to version 1.1.8, has a serious vulnerability that exposes an unauthenticated CSV export script. This script can be exploited by unauthorized users to access and disclose all stored subscriber email addresses, leading to potential privacy breaches and...
PoC for CVE-2024-3773
The LiveJournal Shortcode plugin for WordPress versions up to 1.1.1 is susceptible to Stored Cross-Site Scripting attacks due to improper validation and escaping of shortcode attributes. This flaw enables users with contributor access and higher to inject malicious scripts, which can be executed ...
PoC for CVE-2023-3360
The Weaver Show Posts plugin for WordPress, prior to version 1.8.1, contains a vulnerability that allows for PHP object injection via improperly unserialised content from imported files. This vulnerability can be exploited when a user with elevated privileges imports a malicious file into the blo...
PoC for CVE-2026-83547
The Xpro Addons plugin for WordPress, prior to version 1.7.4, is susceptible to Stored Cross-Site Scripting attacks. This vulnerability arises from the plugin's failure to properly escape certain settings of its widgets before rendering them in HTML attributes. As a result, users with a Contribut...
PoC for CVE-2026-83533
The WP Express Checkout plugin for WordPress versions prior to 2.4.9 is susceptible to a vulnerability that allows unauthorized users to artificially complete orders without making actual payments. This flaw arises due to the plugin's failure to validate whether a payment transaction was genuinel...
PoC for CVE-2026-82884
The All in One SEO plugin for WordPress, prior to version 5.0.0.1, contains a vulnerability where it fails to properly sanitize and escape content stored within posts. This oversight allows users with contributor roles and above to conduct Stored Cross-Site Scripting attacks. The vulnerability is...
PoC for CVE-2026-81571
The Brave WordPress plugin prior to version 0.8.8 contains a vulnerability that allows unauthenticated attackers to exploit URL parameters used to pre-fill form fields. This exploit enables malicious actors to execute arbitrary shortcodes server-side, posing a significant risk to the security and...
PoC for CVE-2026-8151
The Simple Membership MailChimp Integration plugin for WordPress prior to version 1.9.8 lacks essential CSRF checks on its settings page. This deficiency allows attackers to exploit the vulnerability by tricking a logged-in administrator into altering the third-party API key. If successful, the a...
PoC for CVE-2026-78153
The Restrict User Access plugin for WordPress prior to version 2.8.1 is susceptible to an access control bypass vulnerability due to insufficient normalization of the REST API routes. This oversight permits unauthorized users to circumvent content protection measures, granting them the ability to...
PoC for CVE-2026-77794
The RegistrationMagic plugin for WordPress prior to version 6.0.9.9 contains a flaw in its payment processing system. Specifically, it fails to validate user-supplied quantity multipliers during registration, allowing unauthorized users to bypass payment requirements. This vulnerability enables u...
PoC for CVE-2026-77009
The WatchMan-Site7 WordPress plugin, prior to version 4.2.0, fails to adequately restrict access to its debugging console. This oversight permits any authenticated user, including those with minimal roles such as subscriber, to execute arbitrary PHP code on the server. Such vulnerabilities can le...
PoC for CVE-2026-77793
The RegistrationMagic WordPress plugin prior to version 6.0.9.9 is susceptible to a security flaw that permits unauthenticated users to exploit insufficient server-side validation of the total payment price. As a result, these users can finalize a paid registration without completing the payment,...
PoC for CVE-2026-4357
The Embed HTML5 Game WordPress plugin prior to version 1.3 is susceptible to a serious file upload vulnerability. This security flaw allows unauthorized users to upload arbitrary files, including PHP scripts, which can result in the injection of malicious backdoors on the server. The compromised ...
PoC for CVE-2026-2688
The HIPAA FORMS WordPress plugin before version 3.2.0 is vulnerable to an authentication bypass issue. This is achieved through a hardcoded parameter present in all AJAX requests which allows attackers to bypass nonce validation checks on the server. As a result, unauthenticated users can access ...
PoC for CVE-2026-19698
The GutenKit WordPress plugin has a vulnerability that allows users with Contributor roles and above to inject arbitrary CSS into posts. This vulnerability arises from the plugin's failure to validate or sanitize style settings before incorporating them into the CSS rendered on the front end. Whi...
PoC for CVE-2026-17563
The User Frontend plugin for WordPress, prior to version 4.3.11, contains a flaw that fails to enforce subscription requirements during post submissions. As a result, unauthenticated users can exploit this weakness to create and potentially publish posts without proper authorization, enabling the...
PoC for CVE-2026-10821
The Yoast SEO Premium WordPress plugin prior to version 27.6.1 exhibits a security flaw where it fails to properly sanitize control characters from redirect origins before writing to the site's Apache configuration file. This issue arises when file-based redirection is enabled and the redirect-cr...
PoC for CVE-2026-14326
The Timetics WordPress plugin prior to version 1.0.61 contains a vulnerability that allows users assigned a custom staff role to exploit the REST API and gain unauthorized access to appointments. This flaw permits these users to modify, disable, or take control of appointments originally assigned...
PoC for CVE-2025-15692
The Icegram Express plugin for WordPress, prior to version 5.8.6, is vulnerable due to improper escaping of a list description setting. This flaw allows users with Administrator privileges and above to inject malicious scripts, leading to potential stored XSS attacks. When executed, such attacks ...
Discovered 20 hours ago
PoC for CVE-2026-82183
The OAuth Single Sign On plugin for WordPress suffers from a significant flaw in its handling of the Steam single sign-on process. This flaw permits unauthenticated attackers to bypass authentication mechanisms, allowing them to log in as any non-administrator user. Furthermore, the vulnerability...
PoC for CVE-2026-81737
The FAQ Builder AYS WordPress plugin, prior to version 1.8.5, has a vulnerability that permits unauthenticated users to submit content without proper sanitization or escaping. This leads to the potential for Stored Cross-Site Scripting (XSS) attacks, where malicious scripts can be executed in the...
PoC for CVE-2026-81583
The My Login WordPress plugin prior to version 7.2.0 is susceptible to a vulnerability that fails to adhere to the network's registration settings during the sign-up process on multisite installations. This flaw permits users with subscriber accounts and even unauthenticated individuals on certai...
PoC for CVE-2026-81807
The Simple Ajax Chat plugin for WordPress, prior to version 20260827, is susceptible to a cross-site scripting vulnerability. This issue arises because the plugin fails to properly escape chat message content before it is displayed. As a result, an unauthenticated user can inject arbitrary HTML a...
PoC for CVE-2026-82182
The WPvivid Backup, Migration & Staging plugin prior to version 0.9.133 is susceptible to SQL injection due to inadequate sanitization of user-supplied identifiers in a SQL query. This vulnerability could be exploited by malicious users to execute arbitrary SQL commands, potentially compromising ...
PoC for CVE-2026-81432
The JetStyleManager for Gutenberg WordPress plugin is vulnerable to Cross-Site Request Forgery (CSRF) attacks. Specifically, versions prior to 1.3.9 lack adequate CSRF protection on certain AJAX actions. This weakness can be exploited by attackers who can deceive a logged-in user with the edit_po...
PoC for CVE-2026-81428
The WC Vendors plugin for WordPress, prior to version 2.7.2.1, contains a critical oversight that allows authenticated users with vendor roles to manipulate product variations that do not belong to them. By exploiting this flaw, these users can alter the status and title of various posts and prod...
PoC for CVE-2026-81198
The MasterStudy LMS Plugin for WordPress prior to version 3.7.46 contains a vulnerability that allows authenticated users with instructor privileges to manipulate curriculum objects. This flaw occurs due to inadequate verification of ownership, enabling these users to delete or alter course secti...