Publicly Disclosed
PoC Exploits
đź”´ Alway take caution when working with PoC Exploits đź”´
Discovered 3 hours ago
PoC for CVE-2026-108891
JeecgBoot versions up to 3.9.5 contain a significant missing authorization flaw in the SysUserController's getUserDetailByUserId method. This vulnerability permits any authenticated user to access and retrieve sensitive information, including real names, usernames, email addresses, phone numbers,...
PoC for CVE-2026-108888
JeecgBoot version 3.9.5 is impacted by a missing authorization vulnerability within the SysDepartRoleController's exportXls handler. This flaw enables any authenticated user, including those with minimal privileges, to exploit the /sys/sysDepartRole/exportXls endpoint. As a result, they can downl...
PoC for CVE-2026-108886
The JeecgBoot application, up to version 3.9.5, is susceptible to a missing authorization issue within the SysUserController's queryChildrenByUsername function. This vulnerability permits authenticated users to gain unauthorized access to sensitive account records of other users. Attackers can ex...
PoC for CVE-2026-108887
JeecgBoot prior to version 3.9.6 has a vulnerability in its SysCommentController exportXls handler that lacks adequate authorization checks. This deficiency allows any authenticated user to exploit the export functionality to download all comments from the system, including sensitive information ...
PoC for CVE-2026-108885
JeecgBoot version 3.9.5 contains a security flaw in the SysMessageController's delete handler, allowing authenticated users with low privileges to execute DELETE requests without proper ownership checks. This vulnerability enables attackers to delete any message records by sending requests with a...
PoC for CVE-2026-108884
JeecgBoot version 3.9.5 contains a vulnerability in the SysMessageTemplateController delete handler. This flaw allows any authenticated user to delete message templates due to missing authorization checks. Low-privileged attackers can exploit an unprotected endpoint to obtain template IDs, subseq...
PoC for CVE-2026-108882
The JeecgBoot product version 3.9.5 contains a vulnerability in the SysPositionController that allows authenticated users to exploit a missing authorization check. This flaw enables low-privileged attackers to execute DELETE requests with arbitrary user IDs and position IDs, leading to unauthoriz...
PoC for CVE-2026-108883
JeecgBoot version 3.9.5 is affected by a missing authorization vulnerability in the editThirdAppConfig handler. This flaw allows any authenticated user, including those with low privileges, to modify critical configurations of third-party applications. Specifically, unauthorized users can alter c...
PoC for CVE-2026-108881
The JeecgBoot application version 3.9.5 has a missing authorization vulnerability within the getTenantPackInfo handler. This flaw permits any authenticated user to access and read product pack membership information for other tenants. By manipulating parameters such as tenantId and predefined pac...
PoC for CVE-2026-108880
JeecgBoot versions up to 3.9.5 exhibit a serious missing authorization issue in the PUT /sys/dict/editDictByLowAppId endpoint. This flaw allows any authenticated user to alter application dictionaries by leveraging the low_app_id, which can be retrieved from the GET /sys/dict/list API endpoint. A...
PoC for CVE-2026-108879
The JeecgBoot application, specifically versions up to 3.9.5, is susceptible to an insecure direct object reference (IDOR) vulnerability in the AiragBaseApiController. This flaw allows authenticated users to access other users' AI chat variables by manipulating the username parameter when making ...
PoC for CVE-2026-108878
A missing authorization vulnerability in JeecgBoot versions prior to 3.9.5 allows low-privileged authenticated users to access sensitive AI application configurations. Exploitation of this vulnerability occurs through the unprotected /airag/app/listDict endpoint, allowing attackers to enumerate a...
PoC for CVE-2026-108877
JeecgBoot version 3.9.5 has a vulnerability in the AiragPromptsController that allows authenticated users to delete AI prompt templates without proper authorization. By leveraging the unprotected GET /airag/prompts/list endpoint, low-privileged attackers can retrieve template IDs and subsequently...
PoC for CVE-2026-108876
JeecgBoot, up to version 3.9.5, has a vulnerability in the putCancelQuit handler of SysUserController, allowing authenticated users to bypass authorization controls. This flaw enables low-privileged attackers to cancel user resignations by supplying user IDs and tenant parameters, effectively res...
PoC for CVE-2026-108875
JeecgBoot, up to version 3.9.5, is susceptible to a missing authorization vulnerability within the SysUserController's addSysUserGroup handler. This flaw allows any authenticated user to manipulate user group memberships without proper permission checks. By sending crafted POST requests that incl...
PoC for CVE-2026-108874
The JeecgBoot application, specifically in version 3.9.5, has a flaw where limited privilege authenticated users can manipulate user roles related to department management. By exploiting the PUT method on the endpoint /sys/user/changeDepartChargePerson, attackers can gain the ability to appoint o...
PoC for CVE-2026-108873
JeecgBoot version 3.9.5 is affected by a vulnerability that allows low-privileged authenticated users to perform unauthorized modifications to department data. By exploiting a flaw in the system, these users can call the PUT endpoint /sys/user/doUpdateDepartInfo, enabling them to change departmen...
PoC for CVE-2026-108871
JeecgBoot 3.9.5 is vulnerable due to a missing authorization check in the saveDatarule handler of the SysDepartRoleController. This flaw permits low-privileged authenticated users to send crafted request parameters such as permissionId, roleId, and dataRuleIds, which may allow them to overwrite d...
PoC for CVE-2026-108872
JeecgBoot version 3.9.5 contains a vulnerability in the batchEditUsers handler within the SysUserController. This issue allows any authenticated user, including those with low privileges, to execute unauthorized edits on user department assignments. By sending crafted PUT requests to the /sys/use...
PoC for CVE-2026-108870
JeecgBoot version 3.9.5 contains a vulnerability within the SysRoleController's saveDatarule handler. This flaw enables low-privileged authenticated users to alter role data rules without proper authorization. Attackers can exploit this by sending specific parameters such as permissionId, roleId,...
PoC for CVE-2026-108868
JeecgBoot versions up to 3.9.5 are impacted by a missing authorization vulnerability, allowing authenticated users to exploit POST requests to the /sys/api/sendBusTemplateAnnouncement endpoint. This oversight enables low-privileged attackers to send templated system announcements to arbitrary use...
PoC for CVE-2026-108869
JeecgBoot before version 3.9.5 contains a missing authorization vulnerability that enables low-privileged authenticated users to send arbitrary system announcements. By exploiting this flaw, attackers can manipulate the announcement parameters—such as title, content, fromUser, and toUser—allowing...
PoC for CVE-2026-108867
JeecgBoot, up to version 3.9.5, has a flaw in the SystemApiController's getUserRoleSetById function, which permits any authenticated user to access other users' role assignments without proper authorization. This issue arises from improper access controls, allowing low-privileged users to supply ...
PoC for CVE-2026-108866
JeecgBoot versions up to 3.9.5 are susceptible to a missing authorization vulnerability that permits authenticated users to access another user's permissions. By exploiting this flaw, low-privileged attackers can manipulate the 'userId' parameter in the queryUserAuths handler, enabling them to ex...
PoC for CVE-2026-108683
A security vulnerability exists in zhayujie CowAgent versions up to 2.1.9, specifically within the Media Download Handler component. This flaw allows for uncontrolled memory allocation, potentially leading to a denial of service. The issue can be exploited remotely, making it crucial for users to...
PoC for CVE-2026-108682
A vulnerability has been discovered in the zhayujie CowAgent, specifically in versions up to 2.1.6. This weakness resides in the Web Console's upload function, which can be exploited to facilitate a Denial of Service (DoS) attack. Attackers can execute this manipulation remotely, leading to servi...
Discovered 4 hours ago
PoC for CVE-2026-108681
A vulnerability has been found in zhayujie CowAgent that impacts the Web Console component, specifically in the web_channel.py file. This security flaw allows attackers to manipulate the session_id argument, leading to a denial-of-service condition. Attackers can exploit this vulnerability remote...
Discovered 5 hours ago
PoC for CVE-2026-43805
A race condition vulnerability has been identified in Apple iOS and macOS products, where improper state handling could lead to unexpected system terminations or allow an app to write unauthorized kernel memory. This flaw has been addressed in recent updates across various Apple platforms, includ...
PoC for CVE-2026-108584
A security flaw has been identified in FunnyWolf Viper versions up to 3.1.11, stemming from a vulnerable function within the file /root/viper/.git/config. This vulnerability allows attackers to exploit hard-coded credentials, thereby opening a pathway for remote exploitation. With the exploit now...
Discovered 9 hours ago
PoC for CVE-2026-102428
An unauthenticated SQL injection vulnerability exists in the OrdaSoft Joomla CCK, where the order column for records is derived from user input and is not adequately validated. This oversight allows attackers to manipulate SQL queries, potentially compromising database integrity and exposing sens...
PoC for CVE-2026-108592
The mini-swe-agent versions 1.10.0 through 2.4.6 are vulnerable due to an information exposure flaw in the BubblewrapEnvironment. This vulnerability arises because the command bwrap fails to clear the environment variables with the --clearenv option, allowing sandboxed commands to unintentionally...
Discovered 10 hours ago
PoC for CVE-2026-108543
A vulnerability exists in the ag2ai product, specifically within the UserProxyAgent component, affecting versions up to 0.13.4. This issue arises from improper handling of the filename argument in the os.path.join function, allowing for a path traversal attack. Such an exploit enables unauthorize...
PoC for CVE-2026-108542
A vulnerability exists in the 021is elvix-sdk up to version 0.10.1, specifically in the MCP Request Handler component. This issue stems from improper handling of the argument path in the src/mcp/index.ts file. An attacker can exploit this vulnerability to perform server-side request forgery (SSRF...
Discovered 12 hours ago
PoC for CVE-2026-97183
The WP-Invoice plugin for WordPress prior to version 4.3.1 contains significant access control weaknesses in its AJAX handlers. These vulnerabilities enable any authenticated user, including those with minimal permissions like Subscribers, to access sensitive information. This includes email addr...
PoC for CVE-2026-91829
The Subscribe to Comments WordPress plugin prior to version 2.3.3 is vulnerable to reflected cross-site scripting due to inadequate parameter validation. This flaw allows an unauthenticated attacker to craft a malicious URL that, when clicked by a user, including administrators, can lead to the e...
PoC for CVE-2026-93550
The Veeqo for WooCommerce plugin version 2.2.8 is vulnerable to remote code execution due to inadequate restrictions on the remote bridge-installation process. It does not validate the URLs provided, allowing users with basic Subscriber-level permissions and above to initiate the download and ext...
PoC for CVE-2026-96227
The Piotnet Forms WordPress plugin, versions up to 1.0.30, has a critical flaw that allows unvalidated file uploads. This vulnerability enables malicious users to upload files that can execute arbitrary JavaScript code within the site's domain when accessed. As a result, this stored XSS issue pos...
PoC for CVE-2026-89287
The ASPL Product Quotation WordPress plugin, up to version 1.1.0, is susceptible to SQL injection due to inadequate sanitization and escaping of user inputs. This vulnerability enables unauthenticated attackers to manipulate SQL queries, potentially gaining unauthorized access to sensitive data s...
PoC for CVE-2026-89304
The Paymendo WordPress plugin version 1.1 is susceptible to a SQL injection vulnerability due to improper sanitization and escaping of user-supplied parameters. This weakness enables unauthorized users to execute blind SQL injection attacks, potentially compromising the integrity and confidential...
PoC for CVE-2026-89299
The WP Verify API plugin for WordPress, up to version 1.0.0, has a security flaw that arises from improper sanitization and escaping of user-supplied parameters in SQL queries. This vulnerability can be exploited by unauthenticated users, allowing them to execute arbitrary SQL code, potentially c...
PoC for CVE-2026-89305
The Paymendo WordPress plugin prior to version 1.1 is vulnerable due to inadequate sanitization and escaping of user input in SQL queries. This flaw permits authenticated users to manipulate queries, potentially leading to unauthorized access to or manipulation of the database. Such vulnerabiliti...
PoC for CVE-2026-89302
The Post Voting System plugin for WordPress, up to version 1.0, has a vulnerability stemming from improper sanitization and escaping of user-supplied parameters in SQL queries. This flaw allows unauthenticated attackers to execute arbitrary SQL code, potentially leading to unauthorized access and...
PoC for CVE-2026-89297
The Loja Automática plugin for WordPress, up to version 1.0.0, is susceptible to SQL injection attacks due to inadequate sanitization and escaping of input parameters before their use in SQL queries. This vulnerability permits unauthorized users to manipulate database queries, potentially leading...
PoC for CVE-2026-89213
The Llavero.io WordPress plugin prior to version 0.1.4 is susceptible to SQL injection due to insufficient sanitization and escaping of user-supplied parameters in SQL statements. This vulnerability enables unauthenticated attackers to execute malicious SQL queries, potentially leading to unautho...
PoC for CVE-2026-89214
The WpCues Basic Quiz plugin for WordPress, up to version 1.6.5, is susceptible to SQL injection due to inadequate sanitization and escaping of user inputs in SQL statements. This vulnerability permits unauthorized attackers to execute malicious SQL queries, potentially leading to unauthorized da...
PoC for CVE-2026-89285
The Datalist plugin for WordPress (version 0.0.3 and earlier) is vulnerable due to improper sanitization and escaping of request parameters used in SQL queries. This flaw allows unauthenticated attackers to execute SQL injection attacks, potentially leading to unauthorized access to sensitive dat...
PoC for CVE-2026-89283
The WP Posts Password Batch Manager plugin for WordPress versions up to 1.1 contains a significant flaw that allows attackers to exploit its bulk post-password feature. The plugin lacks essential capability and nonce checks, enabling unauthenticated users to reset or overwrite the passwords of al...
PoC for CVE-2026-89232
The Recordbrowser plugin for WordPress, up to version 1.1.7, exposes a critical vulnerability due to improper sanitization and escaping of parameters in SQL queries. This flaw permits unauthenticated attackers to manipulate SQL statements, potentially allowing them to execute arbitrary commands a...
PoC for CVE-2026-89234
The WP-Partner plugin for WordPress versions up to 1.2.1 has a vulnerability that allows unauthenticated attackers to inject additional SQL queries. This flaw occurs due to improper sanitization and escaping of a parameter before executing it in a SQL query. As a result, an attacker could extract...
PoC for CVE-2026-108540
A vulnerability has been identified in the File Transfer component of OpenSpug, specifically affecting versions 3.4.0 and 4.0.1. This flaw allows remote execution of unauthorized OS commands through the manipulation of the /exec/transfer file. Due to the nature of the exploit, attackers can poten...