Publicly Disclosed
PoC Exploits
đź”´ Alway take caution when working with PoC Exploits đź”´
Discovered 3 hours ago
PoC for CVE-2026-103117
A security vulnerability identified in OS4ED openSIS-Classic affects the 'db_properties' function within the 'DatabaseInc.php' file of the Save Data Handler component. This vulnerability arises from improper handling of argument values, allowing for SQL injection attacks that can be executed remo...
PoC for CVE-2026-103116
A vulnerability has been detected in OS4ED's openSIS-Classic version up to 9.3, specifically in the Student List Search Endpoint's DBQuery function located in functions/GetStuListFnc.php. This issue arises from improper handling of the LO_sort argument, allowing for SQL injection attacks that can...
PoC for CVE-2026-103115
A security vulnerability has been identified in the OS4ED openSIS-Classic application, specifically within the Student Search component's CustomFieldsFnc.php file. This vulnerability allows an attacker to manipulate the cust argument, leading to SQL injection attacks. Such exploits can be execute...
Discovered 4 hours ago
PoC for CVE-2026-96760
Authlib versions 1.7.2 and earlier have a vulnerability in the JsonWebSignature.deserialize_json() method, which improperly validates signatures. This flaw allows for the potential bypass of signature checks, as it accepts a JSON Serialization JWS object and returns the payload as verified, witho...
PoC for CVE-2026-103114
A vulnerability exists in OS4ED openSIS-Classic versions up to 9.3, specifically in the function DBQuery_assignment found in the Assignments.php file within the Assignment Management component. This issue arises from improper handling of user inputs, allowing attackers to manipulate the argument ...
Discovered 5 hours ago
PoC for CVE-2026-48121
The LangGraph.js CheckpointSaver implementation utilizing MongoDB storage is susceptible to a NoSQL injection vulnerability. This issue arises due to the lack of type enforcement when passing checkpoint identifiers from config.configurable into MongoDB queries in the MongoDBSaver.getTuple() metho...
Discovered 10 hours ago
PoC for CVE-2026-96886
The Course Booking System WordPress plugin prior to version 7.0.9 is susceptible to an access control flaw that permits unauthenticated individuals to exploit the booking export feature. This oversight enables them to gain unauthorized access to sensitive user data, including names, email address...
PoC for CVE-2026-97316
The Broken Link Notifier plugin for WordPress versions before 2.0.0.1 is susceptible to a redirect bypass vulnerability. This issue allows unauthenticated attackers to circumvent the plugin's internal-address filter, enabling them to exploit the server's functionality by sending unauthorized requ...
PoC for CVE-2026-92994
The Verge3D Publishing and E-Commerce WordPress plugin prior to version 4.13.1 lacks proper validation for files uploaded via its file storage feature. This allows unauthenticated users to store malicious files that can execute harmful JavaScript in the browsers of users who access them, potentia...
PoC for CVE-2026-92424
The Content Egg plugin for WordPress fails to verify user authorization when using its bulk content-import feature. This oversight allows users with contributor-level access and above to select import presets intended for privileged users, effectively switching the import process to the identity ...
PoC for CVE-2026-93580
The InPost PL WordPress plugin version prior to 1.9.8 is susceptible to a vulnerability where it fails to adequately verify the authenticity of incoming shipment webhook requests. The plugin relies solely on a non-secret identifier and an optional IP check, which can be easily bypassed. This over...
PoC for CVE-2026-94274
The YayReviews plugin for WordPress versions prior to 1.4.1 is susceptible to an API access control vulnerability that allows unauthenticated users to access sensitive data. This vulnerability permits attackers to retrieve individual customer reviews—including those awaiting moderation—along with...
PoC for CVE-2026-94297
The Media Library Organizer plugin for WordPress prior to version 2.1.4 has a significant access control vulnerability. It fails to adequately verify whether a user has the necessary capabilities to manage a target taxonomy when creating new terms. This flaw permits users with contributor access ...
PoC for CVE-2026-91072
The EWWW Image Optimizer plugin for WordPress, specifically versions preceding 8.8.0, allows attackers with Administrator-level privileges to exploit a weakness related to WebP-derivative file management. This vulnerability is significant as it enables unauthorized users to manipulate, rename, or...
PoC for CVE-2026-91832
The WP Mobile Menu plugin for WordPress, prior to version 2.9, lacks proper nonce verification during its settings import. This flaw allows an attacker to perform arbitrary imports of settings within the context of an administrator's session via a cross-site request. Consequently, any imported se...
PoC for CVE-2026-91051
The EWWW Image Optimizer plugin for WordPress, prior to version 8.8.0, allows authenticated users with author-level permissions to insert a serialized value into a post's meta field. Upon rendering, this serialized data is deserialized, which could permit PHP Object Injection. This opens the poss...
PoC for CVE-2026-90953
The Image Optimizer WordPress plugin prior to version 1.7.7 contains an authorization flaw that fails to properly enforce capability checks on multiple read REST routes. This lack of enforcement permits authenticated users to access sensitive attachment metadata and site-wide statistics, which sh...
PoC for CVE-2026-89190
The Robin Image Optimizer plugin for WordPress, prior to version 2.0.8, contains an access control vulnerability that allows subscribers to access admin-only pages. This flaw arises from inadequate checks on user capabilities, enabling unauthorized users to view sensitive settings stored within t...
PoC for CVE-2026-89193
The Robin Image Optimizer plugin for WordPress, prior to version 2.0.8, contains a Cross-Site Scripting (XSS) vulnerability. This occurs due to inadequate escaping of values in its bundled HTML parser when attributes are emitted in certain non-default image delivery modes. As a result, this flaw ...
PoC for CVE-2026-88797
The Vayu X WordPress theme prior to version 1.0.6 contains a critical vulnerability that fails to verify user capabilities on a specific AJAX action. This oversight grants authenticated users, including roles with limited permissions like subscribers, the ability to bypass nonce protections. As a...
PoC for CVE-2026-88791
The Safe Redirect Manager plugin for WordPress prior to version 2.3.0 is susceptible to improper validation of redirect destinations. This vulnerability allows unauthenticated attackers to manipulate redirect rules, potentially redirecting users to malicious external websites when specific wildca...
PoC for CVE-2026-87777
The Hostinger Reach WordPress plugin prior to version 1.8.3 is susceptible to a cross-site scripting vulnerability. This issue arises because the plugin fails to adequately sanitize and escape widget settings before displaying them in the editor preview. As a result, users with contributor-level ...
PoC for CVE-2026-85573
The All in One Files Upload plugin for WordPress prior to version 2.0.17 introduces a significant security risk by permitting SVG files as allowable upload types. This vulnerability arises from the plugin's failure to properly sanitize these uploaded files or to verify the authenticity of public ...
PoC for CVE-2026-85576
The All in One Files Upload plugin for WordPress lacks proper capability checks and fails to authenticate requests when saving settings. This vulnerability allows any authenticated user, regardless of their role, to make unauthorized changes to important settings. This poses a significant risk as...
PoC for CVE-2026-86789
A flaw in the Connections Business Directory plugin for WordPress versions up to 10.4.67 allows unauthenticated users to access sensitive directory entries via specific REST API read endpoints. This includes private or unlisted entries and content pending moderation, such as names, organizations,...
PoC for CVE-2026-82127
The Schema & Structured Data for WP & AMP plugin for WordPress prior to version 1.67 is susceptible to a cross-site scripting vulnerability. The issue lies in the lack of capability checks during the saving of specific fields, alongside insufficient escaping when displaying these fields. This ove...
PoC for CVE-2026-85001
The EmbedPress plugin for WordPress, prior to version 4.6.7, exhibits a security flaw where it fails to properly sanitize and escape an Elementor widget setting. This oversight allows users with Contributor roles or higher to execute arbitrary web scripts through HTML attributes. When affected co...
PoC for CVE-2026-80333
The Solace Extra WordPress plugin, prior to version 1.7.2, lacks essential authorization and post-status checks on its front-end preview routes. This deficiency allows unauthenticated individuals to view the contents of unpublished posts and pages, bypassing restrictions that WordPress typically ...
PoC for CVE-2026-85415
The Audio Player Block plugin for WordPress prior to version 1.6.3 lacks proper validation of user-supplied URLs, allowing contributors and above to introduce malicious JavaScript. When other users engage with such links, their sessions may be compromised, leading to potential exploit risks durin...
PoC for CVE-2026-83560
The New User Approve plugin for WordPress prior to version 3.2.10 exhibits an authentication flaw in its integration REST API routes. When the integration is unconfigured, this vulnerability allows unauthenticated attackers to access sensitive information such as user IDs, usernames, email addres...
PoC for CVE-2026-75873
The Zella Theme for WordPress, prior to version 2.6.3, contains a flaw that allows unauthenticated users to upload files without proper capability or nonce checks. This oversight permits the upload of potentially harmful files, including PHP scripts, which can be exploited for remote code executi...
PoC for CVE-2026-75823
The User Frontend WordPress plugin, versions earlier than 4.3.12, is susceptible to a privilege escalation issue that allows unauthenticated users to manipulate the role assigned during the registration process. This vulnerability enables such users to sign up with elevated privileges, potentiall...
PoC for CVE-2026-75824
The User Frontend plugin for WordPress fails to validate site settings regarding user registration, allowing unauthorized individuals to create accounts even on sites where registration is deliberately disabled. This flaw results in users receiving the default role assigned by the site, potential...
PoC for CVE-2026-100143
The FluentCart plugin for WordPress prior to version 1.6.5 exhibits a security weakness in its guest checkout functionality. Specifically, it fails to validate control over the email address used during the guest checkout process. This oversight allows malicious users who are aware of an existing...
PoC for CVE-2026-87902
An unauthenticated attacker can exploit a vulnerability in WordPress that allows `get_page_template()` to inadvertently resolve and include a chosen local `.php` file located outside of the active theme directories. When specific server conditions and configurations of the active theme are met, t...
Discovered 11 hours ago
PoC for CVE-2026-102913
A vulnerability has been identified in the SourceCodester Car Driving School Management System 1.0, specifically within the '/classes/Master.php?f=save_enrollment' function. This flaw allows attackers to execute SQL injection attacks remotely, which can lead to unauthorized access to sensitive da...
Discovered 12 hours ago
PoC for CVE-2026-102912
A SQL injection vulnerability exists in the SourceCodester Online Leave Management System version 1.0, specifically affecting processing in the /admin/?page=reports file. Malicious manipulation of the date_start and date_end parameters allows an attacker to inject SQL commands, potentially leadin...
PoC for CVE-2023-3776
A use-after-free vulnerability exists within the Linux kernel's net/sched: cls_fw component, where improper handling of reference counts could allow an attacker to manipulate the reference counter, potentially causing a local privilege escalation exploit. If an operation such as tcf_change_indev(...
PoC for CVE-2026-102911
A vulnerability exists in the zosmaai pi-llm-wiki component, specifically within an unknown function of the mcp/index.ts file. This flaw can be exploited to perform OS command injection through manipulation of the 'url' argument, allowing an attacker to execute commands remotely. The issue has be...
PoC for CVE-2026-102910
A security vulnerability has been identified in the SourceCodester Online Reviewer Management System version 1.0, specifically within the /reviewer_0/admins/assessments/examproper/exam-delete.php file. This flaw occurs due to improper handling of user input in the test_id parameter, enabling SQL ...
Discovered 13 hours ago
PoC for CVE-2026-102909
A vulnerability has been identified in the SourceCodester Online Reviewer Management System 1.0, specifically in the file /reviewer_0/admins/assessments/examproper/btn_functions.php. This issue arises from improper handling of the access_code argument, allowing attackers to initiate SQL injection...
PoC for CVE-2026-102908
A security flaw has been identified in the SourceCodester Online Reviewer Management System 1.0, specifically within the file located at /reviewer_0/admins/assessments/examproper/questions-view.php. This vulnerability allows for SQL injection through the manipulation of the argument ID, which can...
PoC for CVE-2026-84383
The vulnerability in libheif, versions prior to 1.23.2, arises from a failure to properly handle crafted HEIF, HEIC, or AVIF item graphs containing nested iden and auxl references. This flaw allows an attacker to trigger a heap out-of-bounds write by exploiting the improper handling of Alpha plan...
PoC for CVE-2026-102906
A vulnerability has been identified in the Git Remove MCP Tool from 0xshariq, where improper handling of arguments in the child_process.exec function can lead to OS command injection. This issue allows remote attackers to execute arbitrary commands on the server by manipulating input parameters. ...
PoC for CVE-2026-102874
A command injection vulnerability has been identified in HKUDS AnyTool 0.1.0, specifically in the 'subprocess.run' function within 'anytool/local_server/main.py'. This vulnerability allows an attacker to manipulate the 'command/shell' argument, leading to remote command execution. The exploit met...
Discovered 14 hours ago
PoC for CVE-2026-102847
A cross site scripting vulnerability has been identified in the gedelumbung HospitalManagement software, specifically within the Guest Book component. This flaw is associated with the manipulation of the parameters 'nama', 'email', and 'pesan' in the 'kirim' function located in the file applicati...
PoC for CVE-2026-102846
A vulnerability has been identified in gedelumbung HospitalManagement that allows for improper authorization via the Configuration Handler. The issue lies within the function sistem.php::simpan, where manipulation of the arguments such as tipe, title, and content_setting can allow unauthorized ac...
PoC for CVE-2026-102261
A security flaw in Owen2345 Camaleon CMS versions up to 2.9.2 has been identified, specifically within the Media Crop Handler component. The issue arises from an improper manipulation of the saved_avatar argument in the crop function located in the media_controller.rb file. This vulnerability may...
PoC for CVE-2026-102845
An information disclosure vulnerability has been identified in the Gedelumbung HospitalManagement product, specifically affecting the error_reporting function in the index.php file related to HTTP Response management. This flaw potentially allows attackers to gain unauthorized access to sensitive...
PoC for CVE-2026-63030
A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...