Publicly Disclosed
PoC Exploits

đź”´ Alway take caution when working with PoC Exploits đź”´

Discovered 3 hours ago

PoC for CVE-2026-78115

SourcecodesterClass And Exam Timetab...5.3MEDIUM
Improper Authorization Vulnerability in SourceCodester Class and Ex...

A security issue has been identified in the SourceCodester Class and Exam Timetabling System version 1.0, specifically within the User Account Update functionality located in /admin/edit_user_account.php. This vulnerability allows attackers to manipulate the 'id' or 'username' parameters, leading...

PoC for CVE-2026-78112

ItsourcecodeHospital Management Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Hospital Management Sys...

A vulnerability has been identified in the itsourcecode Hospital Management System Project in PHP version 1.0, specifically within the /viewservicetype.php file. This weakness allows for SQL injection attacks through the manipulation of the 'delid' argument, potentially exposing sensitive data an...

Discovered 7 hours ago

PoC for CVE-2026-77115

BraveBrave
Reflected XSS Vulnerability in Brave Popup Builder by Brave

The Brave Popup Builder plugin allows for the reflection of UTM query parameters into the popup form HTML without proper escaping. This vulnerability can be exploited by attackers to execute malicious scripts in the context of the user's browser, potentially leading to unauthorized actions or dat...

PoC for CVE-2026-77116

BraveBrave
Access Control Flaw in Brave Popup Builder by Brave

The Brave Popup Builder plugin suffers from a broken access control vulnerability that affects versions up to 0.8.5. This flaw allows any logged-in user, including those with Subscriber or WooCommerce Customer roles, to access popup content by manipulating the post ID in the URL. Such unauthorize...

PoC for CVE-2026-77003

WordPressContent Mask
Improper Capabilities in Content Mask Plugin for WordPress

The Content Mask plugin for WordPress prior to version 1.8.5.5 contains a vulnerability that fails to validate user permissions when creating post types. This oversight permits users with minimal roles, such as Contributor, to publish posts and pages without possessing the required publish capabi...

PoC for CVE-2026-13598

WordPressRestrictmate
Role Restriction Bypass in RestrictMate Plugin Affects WordPress Sites

The RestrictMate plugin for WordPress prior to version 1.3.0 contains a flaw that fails to properly restrict the user role during the account registration process. This oversight permits unauthenticated attackers to create a new account with administrative privileges, enabling them to gain unauth...

PoC for CVE-2026-14853

WordPressWooCommerce Bookings
Improper Access Control in WooCommerce Bookings Plugin by Automattic

The WooCommerce Bookings plugin for WordPress prior to version 3.9.0 contains an improper access control vulnerability. It lacks adequate checks on an AJAX action, enabling users with Subscriber-level roles or higher to create draft bookable products by bypassing the nonce verification process. T...

Discovered 8 hours ago

PoC for CVE-2026-78063

TendaCh225.3MEDIUM
Command Injection Vulnerability in Tenda CH22 Router

A command injection vulnerability exists in the Tenda CH22 router, specifically in the formeditFileName function located in the /goform/editFileName file. This flaw allows an attacker to manipulate the editNameMit argument, enabling the execution of arbitrary commands remotely. The exploit has be...

Discovered 9 hours ago

PoC for CVE-2026-78060

SourcecodesterStock Management System5.3MEDIUM
Cross-Site Scripting Vulnerability in SourceCodester Stock Manageme...

A significant cross-site scripting vulnerability has been detected in the SourceCodester Stock Management System, specifically affecting the file /php_action/getOrderReport.php. This flaw allows attackers to manipulate the parameters clientName and clientContact to inject malicious scripts. The v...

PoC for CVE-2026-78059

SourcecodesterStock Management System5.3MEDIUM
Cross Site Scripting Vulnerability in SourceCodester Stock Manageme...

A cross site scripting vulnerability exists in the SourceCodester Stock Management System v1.0, specifically within the /php_action/printOrder.php file. Attackers can manipulate parameters such as clientName and clientContact, allowing them to inject malicious scripts remotely. This potential exp...

Discovered 10 hours ago

PoC for CVE-2026-78057

SambitrajStudent-management-system5.3MEDIUM
SQL Injection Vulnerability in sambitraj Student-Management System

A vulnerability has been identified in the sambitraj Student-Management System that allows for SQL injection via manipulation of the argument fields including roll_no, name, father_name, class, mobile, email, password, and remark. This flaw could enable remote attackers to execute unauthorized SQ...

PoC for CVE-2026-78056

SambitrajStudent-management-system5.3MEDIUM
SQL Injection Vulnerability in sambitraj Student-Management-System ...

A SQL injection vulnerability exists in the Dashboard component of the sambitraj Student-Management-System. The flaw arises from improper handling of user input via the roll_no or teacher_name arguments, allowing an attacker to execute malicious SQL commands remotely. As this exploit is now publi...

Discovered 12 hours ago

PoC for CVE-2026-78055

SourcecodesterClass And Exam Timetab...5.3MEDIUM
Cross-Site Scripting Vulnerability in SourceCodester Class and Exam...

A cross-site scripting vulnerability has been discovered in the SourceCodester Class and Exam Timetabling System version 1.0. The vulnerability lies in the manipulation of an unspecified argument within the file /BSIT2.php, which allows attackers to execute arbitrary JavaScript in the context of ...

PoC for CVE-2026-78054

SourcecodesterClass And Exam Timetab...5.3MEDIUM
Cross-Site Scripting Vulnerability in SourceCodester Class and Exam...

A security flaw has been detected in the SourceCodester Class and Exam Timetabling System version 1.0. This vulnerability resides in the BSIS1.php file, where an improper handling of the 'course' argument allows for cross-site scripting (XSS) attacks. Malicious users can exploit this weakness rem...

Discovered 13 hours ago

PoC for CVE-2026-78051

Alexta69Metube6.9MEDIUM
Information Disclosure in alexta69 MeTube Cookie File Handler

A vulnerability exists in the alexta69 MeTube application due to an issue in the Cookie File Handler component. This flaw affects the cookies.txt file located at /download/.metube/cookies.txt, which may allow an attacker to gain unauthorized access to files or directories. The potential for explo...

PoC for CVE-2026-78050

ComfastCf-n1-s9.4CRITICAL
Stack-based Buffer Overflow Vulnerability in Comfast CF-N1-S Web Ma...

A stack-based buffer overflow vulnerability has been identified in the Web Management component of Comfast CF-N1-S 2.6.0.1. The issue occurs within the function sub_41AD7C located in the mbox-config endpoint when handling user input parameters such as timestr and ntp_client_enabled. This vulnerab...

PoC for CVE-2026-78122

TecnativaDocker-socket-proxy8.3HIGH
Insufficient Access Control in Docker-Socket-Proxy Exposes Containe...

The docker-socket-proxy has a security flaw that allows unauthorized access to sensitive information through the Docker API. When the CONTAINERS environment variable is set, attackers can exploit this weakness to perform GET requests on specific API endpoints, such as /containers/{id}/logs and /c...

Discovered 14 hours ago

PoC for CVE-2026-78049

SysterelS2opc6.3MEDIUM
Out-of-Bounds Read Vulnerability in Systerel S2OPC Software

A vulnerability exists in the Systerel S2OPC software, particularly affecting the AddNodes Service. The flaw is located in the SOPC_NodeMgtHelperInternal_AddVariableNodeAttributes function, where improper handling of the UserAccessLevel argument can result in an out-of-bounds read. This issue can...

Discovered 1 day ago

PoC for CVE-2026-77988

TrendnetTew-823dru5.1MEDIUM
Command Injection Vulnerability in TRENDnet TEW-823DRU Router

A vulnerability has been found in the TRENDnet TEW-823DRU router's CLI Configuration Tool, specifically within the nvram_get function. This flaw allows for command injection, which can be exploited remotely. The potential for unauthorized access and manipulation of system commands poses significa...

PoC for CVE-2026-77946

TrendnetTew-821dap10CRITICAL
Buffer Overflow Vulnerability in TRENDnet TEW-821DAP NTP Configuration

A vulnerability exists in the TRENDnet TEW-821DAP product version 2.2.01b05, specifically within the uci_safe_get function of the /cgi-bin/apply_time.cgi script related to the NTP Timezone Configuration. An attacker can exploit this vulnerability by manipulating specific arguments, leading to a s...

PoC for CVE-2026-77945

TrendnetTew-821dap5.3MEDIUM
Command Injection Vulnerability in TRENDnet Wireless Access Point

A command injection vulnerability exists in the TRENDnet TEW-821DAP version 2.2.01b05, specifically in the functionality of the /cgi-bin/upload.cgi file related to the ssi component. By manipulating the filename parameter, an attacker can execute arbitrary commands remotely, posing a significant ...

PoC for CVE-2026-77001

WordPressSocial Login & Sharing...
Unauthorized Access in Social Login & Sharing Plugin by SoClever fo...

The Social Login & Sharing buttons with Analytics plugin by SoClever, prior to version 1.2.0, contains a significant security flaw that lacks essential authentication, authorization, and nonce checks in its publicly accessible login handlers. This oversight enables unauthenticated attackers to ex...

PoC for CVE-2026-76793

WordPressFirebase Authentication
Authentication Bypass in Firebase Authentication Plugin for WordPress

The Firebase Authentication plugin for WordPress has a security vulnerability that permits unauthenticated attackers to log in as any user, including those with administrative privileges. This issue arises because the plugin fails to verify the email address in the authentication token prior to m...

PoC for CVE-2026-19222

WordPressForminator Forms
Role Assignment Vulnerability in Forminator Forms Plugin by WordPress

The Forminator Forms plugin for WordPress, prior to version 1.57.0.7, has a security flaw in its role restriction enforcement for registration forms. This vulnerability permits users who are authorized to create forms to set configurations that allow any visitor registering through the form to be...

PoC for CVE-2026-76789

WordPressSlider Hero With Video...
Authorization Flaw in Slider Hero with Video Background, Animation ...

The Slider Hero with Video Background, Animation WordPress plugin prior to version 9.1.3 is susceptible to a critical security flaw that permits unauthenticated users to exploit the plugin's request handlers. This exploit bypasses essential authorization and nonce checks, enabling the injection o...

PoC for CVE-2026-77002

WordPressSmilepass Selfie Login
Authentication Bypass in SmilePass Selfie Login Plugin for WordPress

The SmilePass Selfie Login plugin for WordPress, up to version 1.0.2, is susceptible to an authentication bypass vulnerability. This flaw allows attackers to impersonate any registered user, including administrators, by circumventing the necessary server-side identity verification. Consequently, ...

PoC for CVE-2026-77000

WordPressWP Social Media Login
Improper Authentication in WP Social Media Login Plugin by WordPress

The WP Social Media Login plugin for WordPress, up to version 1.0.6, contains a vulnerability where it fails to properly verify social logins from identity providers. This flaw permits unauthorized users to bypass authentication and log in as any existing user by merely providing the email addres...

PoC for CVE-2026-16738

WordPressConekta Payment Gateway
Web Payment Vulnerability in Conekta Payment Gateway Plugin for Wor...

The Conekta Payment Gateway plugin for WordPress versions prior to 6.2.2 contains a serious security flaw where it fails to authenticate incoming webhook notifications from the payment gateway. This oversight allows attackers to manipulate order statuses by marking any order as paid without prope...

PoC for CVE-2026-19221

WordPressForminator Forms
Code Execution Vulnerability in Forminator Forms Plugin by WordPress

The Forminator Forms plugin for WordPress, prior to version 1.57.0.5, exposes a critical weakness that allows any site administrator within a multisite network to execute arbitrary code. This occurs due to the improper restriction of a network-wide setting, thereby enabling potential malicious ac...

PoC for CVE-2026-16612

WordPressFibosearch
Unauthenticated Data Exposure in FiboSearch Plugin for WordPress

The FiboSearch plugin for WordPress prior to version 1.34.1 allows unauthorized users to access sensitive information on password-protected products through its unauthenticated AJAX endpoints. Specifically, the autocomplete search and details panel endpoints do not enforce adequate authentication...

PoC for CVE-2026-19093

WordPressTutor Lms
File Path Validation Flaw in Tutor LMS Plugin for WordPress

The Tutor LMS WordPress plugin, prior to version 4.0.6, has a significant security issue due to the lack of validation for stored file paths when streaming media. This oversight allows users with instructor permissions to read arbitrary files stored on the server. As a result, sensitive informati...

PoC for CVE-2026-18052

WordPressManageWP Worker
Session Hijacking in ManageWP Worker Plugin for WordPress

The ManageWP Worker plugin for WordPress has a vulnerability that allows attackers to bypass authentication processes. This is due to the plugin failing to bind the account being logged into with the authorization signature, which can lead to session hijacking. If an attacker gains access to a pr...

PoC for CVE-2026-14187

WordPressTutor Lms
Insecure Access Control in Tutor LMS Plugin by WordPress

The Tutor LMS WordPress plugin versions prior to 4.0.6 are susceptible to an insecure access control vulnerability. This flaw allows users with the instructor role to access private course content owned by other instructors. Consequently, an unauthorized user can view sensitive course materials, ...

PoC for CVE-2026-16260

WordPressPost Grid, Slider & Ca...
JavaScript Injection Vulnerability in Post Grid, Slider & Carousel ...

The Post Grid, Slider & Carousel Ultimate plugin for WordPress prior to version 1.8.1 is susceptible to a JavaScript injection vulnerability. This flaw arises from the plugin's failure to properly sanitize and escape specific custom post type settings prior to rendering them in HTML attributes on...

Discovered 2 days ago

PoC for CVE-2026-49114

OnnxOnnx6.8MEDIUM
Symlink Vulnerability in ONNX Affects Data Integrity

In ONNX versions prior to 1.21.0, a vulnerability exists in the 'save_external_data' function that allows a local attacker to exploit symlinks when writing external data. This issue arises because the function constructs the file path from the model's external_data location field and opens it wit...

PoC for CVE-2026-19848

WordPressProfilepress6.5MEDIUM
Shortcode Execution Vulnerability in ProfilePress Plugin for WordPress

The ProfilePress plugin for WordPress, prior to version 4.17.1, is susceptible to a vulnerability that fails to adequately sanitize input in profile fields before rendering. This flaw enables unauthenticated attackers to inject shortcodes, which are executed when the affected profile page is view...

PoC for CVE-2026-18356

WordPressLimit Login Attempts S...3.7LOW
Authentication Bypass in Limit Login Attempts Reloaded Plugin for W...

The Limit Login Attempts Reloaded plugin for WordPress is susceptible to an authentication bypass due to its failure to perform case-insensitive comparisons on its username denylist. Furthermore, the plugin does not consider the account's associated email address, which allows blocked accounts to...

PoC for CVE-2026-16650

WordPressCharitable5.3MEDIUM
Authentication Bypass in Charitable WordPress Plugin by WPChivalry

The Charitable WordPress plugin prior to version 1.8.12 contains a critical flaw that allows unauthenticated attackers to forge payment webhook notifications. This occurs due to the plugin's failure to verify the authenticity of incoming Square payment webhooks, enabling attackers to mark donatio...

PoC for CVE-2026-17559

WordPressPassster5.3MEDIUM
Improper Input Validation in Passster Plugin for WordPress

The Passster plugin for WordPress prior to version 4.3.9 contains a flaw that allows unauthenticated attackers to bypass globally set password protections due to improper comparison of REST API endpoint paths. Instead of accurately matching resolved routes, the plugin evaluates paths as unanchore...

PoC for CVE-2026-15150

WordPressMycred5.3MEDIUM
Payment Processing Vulnerability in myCred Plugin for WordPress

The myCred plugin for WordPress prior to version 3.2.5 contains a security flaw that allows attackers to manipulate the in-site currency system. Specifically, the plugin fails to validate whether the payment notification received corresponds to a legitimate merchant account configured by the site...

PoC for CVE-2026-15046

WordPressLitextension4.2MEDIUM
CSRF Vulnerability in LitExtension Plugin for WordPress

The LitExtension WordPress plugin, up to version 1.2.5, is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability. This issue stems from the plugin's failure to verify nonce tokens before allowing administrative actions. An attacker can exploit this oversight by tricking an authenticate...

PoC for CVE-2026-13176

WordPressEventin2.7LOW
Server-Side Request Forgery in Eventin WordPress Plugin

The Eventin WordPress plugin prior to version 4.1.21 has a significant vulnerability where it fails to validate user-provided webhook URLs associated with events. This oversight allows users with contributor-level access or higher to send concealed server-side requests to any external server, pot...

PoC for CVE-2026-77686

DolibarrDolibarr5.3MEDIUM
Improper Authorization in Dolibarr Account Handler

A vulnerability exists in Dolibarr versions up to 23.0.4, specifically within the Account Handler component located in htdocs/user/card.php. The issue arises from improper handling of the argument ID, allowing unauthenticated users to gain access to functionalities they should not be permitted to...

PoC for CVE-2026-77683

ComfastCf-n1-s9.4CRITICAL
Command Injection Vulnerability in Comfast CF-N1-S Product

A security flaw has been identified in the Comfast CF-N1-S, specifically in version 2.6.0.1. The vulnerability affects the /cgi-bin/mbox-config?method=SET&section=ntp_timezone file, where manipulation of the 'timestr' argument can lead to command injection attacks. This vulnerability can be explo...

PoC for CVE-2026-77681

CodeastroOnline Job Portal5.3MEDIUM
Unrestricted File Upload Vulnerability in CodeAstro Online Job Port...

A vulnerability exists within the CodeAstro Online Job Portal 1.0 that allows attackers to exploit the file '/users/update-profile.php'. This security flaw enables remote attackers to manipulate the 'Name' argument, leading to unrestricted file uploads. The exploitation does not require any speci...

PoC for CVE-2026-19435

WordPressDuplicate Post2.7LOW
Access Control Issue in Duplicate Post WordPress Plugin Exposes Sen...

The Duplicate Post plugin for WordPress prior to version 1.5.6 has a serious access control flaw that fails to properly verify user capabilities when retrieving post data. This oversight allows users with delegated roles to access sensitive content, including metadata and passwords associated wit...

PoC for CVE-2026-19085

WordPressDuplicate Post2.7LOW
User Role Misconfiguration in Duplicate Post Plugin for WordPress

The Duplicate Post plugin for WordPress before version 1.5.6 fails to properly validate user permissions, allowing users with limited roles to duplicate posts that are password-protected. This oversight enables unauthorized users to republish sensitive content without permission, posing a signifi...

PoC for CVE-2026-75796

WordPressAi Engine7.2HIGH
Privilege Escalation Vulnerability in AI Engine WordPress Plugin

The AI Engine plugin for WordPress, prior to version 3.6.1, contains a vulnerability that fails to properly validate user permissions for privileged management actions. This allows unauthorized users with Administrator roles on Multisite sub-sites to gain control over any account within the netwo...

PoC for CVE-2026-16959

WordPressMedia Library Assistant6.8MEDIUM
SQL Injection Vulnerability in Media Library Assistant WordPress Pl...

The Media Library Assistant plugin for WordPress is susceptible to SQL injection due to improper validation of search parameters used in media-library query handlers. This vulnerability enables users with the Author role to inject malicious SQL code into queries, potentially compromising the data...

PoC for CVE-2026-16575

WordPressDokan: Ai Powered WooC...5.3MEDIUM
Access Control Vulnerability in Dokan Multivendor Marketplace Plugi...

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution plugin for WordPress, prior to version 5.0.14, suffers from an access control vulnerability. This flaw arises from the plugin's failure to adequately restrict access to commission configuration data available through unauthenticat...