Publicly Disclosed
PoC Exploits
đź”´ Alway take caution when working with PoC Exploits đź”´
Discovered just now...
PoC for CVE-2026-44011
Craft CMS contains an input-handling flaw that allows authenticated users to manipulate configuration settings and execute arbitrary commands on the server. This vulnerability arises from a flaw in the Yii object creation path, where request-controlled condition fields are incorrectly handled. Du...
PoC for CVE-2026-8712
The Wyoming application prior to version 1.10.2 is vulnerable to a server-side request forgery attack. This vulnerability allows unauthenticated attackers with network access to manipulate the application's outgoing connections by passing malicious `uri` query parameters to the HTTP API. Specific...
Discovered 4 hours ago
PoC for CVE-2025-11201
A vulnerability exists in MLflow Tracking Server that allows remote attackers to exploit improper validation in model file paths. This oversight can lead to directory traversal attacks, enabling malicious users to execute arbitrary code within the context of the service account. Importantly, this...
Discovered 8 hours ago
PoC for CVE-2021-44228
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log messag...
Discovered 9 hours ago
PoC for CVE-2026-82901
The Ultra Addons for Contact Form 7 plugin for WordPress contains a vulnerability that allows unauthorized file uploads due to inadequate validation of file types in the 'uacf7_wpcf7_mail_components' function. This weakness affects all versions up to and including 3.5.50. When exploited, particul...
PoC for CVE-2026-97319
The PowerPress Podcasting plugin, developed by Blubrry, is susceptible to a stored cross-site scripting vulnerability due to inadequate sanitization and escaping of a block attribute before it is rendered on a webpage. This flaw permits users with contributor privileges and higher to inject malic...
PoC for CVE-2026-96899
The Optima Express IDX WordPress plugin versions prior to 8.7.6 are vulnerable due to inadequate sanitization of script values submitted via its REST endpoints. This oversight potentially allows users with even minimal permissions, such as authors, to execute Stored Cross-Site Scripting (XSS) att...
PoC for CVE-2026-96896
The Malcure Malware Shield plugin for WordPress before version 19.9.7 is susceptible to an authorization bypass vulnerability. This flaw allows individuals with a subsite administrator role on a multisite WordPress network to perform AJAX actions without proper authorization checks. As a result, ...
PoC for CVE-2026-97227
The NextScripts: Social Networks Auto-Poster plugin for WordPress, versions before 4.4.8, suffers from improper access control. It fails to implement adequate capability and ownership checks on several AJAX actions, relying solely on a nonce for security. This oversight enables users with adminis...
PoC for CVE-2026-96897
The Optima Express IDX plugin for WordPress prior to version 8.7.6 has a serious issue where it fails to implement authorization checks for certain AJAX actions accessible to users who are not logged in. This could allow unauthorized attackers to create an account with fixed author-role privilege...
PoC for CVE-2026-96895
The WP YouTube Lyte plugin for WordPress, prior to version 1.7.31, contains a vulnerability that fails to properly escape YouTube embed block attributes. This inadequate escaping can lead to the execution of stored Cross-Site Scripting (XSS) attacks by users with minimal privileges, such as contr...
PoC for CVE-2026-89001
The WPeMatico RSS Feed Fetcher plugin for WordPress prior to version 2.8.27 suffers from improper access control. This vulnerability allows users with contributor-level access and above to publish posts without adequate permissions. Users can attribute published content to any registered user, in...
PoC for CVE-2026-92436
The Mailchimp for WooCommerce plugin prior to version 6.3 is susceptible to an authentication bypass vulnerability. This issue arises from the plugin's failure to require proper authentication or verify ownership when loading a saved cart using a request-supplied identifier linked to a customer's...
PoC for CVE-2026-89006
The WPeMatico RSS Feed Fetcher plugin for WordPress prior to version 2.8.27 has a serious oversight in its handling of imported feed content. It fails to properly sanitize this content before it is saved as post content. This flaw permits users with Contributor roles and higher to exploit the vul...
PoC for CVE-2026-92995
The Verge3D Publishing and E-Commerce WordPress plugin prior to version 4.13.0 exhibits improper access control, which allows unauthenticated users to access sensitive file-download handlers. As a result, attackers may exploit this vulnerability to gain unauthorized access to digital goods files ...
PoC for CVE-2026-89003
The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable due to inadequate capability checks when processing user-supplied URLs. This flaw allows users with contributor-level access and higher permissions to manipulate the plugin into making unauthorized requests to internal servers, the...
PoC for CVE-2026-89000
The WPeMatico RSS Feed Fetcher plugin, prior to version 2.8.27, lacks proper capability checks and does not validate the destination of user-supplied feed URLs. This oversight permits users with contributor-level access or higher to generate server-side requests to internal-only resources, potent...
PoC for CVE-2026-86839
The Online Scheduling and Appointment Booking System plugin for WordPress fails to adequately verify the ownership of appointment and payment records during AJAX requests made by staff members. This flaw allows authenticated users with staff-level accounts to access, alter, and delete appointment...
PoC for CVE-2026-86841
The Online Scheduling and Appointment Booking System for WordPress is susceptible to a deserialization issue which can be exploited to inject arbitrary PHP objects. This vulnerability arises from the failure to restrict a privileged maintenance feature, allowing users with a custom booking-manage...
PoC for CVE-2026-86609
The Download Manager Pro plugin for WordPress has a vulnerability that arises from inadequate data sanitization and escaping in its email-locked download subscription form. This flaw allows an unauthenticated attacker to inject malicious scripts, potentially leading to Stored Cross-Site Scripting...
PoC for CVE-2026-85002
The EmbedPress WordPress plugin prior to version 4.6.7 contains a vulnerability that fails to properly escape one of its block attributes when rendering it within an HTML attribute. This oversight can potentially enable user roles of contributor and higher to execute Stored Cross-Site Scripting a...
PoC for CVE-2026-81655
The Ad Inserter plugin for WordPress fails to properly restrict access to one of its settings pages, allowing any logged-in user to access it under certain configurations. Additionally, the plugin lacks adequate content filtering for entries saved within this page, which enables users with minima...
PoC for CVE-2026-84069
The WebFacing™ WordPress plugin prior to version 5.4 is susceptible to a security flaw that allows unauthenticated users to exploit the system via Local File Inclusion. This vulnerability arises from insufficient access restrictions on a bundled script and a failure to validate user-supplied path...
PoC for CVE-2026-82841
The UpdraftPlus: WP Backup & Migration Plugin for WordPress allows authenticated users to exploit a lack of adequate capability checks. In certain post-migration states, stored remote storage settings are exposed on admin pages, enabling unauthorized access to sensitive backup credentials like pa...
PoC for CVE-2026-97161
The UP plugin for Joomla, developed by Lomart, suffers from multiple path traversal and file access vulnerabilities. These vulnerabilities can allow unauthorized access to sensitive files and directories on the server, potentially leading to exploitation of the underlying system. Versions 5.0.0 t...
PoC for CVE-2026-97163
The UP plugin for Joomla, developed by lomart.fr, is susceptible to an unauthenticated remote code installation vulnerability. This allows malicious actors to exploit the plugin versions 5.0.0 through 5.2.0 and 6.0.0 through 6.0.29, potentially leading to unauthorized access and execution of arbi...
Discovered 12 hours ago
PoC for CVE-2026-100746
A flaw has been identified in the GitHub App Setup Handler of Coolify versions up to 4.1.0, where the function Github::redirect fails to enforce proper authentication for the 'state' argument. This weakness enables unauthorized parties to exploit the system remotely, potentially leading to securi...
Discovered 13 hours ago
PoC for CVE-2026-100745
A vulnerability exists in the Edimax BR-6428nC router, specifically within the Wireless Wizard Handler component located at /goform/formWizSurvey. This issue arises from improper handling of the interface1 and interface2 arguments, leading to a stack-based buffer overflow. An attacker could explo...
Discovered 14 hours ago
PoC for CVE-2026-100744
A vulnerability exists in the Coolify application by Coollabsio, specifically related to an authorization issue in the Route-Level Middleware component. This flaw allows an attacker to execute a manipulation that can bypass crucial authorization checks, potentially leading to unauthorized access....
Discovered 15 hours ago
PoC for CVE-2026-61500
The Rejetto HFS versions 3.0.0 to 3.2.0 contain a session forgery vulnerability due to the insecure generation of session-cookie signing keys, derived from the non-cryptographic Math.random() function. This design flaw allows unauthenticated attackers to intercept and analyze login responses. By ...
Discovered 17 hours ago
PoC for CVE-2026-100739
A SQL injection vulnerability was discovered in the viewresult.php file of the mathurvishal CloudClassroom-PHP-Project. By manipulating the 'seno' argument, an attacker can execute unauthorized SQL commands and potentially compromise the database. This vulnerability affects all versions up to com...
PoC for CVE-2026-93485
An improper neutralization of input during web page generation vulnerability in Automattic WordPress core can lead to a DOM-Based XSS attack. This issue arises from the default configuration of WordPress, which allows unauthenticated users to exploit cross-site scripting by bypassing comment mode...
Discovered 18 hours ago
PoC for CVE-2026-29053
Ghost, a popular Node.js content management system, is vulnerable to an attack where specially crafted malicious themes can lead to arbitrary code execution on the server. This vulnerability affects versions 0.7.2 to 6.19.0 and has been addressed in version 6.19.1. Administrators are encouraged t...
Discovered 19 hours ago
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
Discovered 1 day ago
PoC for CVE-2026-43682
A vulnerability has been identified in Apple macOS products that relates to improper memory handling. This flaw allows a remote user to potentially exploit the issue, leading to unexpected system terminations and possible corruption of kernel memory. The flaw has been resolved in macOS Sequoia 15...
PoC for CVE-2026-67279
The RouterOS SSH service is vulnerable due to improper authentication, enabling unauthenticated clients to establish a session channel after a rekey request. This flaw allows attackers to send execution requests without user credentials, leading to unauthorized command execution and potential alt...
PoC for CVE-2026-100312
A security flaw has been identified in the mathurvishal CloudClassroom-PHP-Project, specifically affecting the /updateguest.php file. An unknown function within this file is susceptible to SQL injection due to manipulation of the 'gname/editassid' argument. This vulnerability can be exploited rem...
PoC for CVE-2026-100311
A significant cross-site scripting vulnerability has been detected in the mathurvishal CloudClassroom PHP Project, specifically within the Faculty Video Management component. This vulnerability is caused by improper handling of parameters in the managevideos2.php file, allowing attackers to manip...
PoC for CVE-2026-96532
The Testimonials Widget plugin for WordPress versions up to 4.0.4 is susceptible to an input validation vulnerability that permits unauthorized users to create and modify posts through the front-end testimonial submission form. This flaw arises from the absence of appropriate capability or owners...
PoC for CVE-2026-96531
The Optimole WordPress plugin versions prior to 4.2.13 has a security flaw that allows users with the Author role or higher to insert unescaped event-handler attributes into the video-player block. This occurs because the plugin fails to properly sanitize these attributes prior to rendering. As a...
PoC for CVE-2026-96533
The Testimonials Widget plugin for WordPress, up to version 4.0.4, fails to properly validate URLs supplied by users. This oversight allows unauthenticated individuals to manipulate the server into making requests to internal services and accessing the resulting data. As a result, sensitive infor...
PoC for CVE-2026-96526
The MCP Server for WordPress plugin prior to version 1.8.2 lacks a crucial object-level authorization check for its workflow REST routes. This deficiency enables users with the Contributor role to gain unauthorized access to sensitive information, disclosing titles and publication statuses of pos...
PoC for CVE-2026-92411
The WP Delicious WordPress plugin prior to version 1.10.8 is vulnerable due to improper validation of user-supplied data in recipe blocks. This flaw permits users with Contributor role or higher to inject arbitrary HTML tags, including potentially malicious script tags. As a result, these scripts...
PoC for CVE-2026-85081
The File Manager and FileOrganizer plugins for WordPress feature a vulnerability that fails to validate the origin of window messages on their admin screens. This oversight permits unauthenticated attackers to execute arbitrary JavaScript within the context of a logged-in administrator's session,...
PoC for CVE-2026-96525
The MCP Server plugin for WordPress is susceptible to a permissions bypass vulnerability that allows users with Contributor roles to execute unauthorized actions. Specifically, the plugin fails to properly validate user capabilities when handling REST API requests related to workflow management. ...
PoC for CVE-2026-96524
The MCP Server plugin for WordPress, prior to version 1.8.2, contains an issue where it fails to properly verify the nonce for REST API calls authenticated via cookies under certain conditions manipulated by an attacker. This flaw could potentially be exploited by unauthenticated adversaries who ...
PoC for CVE-2026-84096
The wp-review-slider-pro plugin for WordPress prior to version 12.7.12 contains a security flaw in its AJAX handler, which saves review submission forms. The vulnerability arises due to the lack of a proper capability check, enabling any authenticated user to manipulate live forms. This is furthe...
PoC for CVE-2026-19708
The File Manager plugin for WordPress, versions prior to 8.0.5, is vulnerable due to its inability to restrict unauthenticated users from downloading sensitive database backup archives. This issue can lead to unauthorized access, potentially allowing malicious actors to download complete database...
PoC for CVE-2026-84095
The wp-review-slider-pro plugin for WordPress, in versions prior to 12.7.12, contains a vulnerability whereby an AJAX handler does not adequately check user capabilities. This oversight allows any authenticated user, such as a subscriber, to submit arbitrary review content that can later be displ...
PoC for CVE-2026-84097
The wp-review-slider-pro plugin for WordPress prior to version 12.7.12 fails to properly sanitize user-supplied data in an AJAX handler, which allows authenticated users to execute SQL injection attacks. This vulnerability exposes sensitive database information to unauthenticated visitors, posing...