Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 3 hours ago

PoC for CVE-2026-96962

WordPressPie Register
Access Control Vulnerability in Pie Register WordPress Plugin

The Pie Register plugin for WordPress prior to version 3.8.4.14 has a significant access control vulnerability that leaves user data exposed. Specifically, this flaw allows unauthenticated users who possess a valid invitation code to access a report containing the usernames and email addresses of...

PoC for CVE-2026-89236

WordPressSaveto Wishlist Lite
SQL Injection Vulnerability in SaveTo Wishlist Lite Plugin by WordP...

The SaveTo Wishlist Lite plugin for WordPress prior to version 1.1.5 contains a security vulnerability that allows unauthenticated attackers to inject malicious SQL code through unsanitized parameters in the ORDER BY clause. This flaw permits attackers to execute arbitrary SQL queries, leading to...

PoC for CVE-2026-94239

WordPressLoco Translate
Stored Cross-Site Scripting Vulnerability in Loco Translate Plugin ...

The Loco Translate WordPress plugin, prior to version 2.8.9, contains a vulnerability that fails to properly sanitize and escape certain bundle configuration values before rendering them in an admin interface. This oversight allows users with translator capabilities and higher to exploit the vuln...

PoC for CVE-2026-92437

WordPressMailchimp For WooCommerce
Improper Authentication Vulnerability in Mailchimp for WooCommerce ...

The Mailchimp for WooCommerce plugin prior to version 6.3 contains a vulnerability that permits unauthenticated attackers to manipulate or remove another user's abandoned cart records. This exploit occurs due to the lack of necessary authentication, nonce verification, or ownership checks when ha...

PoC for CVE-2026-92923

WordPressUnlimited Elements For...
SQL Injection Vulnerability in Unlimited Elements for Elementor Plu...

The Unlimited Elements for Elementor plugin for WordPress prior to version 2.0.21 contains a vulnerability that allows users with minimal privileges (as low as a subscriber) to execute blind SQL injection attacks. This flaw arises from inadequate sanitization and escaping of parameters used in SQ...

PoC for CVE-2026-94238

WordPressLoco Translate
File Path Exposure in Loco Translate Plugin for WordPress

The Loco Translate plugin for WordPress, prior to version 2.8.9, contains a vulnerability that permits users with translator capabilities to access and read sensitive files from arbitrary paths on the server. This flaw allows unauthorized access to information outside the intended web root, poten...

PoC for CVE-2026-91078

WordPressTillkit
Authentication Bypass in TillKit WordPress Plugin by TillKit

The TillKit WordPress plugin, prior to version 1.0.5, creates a privileged POS account with a hard-coded PIN known publicly. This design flaw permits unauthenticated attackers to exploit the public POS login endpoint, gaining access to a privileged POS session without undergoing necessary identit...

PoC for CVE-2026-88783

WordPressKubio Ai Page Builder
HTML Injection Vulnerability in Kubio AI Page Builder by WordPress

The Kubio AI Page Builder plugin for WordPress before version 2.9.3 is susceptible to an HTML injection vulnerability. This flaw arises because the plugin fails to restrict the allowed HTML elements strictly to the editor context. Consequently, when unauthenticated users submit content, the plugi...

PoC for CVE-2026-86834

WordPressMetform
Unauthorized Access in MetForm WordPress Plugin Allows Data Exposure

The MetForm WordPress plugin prior to version 4.3.1 contains a security flaw that fails to sufficiently restrict access to a debug file created in the web root during form submissions, especially when the HubSpot Forms integration is active. This oversight permits unauthorized attackers to retrie...

PoC for CVE-2026-88782

WordPressKubio Ai Page Builder
Improper URI Validation in Kubio AI Page Builder for WordPress

The Kubio AI Page Builder plugin for WordPress versions prior to 2.9.3 is vulnerable due to improper validation of the URI scheme for user-supplied values. This allows users with roles of contributor and above to store payloads that can be executed in the browsers of anyone who interacts with the...

PoC for CVE-2026-86832

WordPressMetform
Access Control Flaw in MetForm WordPress Plugin by WPMet

The MetForm WordPress plugin, prior to version 4.3.1, contains a security flaw that fails to adequately restrict access to form submission data. This vulnerability allows unauthenticated attackers to exploit the REST API, potentially revealing sensitive user information submitted through the form...

PoC for CVE-2026-103514

WordPressWP 2fa
Bypass of Two-Factor Authentication in WP 2FA Plugin by WordPress

The WP 2FA plugin for WordPress prior to version 4.1.0 allows for a critical security issue where a time-based one-time passcode (TOTP) remains valid even after being used. This flaw enables an attacker with knowledge of a user's password and access to a valid TOTP within its active period to rep...

PoC for CVE-2026-85568

WordPressUnlimited Elements For...
SQL Injection Vulnerability in Unlimited Elements for Elementor Plu...

The Unlimited Elements for Elementor plugin prior to version 2.0.21 is susceptible to an SQL injection vulnerability. This issue stems from an improper handling of search values, which allows unauthenticated users to manipulate SQL statements. If certain widget options are set to values other tha...

PoC for CVE-2026-80517

WordPressWP Ultimate Csv Importer
Stored Cross-Site Scripting Vulnerability in WP Ultimate CSV Import...

The WP Ultimate CSV Importer plugin for WordPress prior to version 9.2 features a significant security flaw. This vulnerability arises from inadequate validation of file types within uploaded archives, coupled with a failure to sanitize their content before storing them in publicly accessible dir...

PoC for CVE-2026-80518

WordPressWP Ultimate Csv Importer
Insecure File Access in WP Ultimate CSV Importer Plugin

The WP Ultimate CSV Importer plugin for WordPress, prior to version 9.2, presents a security risk by failing to implement a site-specific secret to manage the storage of import logs. This oversight allows unauthenticated attackers to access sensitive user data stored in these logs, which are loca...

PoC for CVE-2026-85015

WordPressUnlimited Elements For...
File Path Vulnerability in Unlimited Elements for Elementor WordPre...

The Unlimited Elements for Elementor plugin prior to version 2.0.21 has a significant flaw where it fails to properly sanitize file paths contained within uploaded archives. This oversight permits authenticated users, typically Administrators or Editors under certain configurations, to exploit th...

PoC for CVE-2026-101160

WordPressWP Ultimate Review
Numeric Input Validation Flaw in WP Ultimate Review Plugin by WordP...

The WP Ultimate Review WordPress plugin, prior to version 2.4.4, contains a significant input validation vulnerability. It fails to ensure that user-submitted review ratings are numeric before processing them. This oversight allows unauthenticated users to submit malicious input, potentially caus...

PoC for CVE-2026-101162

WordPressWP Ultimate Review
Stored Cross-Site Scripting Vulnerability in WP Ultimate Review Plugin

The WP Ultimate Review plugin for WordPress prior to version 2.4.4 is vulnerable due to inadequate escaping of review overview settings. This flaw allows users with author permissions to potentially execute stored cross-site scripting attacks, especially when author reviews are enabled. Attackers...

PoC for CVE-2026-103293

WordPressMpg
Remote File Inclusion in MPG WordPress Plugin by MPG

The MPG WordPress plugin, in versions before 4.2.3, contains a vulnerability where it fails to validate the source of a dataset provided during the import process. Specifically, it allows users with Editor roles and above to manipulate file imports, treating remote URLs as local file paths. This ...

PoC for CVE-2026-101159

WordPressWP Ultimate Review
Stored Cross-Site Scripting Vulnerability in WP Ultimate Review Plu...

The WP Ultimate Review plugin for WordPress, prior to version 2.4.4, fails to adequately sanitize and escape user-generated reviews submitted via its public review form, which is accessible to unauthenticated users. This oversight allows potential attackers to execute stored Cross-Site Scripting ...

PoC for CVE-2026-101161

WordPressWP Ultimate Review
Persistent Denial of Service in WP Ultimate Review Plugin by WordPress

The WP Ultimate Review plugin for WordPress, prior to version 2.4.4, is susceptible to exploitation by unauthenticated users. These attackers can submit specially crafted review content that causes the website to generate a fatal error upon each visit. This leads to a persistent denial of service...

Discovered 6 hours ago

PoC for CVE-2026-43284

LinuxLinux8.8HIGH
Vulnerability in Linux Kernel Affects Shared skb Fragments

A vulnerability exists in the Linux kernel that concerns the handling of shared skb fragments during the decryption process in ESP-in-UDP packets. When pages are attached from a pipe directly to an skb using MSG_SPLICE_PAGES, the kernel marked these SKBs with SKBFL_SHARED_FRAG, which plays a cruc...

Discovered 8 hours ago

PoC for CVE-2026-4480

Red HatRed Hat Enterprise Lin...🟣 EPSS 14%9CRITICAL
Samba Printing Subsystem Vulnerability in Samba Software

A vulnerability exists in the Samba printing subsystem that allows remote attackers to execute arbitrary commands on affected systems. The flaw occurs due to improper handling of the client-controlled job description string, which is passed directly to the configured print command without escapin...

Discovered 9 hours ago

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

Discovered 10 hours ago

PoC for CVE-2026-55559

YamcsYamcs9.8CRITICAL
Yamcs Mission Control Framework Vulnerability in Service Account Ex...

The Yamcs Mission Control Framework is exposed to a vulnerability where template arguments from POST and PATCH requests can be inserted into YAML without proper context escaping. This flaw exists in versions preceding 5.12.8 and 5.13.2. An attacker can exploit this vulnerability to inject malicio...

PoC for CVE-2026-40281

GotenbergGotenberg10CRITICAL
Injection Vulnerability in Gotenberg PDF Processing API

The Gotenberg PDF API, a Docker-based tool for PDF file processing, has a significant vulnerability affecting versions 8.30.1 and earlier. It allows unauthenticated attackers to exploit the metadata write endpoint, which inadequately sanitizes metadata values. By including a newline character in ...

PoC for CVE-2025-45737

NetEaseNeacSafe64 Driver6.5MEDIUM
Privilege Escalation Vulnerability in NeacSafe64 Driver by NetEase

A vulnerability exists in the NeacSafe64 Driver developed by NetEase, allowing attackers to gain elevated privileges. By crafting and sending specific IOCTL commands to the NeacSafe64.sys component, adversaries can exploit this weakness to manipulate system operations and gain unauthorized access...

Discovered 11 hours ago

PoC for CVE-2012-1823

PHPPHP🟣 EPSS 100%9.8CRITICAL
Remote Code Execution Vulnerability in PHP CGI Configuration

This vulnerability in PHP occurs when the software is configured to run as a CGI script. Specifically, when the query string lacks an equals sign, PHP fails to handle it appropriately, which can lead to remote attackers executing arbitrary code. This occurs due to insufficient validation of comma...

Discovered 15 hours ago

PoC for CVE-2014-125130

WordPressCodeart Google Mp3 Aud...8.7HIGH
Unauthenticated File Read Vulnerability in CodeArt Google MP3 Audio...

The CodeArt Google MP3 Audio Player plugin for WordPress, up to version 1.0.11, is susceptible to an unauthenticated arbitrary file read vulnerability. This weakness allows remote attackers to exploit path traversal flaws in the direct_download.php file parameter, enabling them to access sensitiv...

PoC for CVE-2026-19856

WordPressAll In One Seo6.5MEDIUM
Security Flaw in All in One SEO WordPress Plugin Allows Unauthorize...

The All in One SEO plugin for WordPress versions prior to 5.0.2.1 contains a significant security flaw that fails to properly identify shortcodes in user-generated content. This oversight permits unauthenticated users to execute arbitrary shortcodes that are registered on any affected site. Addit...

Discovered 18 hours ago

PoC for CVE-2026-104638

OnetwothreenethHospitalmanagementsystem6.9MEDIUM
Improper Authentication in onetwothreeneth HospitalManagementSystem

A security vulnerability has been identified in the onetwothreeneth HospitalManagementSystem, specifically within the php/sessions.php file. The vulnerability arises from improper handling of the ID argument, allowing for potential unauthorized access. This flaw enables remote attackers to exploi...

PoC for CVE-2026-19660

WordPressDivi Membership9.8CRITICAL
Authentication Bypass Vulnerability in Divi Membership Plugin for W...

The Divi Membership plugin for WordPress has a critical vulnerability that allows unauthenticated attackers to bypass authentication processes, enabling them to log in as any existing user, including administrators. This issue arises from a flaw in how the `process_paypal_callback` function handl...

Discovered 19 hours ago

PoC for CVE-2026-104637

OnetwothreenethHospitalmanagementsystem6.9MEDIUM
Unrestricted Upload Vulnerability in onetwothreeneth HospitalManage...

A vulnerability has been identified in the onetwothreeneth HospitalManagementSystem, where the functions responsible for managing patient and physician data suffer from an unrestricted file upload issue. This weakness resides in the php/controller.php file, particularly within the functions add_p...

PoC for CVE-2026-104625

CodeastroSimple Loan Management...5.3MEDIUM
SQL Injection Vulnerability in CodeAstro Simple Loan Management System

A security flaw has been identified in the CodeAstro Simple Loan Management System version 1.0, specifically within an unidentified function in the /admin/index.php file. This vulnerability allows attackers to carry out SQL injection attacks by manipulating the 'g_name' argument, potentially lead...

PoC for CVE-2026-104614

CodeastroSimple Pharmacy Manage...5.3MEDIUM
SQL Injection Vulnerability in CodeAstro Simple Pharmacy Management...

An SQL injection vulnerability has been identified in the CodeAstro Simple Pharmacy Management System version 1.0. This vulnerability arises from improper handling of the ID parameter in the file /SimplePharmacy-PHP/product/delete.php, which allows remote attackers to manipulate the SQL query exe...

Discovered 20 hours ago

PoC for CVE-2026-104613

CodeastroSimple Pharmacy Manage...5.3MEDIUM
SQL Injection Vulnerability in CodeAstro Simple Pharmacy Management...

The Simple Pharmacy Management System by CodeAstro, version 1.0, contains a vulnerability that can be exploited through an SQL injection attack via the view.php file. This vulnerability allows an attacker to manipulate the ID argument, potentially leading to unauthorized access to sensitive data....

Discovered 21 hours ago

PoC for CVE-2026-104612

SourcecodesterStudent Result Managem...5.3MEDIUM
Cross Site Scripting Vulnerability in SourceCodester Student Result...

A vulnerability exists in the SourceCodester Student Result Management System version 1.0, specifically within the Announcement Module's new_announcement.php file. This weakness allows remote attackers to execute cross site scripting (XSS) attacks by manipulating the 'title' or 'announcement' arg...

PoC for CVE-2026-104611

TendaAc99.4CRITICAL
Stack-based Buffer Overflow in Tenda AC9 Router

A vulnerability exists in the Tenda AC9 router, specifically in the POST Request Handler component found at /goform/fast_setting_internet_set. This vulnerability arises when an attacker manipulates the netWanType argument, leading to a stack-based buffer overflow. The exploit can be executed remo...

PoC for CVE-2026-104610

TendaHg710CRITICAL
Stack-Based Buffer Overflow in Tenda HG Series

A critical security vulnerability exists in Tenda's HG7, HG9, and HG10 routers, specifically within the function boaGetVar of the Boa Web Server component. This vulnerability allows an attacker to manipulate the Ethtype argument, resulting in a stack-based buffer overflow. The nature of this vuln...

Discovered 22 hours ago

PoC for CVE-2026-104609

OnetwothreenethHospitalmanagementsystem6.9MEDIUM
SQL Injection Vulnerability in onetwothreeneth HospitalManagementSy...

A critical security weakness has been detected in the onetwothreeneth HospitalManagementSystem affecting the edit_accounts.php file's get function. This flaw occurs due to improper handling of query parameters such as user_id, patient_id, physician_id, discounts_id, and services_id, which allows ...

Discovered 23 hours ago

PoC for CVE-2026-104606

ItsourcecodeOnline Admission Syste...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Online Admission System...

A vulnerability exists in the itsourcecode Online Admission System Project version 1.0, specifically within the confirm.php file. An unknown function in this file processes an argument ID, which can be manipulated to execute SQL injection attacks. This flaw allows unauthorized users to potentiall...

Discovered 1 day ago

PoC for CVE-2026-40281

GotenbergGotenberg10CRITICAL
Injection Vulnerability in Gotenberg PDF Processing API

The Gotenberg PDF API, a Docker-based tool for PDF file processing, has a significant vulnerability affecting versions 8.30.1 and earlier. It allows unauthenticated attackers to exploit the metadata write endpoint, which inadequately sanitizes metadata values. By including a newline character in ...

PoC for CVE-2026-97219

WordPressMstore Api4.3MEDIUM
User Manipulation Vulnerability in MStore API WordPress Plugin

The MStore API WordPress plugin prior to version 4.22.1 is susceptible to a user manipulation vulnerability that permits any authenticated user with a self-registerable account to alter the status of their own unpaid orders. This flaw enables individuals to change their order status to 'paid' or ...

PoC for CVE-2026-92924

WordPressUnlimited Elements For...5.4MEDIUM
Insecure Widget Output Rendering in Unlimited Elements for Elemento...

The Unlimited Elements for Elementor WordPress plugin is affected by a vulnerability allowing unauthorized users, including those with minimal permissions such as 'subscriber', to execute arbitrary shortcodes on the site. This flaw arises from inadequate validation of requests made to render widg...

PoC for CVE-2026-90987

WordPressEasy Paypal & Stripe B...5.3MEDIUM
Insecure Payment Calculation in Easy PayPal & Stripe Buy Now Button...

The Easy PayPal & Stripe Buy Now Button WordPress plugin, prior to version 2.0.6, contains a vulnerability where the payment amount is derived directly from a client-supplied field. This design flaw allows unauthenticated attackers to manipulate the payment amount, enabling them to set an arbitra...

PoC for CVE-2026-91020

WordPressWebtoffee Gift Cards F...5.3MEDIUM
Unauthorized Manipulation in WebToffee Gift Cards Plugin for WooCom...

The WebToffee Gift Cards for WooCommerce plugin prior to version 1.3.1 fails to adequately validate user-provided gift card amounts on the server side. This oversight permits unauthenticated users to input arbitrary or negative amounts, sidestepping the established denominations set by the store....

PoC for CVE-2026-90952

WordPressWP Edit Password Prote...5.3MEDIUM
Access Control Bypass in WP Edit Password Protected Plugin

The WP Edit Password Protected WordPress plugin prior to version 2.0.7 suffers from an access control bypass issue, failing to properly enforce site-wide restrictions on the WordPress REST API. This flaw permits unauthenticated attackers to gain unauthorized access to the content of published pos...

PoC for CVE-2026-84740

WordPressThe Events Calendar6.5MEDIUM
AJAX Vulnerability in The Events Calendar Plugin for WordPress

The Events Calendar plugin for WordPress, in versions prior to 6.17.5.1, is prone to a vulnerability that allows unauthenticated users to submit data through an AJAX action without proper validation or sanitization. This can lead to unauthorized execution of arbitrary shortcodes registered on the...

PoC for CVE-2026-85005

WordPressPopup Maker WP5.4MEDIUM
Unauthorized Access Issue in Popup Maker WP Plugin by WordPress

The Popup Maker WP plugin for WordPress prior to version 1.4.5 lacks proper authorization checks on multiple actions, leaving its management interface exposed to any logged-in user. This exploitation allows individuals with low-privileged roles, such as Subscribers, to manipulate display-targetin...

PoC for CVE-2026-79618

WordPressWP User Frontend4.3MEDIUM
Post Creation Bypass in WP User Frontend Plugin by WordPress

The WP User Frontend plugin for WordPress, prior to version 4.3.12, contains a flaw in its post-creation handler, permitting authenticated users with subscriber-level access and above to create and publish posts through forms intended for paying subscribers only. This vulnerability circumvents th...