Publicly Disclosed
PoC Exploits
đź”´ Alway take caution when working with PoC Exploits đź”´
Discovered 25 minutes ago
PoC for CVE-2026-103446
An authorization bypass vulnerability exists in the WikiLambda extension of MediaWiki, allowing unauthorized users to bypass authentication mechanisms. This flaw is triggered by user-controlled keys, enabling potentially malicious actions. The vulnerability affects the MediaWiki WikiLambda extens...
PoC for CVE-2026-103445
The MediaWiki Page_Forms extension from Wikimedia Foundation contains a vulnerability that allows for stored cross-site scripting (XSS). This issue arises from the improper neutralization of script-related HTML tags within web pages, potentially enabling attackers to inject malicious scripts that...
PoC for CVE-2026-103442
A vulnerability exists in the MediaWiki CentralAuth extension that allows external entities to manipulate system or configuration settings, leading to potential code injection. This issue impacts versions 1.46, 1.45, and 1.43. Users of affected versions are encouraged to update their installation...
PoC for CVE-2026-103441
A deserialization of untrusted data vulnerability exists in the Wikimedia Foundation MediaWiki Wikibase extension, potentially enabling the execution of executable code in files that are not typically executable. This issue raises significant security concerns as it affects multiple versions of t...
PoC for CVE-2026-103440
A vulnerability in the MediaWiki PageTriage extension enables the exposure of sensitive information through improper data queries. Attackers can potentially elicit data that should be protected, impacting user privacy and system integrity. This issue affects specific versions of the PageTriage ex...
Discovered 26 minutes ago
PoC for CVE-2026-103437
A reflected XSS vulnerability exists in the MediaWiki ReadingLists extension developed by Wikimedia Foundation. This vulnerability stems from improper neutralization of script-related HTML tags in web pages, allowing attackers to execute malicious scripts in the context of a user's browser. Users...
Discovered 39 minutes ago
PoC for CVE-2026-12227
The Visual Composer Website Builder plugin for WordPress allows local file inclusion through the `vcv-template` parameter in all versions up to and including 45.16.0. This vulnerability enables unauthenticated attackers to include and execute arbitrary files on the server, potentially leading to ...
Discovered 47 minutes ago
PoC for CVE-2026-102427
The OrdaSoft Joomla CCK extension prior to version 8.3.16 is susceptible to unauthenticated remote code execution due to inadequate handling of file uploads. The vulnerability allows attackers to upload malicious files disguised as images, which can then be executed on the server. This occurs bec...
Discovered 54 minutes ago
PoC for CVE-2025-29927
A security flaw exists in the Next.js framework that allows an attacker to bypass authorization checks if such checks are implemented in middleware. This vulnerability arises in versions prior to 14.2.25 and 15.2.3. To mitigate risk, it is recommended to restrict incoming requests that include th...
Discovered 4 hours ago
PoC for CVE-2026-94545
The Satori library, developed by Vercel for converting HTML and CSS into SVG, contains a vulnerability in versions prior to 0.33.5. In these affected versions, the library fails to properly escape certain values before embedding them in the generated SVG output. This oversight can lead to the exe...
Discovered 8 hours ago
PoC for CVE-2023-54403
The Yonyou U8 CRM software versions before V16.5 and V18 contain a vulnerability in the /ajax/getemaildata.php file, which allows unauthenticated users to bypass authentication by manipulating the DontCheckLogin parameter. This vulnerability permits the reading of arbitrary files through an unval...
PoC for CVE-2024-58387
Inspur Haiyue HCM Cloud features a vulnerability that allows remote attackers to read arbitrary files through the /api/model_report/file/download endpoint. By exploiting unvalidated parameters such as 'index' and 'ext', attackers can craft malicious requests that enable directory traversal, leadi...
PoC for CVE-2026-103387
A weakness exists in the Mailto Header Handler of garycourt's uri-js library up to version 4.4.1, specifically in the URI.parse function located in src/schemes/mailto.ts. This vulnerability can lead to uncaught exceptions due to improper handling of parsed arguments. An attacker may exploit this ...
Discovered 11 hours ago
PoC for CVE-2026-103241
A flaw has been identified in the vLLM software by vllm-project, specifically within the Gemma4UnifiedParser component. This vulnerability allows for a denial of service, which can be exploited remotely through manipulation of certain code segments within the parser. The vulnerable versions of vL...
PoC for CVE-2026-103233
A security vulnerability exists in the AdithyaYelloju Restaurant Management System, affecting the admin area. This vulnerability allows an attacker to manipulate the argument ID, resulting in an unauthorized access control condition. The issue can be exploited remotely, leading to potential unaut...
Discovered 12 hours ago
PoC for CVE-2026-103232
A vulnerability has been detected in the AdithyaYelloju Restaurant-Management-System that could be exploited to perform SQL injection attacks through the mysqli_query function in the admin/table_booking.php file. This flaw allows attackers to manipulate input parameters, particularly the argument...
PoC for CVE-2026-103231
The AdithyaYelloju Restaurant Management System is vulnerable to an SQL injection flaw in the cancellation feature. Specifically, the issue lies within the 'mysqli_query' function in the 'User/cancel.php' file. An attacker can exploit this vulnerability by manipulating the 'ID' argument, potentia...
PoC for CVE-2026-103230
A vulnerability exists in AdithyaYelloju Restaurant-Management-System within the Order Placement component that could allow an attacker to exploit the mysqli_query function in User/ord.php. By manipulating request parameters such as 'id' or 'name', an attacker could execute arbitrary SQL commands...
Discovered 13 hours ago
PoC for CVE-2026-103229
A security vulnerability exists in the AdithyaYelloju Restaurant Management System's Unauthenticated Action Script due to improper input validation in the mysqli_query function located in admin/delete1.php. This flaw allows remote attackers to manipulate the argument ID, leading to SQL injection ...
PoC for CVE-2026-94545
The Satori library, developed by Vercel for converting HTML and CSS into SVG, contains a vulnerability in versions prior to 0.33.5. In these affected versions, the library fails to properly escape certain values before embedding them in the generated SVG output. This oversight can lead to the exe...
Discovered 14 hours ago
PoC for CVE-2026-103226
A notable vulnerability was discovered in Artifex Ghostscript's Pdfwrite component, specifically in the type1_callsubr function within the gdevpsfx.c file. This issue allows for a stack-based buffer overflow, which may be exploited remotely. Given that the exploit is publicly accessible, it poses...
Discovered 15 hours ago
PoC for CVE-2026-103117
A security vulnerability identified in OS4ED openSIS-Classic affects the 'db_properties' function within the 'DatabaseInc.php' file of the Save Data Handler component. This vulnerability arises from improper handling of argument values, allowing for SQL injection attacks that can be executed remo...
PoC for CVE-2026-103116
A vulnerability has been detected in OS4ED's openSIS-Classic version up to 9.3, specifically in the Student List Search Endpoint's DBQuery function located in functions/GetStuListFnc.php. This issue arises from improper handling of the LO_sort argument, allowing for SQL injection attacks that can...
Discovered 16 hours ago
PoC for CVE-2026-103115
A security vulnerability has been identified in the OS4ED openSIS-Classic application, specifically within the Student Search component's CustomFieldsFnc.php file. This vulnerability allows an attacker to manipulate the cust argument, leading to SQL injection attacks. Such exploits can be execute...
PoC for CVE-2026-96760
Authlib versions 1.7.2 and earlier have a vulnerability in the JsonWebSignature.deserialize_json() method, which improperly validates signatures. This flaw allows for the potential bypass of signature checks, as it accepts a JSON Serialization JWS object and returns the payload as verified, witho...
Discovered 17 hours ago
PoC for CVE-2026-103114
A vulnerability exists in OS4ED openSIS-Classic versions up to 9.3, specifically in the function DBQuery_assignment found in the Assignments.php file within the Assignment Management component. This issue arises from improper handling of user inputs, allowing attackers to manipulate the argument ...
Discovered 18 hours ago
PoC for CVE-2026-48121
The LangGraph.js CheckpointSaver implementation utilizing MongoDB storage is susceptible to a NoSQL injection vulnerability. This issue arises due to the lack of type enforcement when passing checkpoint identifiers from config.configurable into MongoDB queries in the MongoDBSaver.getTuple() metho...
Discovered 22 hours ago
PoC for CVE-2026-96886
The Course Booking System WordPress plugin prior to version 7.0.9 is susceptible to an access control flaw that permits unauthenticated individuals to exploit the booking export feature. This oversight enables them to gain unauthorized access to sensitive user data, including names, email address...
PoC for CVE-2026-97316
The Broken Link Notifier plugin for WordPress versions before 2.0.0.1 is susceptible to a redirect bypass vulnerability. This issue allows unauthenticated attackers to circumvent the plugin's internal-address filter, enabling them to exploit the server's functionality by sending unauthorized requ...
PoC for CVE-2026-94274
The YayReviews plugin for WordPress versions prior to 1.4.1 is susceptible to an API access control vulnerability that allows unauthenticated users to access sensitive data. This vulnerability permits attackers to retrieve individual customer reviews—including those awaiting moderation—along with...
PoC for CVE-2026-92994
The Verge3D Publishing and E-Commerce WordPress plugin prior to version 4.13.1 lacks proper validation for files uploaded via its file storage feature. This allows unauthenticated users to store malicious files that can execute harmful JavaScript in the browsers of users who access them, potentia...
PoC for CVE-2026-92424
The Content Egg plugin for WordPress fails to verify user authorization when using its bulk content-import feature. This oversight allows users with contributor-level access and above to select import presets intended for privileged users, effectively switching the import process to the identity ...
PoC for CVE-2026-93580
The InPost PL WordPress plugin version prior to 1.9.8 is susceptible to a vulnerability where it fails to adequately verify the authenticity of incoming shipment webhook requests. The plugin relies solely on a non-secret identifier and an optional IP check, which can be easily bypassed. This over...
PoC for CVE-2026-94297
The Media Library Organizer plugin for WordPress prior to version 2.1.4 has a significant access control vulnerability. It fails to adequately verify whether a user has the necessary capabilities to manage a target taxonomy when creating new terms. This flaw permits users with contributor access ...
PoC for CVE-2026-91832
The WP Mobile Menu plugin for WordPress, prior to version 2.9, lacks proper nonce verification during its settings import. This flaw allows an attacker to perform arbitrary imports of settings within the context of an administrator's session via a cross-site request. Consequently, any imported se...
PoC for CVE-2026-91051
The EWWW Image Optimizer plugin for WordPress, prior to version 8.8.0, allows authenticated users with author-level permissions to insert a serialized value into a post's meta field. Upon rendering, this serialized data is deserialized, which could permit PHP Object Injection. This opens the poss...
PoC for CVE-2026-91072
The EWWW Image Optimizer plugin for WordPress, specifically versions preceding 8.8.0, allows attackers with Administrator-level privileges to exploit a weakness related to WebP-derivative file management. This vulnerability is significant as it enables unauthorized users to manipulate, rename, or...
PoC for CVE-2026-89193
The Robin Image Optimizer plugin for WordPress, prior to version 2.0.8, contains a Cross-Site Scripting (XSS) vulnerability. This occurs due to inadequate escaping of values in its bundled HTML parser when attributes are emitted in certain non-default image delivery modes. As a result, this flaw ...
PoC for CVE-2026-90953
The Image Optimizer WordPress plugin prior to version 1.7.7 contains an authorization flaw that fails to properly enforce capability checks on multiple read REST routes. This lack of enforcement permits authenticated users to access sensitive attachment metadata and site-wide statistics, which sh...
PoC for CVE-2026-88797
The Vayu X WordPress theme prior to version 1.0.6 contains a critical vulnerability that fails to verify user capabilities on a specific AJAX action. This oversight grants authenticated users, including roles with limited permissions like subscribers, the ability to bypass nonce protections. As a...
PoC for CVE-2026-89190
The Robin Image Optimizer plugin for WordPress, prior to version 2.0.8, contains an access control vulnerability that allows subscribers to access admin-only pages. This flaw arises from inadequate checks on user capabilities, enabling unauthorized users to view sensitive settings stored within t...
PoC for CVE-2026-87777
The Hostinger Reach WordPress plugin prior to version 1.8.3 is susceptible to a cross-site scripting vulnerability. This issue arises because the plugin fails to adequately sanitize and escape widget settings before displaying them in the editor preview. As a result, users with contributor-level ...
PoC for CVE-2026-86789
A flaw in the Connections Business Directory plugin for WordPress versions up to 10.4.67 allows unauthenticated users to access sensitive directory entries via specific REST API read endpoints. This includes private or unlisted entries and content pending moderation, such as names, organizations,...
PoC for CVE-2026-85573
The All in One Files Upload plugin for WordPress prior to version 2.0.17 introduces a significant security risk by permitting SVG files as allowable upload types. This vulnerability arises from the plugin's failure to properly sanitize these uploaded files or to verify the authenticity of public ...
PoC for CVE-2026-88791
The Safe Redirect Manager plugin for WordPress prior to version 2.3.0 is susceptible to improper validation of redirect destinations. This vulnerability allows unauthenticated attackers to manipulate redirect rules, potentially redirecting users to malicious external websites when specific wildca...
PoC for CVE-2026-85576
The All in One Files Upload plugin for WordPress lacks proper capability checks and fails to authenticate requests when saving settings. This vulnerability allows any authenticated user, regardless of their role, to make unauthorized changes to important settings. This poses a significant risk as...
PoC for CVE-2026-80333
The Solace Extra WordPress plugin, prior to version 1.7.2, lacks essential authorization and post-status checks on its front-end preview routes. This deficiency allows unauthenticated individuals to view the contents of unpublished posts and pages, bypassing restrictions that WordPress typically ...
PoC for CVE-2026-85001
The EmbedPress plugin for WordPress, prior to version 4.6.7, exhibits a security flaw where it fails to properly sanitize and escape an Elementor widget setting. This oversight allows users with Contributor roles or higher to execute arbitrary web scripts through HTML attributes. When affected co...
PoC for CVE-2026-83560
The New User Approve plugin for WordPress prior to version 3.2.10 exhibits an authentication flaw in its integration REST API routes. When the integration is unconfigured, this vulnerability allows unauthenticated attackers to access sensitive information such as user IDs, usernames, email addres...
PoC for CVE-2026-85415
The Audio Player Block plugin for WordPress prior to version 1.6.3 lacks proper validation of user-supplied URLs, allowing contributors and above to introduce malicious JavaScript. When other users engage with such links, their sessions may be compromised, leading to potential exploit risks durin...