Publicly Disclosed
PoC Exploits
đź”´ Alway take caution when working with PoC Exploits đź”´
Discovered 3 hours ago
PoC for CVE-2026-87902
An unauthenticated attacker can exploit a vulnerability in WordPress that allows `get_page_template()` to inadvertently resolve and include a chosen local `.php` file located outside of the active theme directories. When specific server conditions and configurations of the active theme are met, t...
Discovered 5 hours ago
PoC for CVE-2026-93662
The Events Manager plugin for WordPress prior to version 7.4.5 is vulnerable to improper access control. This vulnerability allows low-privileged users to manipulate owner values in event and location searches. As a result, these users can access unpublished, pending, or trashed content from othe...
PoC for CVE-2026-93661
The Events Manager WordPress plugin, before version 7.4.5, is susceptible to a vulnerability that allows users managing tickets for a single event to execute unauthorized updates. This flaw permits the overwriting and reassignment of tickets to different events, which can lead to unauthorized acc...
PoC for CVE-2026-89005
The WPeMatico RSS Feed Fetcher plugin for WordPress prior to version 2.8.26 allows attackers to exploit a lack of proper sanitization and escaping in a campaign configuration field. This vulnerability permits users with Contributor roles and higher to execute Stored Cross-Site Scripting (XSS) att...
PoC for CVE-2026-89004
The WPeMatico RSS Feed Fetcher WordPress plugin prior to version 2.8.26 has a security weakness where it fails to authenticate user ownership or authorization before disclosing sensitive campaign configuration and execution logs. This vulnerability allows users with contributor-level access and h...
PoC for CVE-2026-89002
The WPeMatico RSS Feed Fetcher plugin for WordPress prior to version 2.8.26 fails to adequately sanitize and escape content retrieved from user-supplied sources. This oversight can enable contributors to exploit the vulnerability and execute Stored Cross-Site Scripting attacks, affecting higher-p...
PoC for CVE-2026-88847
The MasterStudy LMS WordPress plugin, prior to version 3.7.50, contains a vulnerability that compromises the enrollment verification process. It permits any authenticated user, including those with subscriber-level accounts, to inaccurately record lesson completions for courses they are not enrol...
PoC for CVE-2026-88846
The MasterStudy LMS WordPress Plugin prior to version 3.7.50 has a significant vulnerability where it fails to verify if user registration is enabled on the WordPress site. This oversight permits unauthenticated users to create accounts via the plugin's front-end registration processes, even when...
PoC for CVE-2026-88845
The MasterStudy LMS WordPress plugin prior to version 3.7.50 lacks necessary capability and nonce checks during an administrative maintenance action. This oversight allows any authenticated user, including those with the lowest privilege levels like subscribers, to create published content on the...
PoC for CVE-2026-88843
The MasterStudy LMS WordPress Plugin prior to version 3.7.50 is vulnerable due to improper validation of display-style settings. This flaw permits users with Contributor roles or above to include and execute arbitrary local PHP files on the server. Notably, a similar path issue was addressed in a...
PoC for CVE-2026-82850
The Masteriyo LMS plugin for WordPress presents a significant access control weakness, allowing authenticated users, including students, to retrieve the correct answers to quizzes. This vulnerability occurs due to improper access restrictions, enabling users to access answer keys for quizzes acro...
PoC for CVE-2026-84151
The Post Grid WordPress plugin versions prior to 7.9.5 suffer from an HTML injection vulnerability due to inadequate restrictions on the allowed HTML elements. This flaw permits users with Contributor roles and higher to insert iframe, style, and input elements that are typically removed from con...
PoC for CVE-2026-82849
The Masteriyo LMS plugin for WordPress prior to version 3.4.2 exhibits an improper access control vulnerability. This flaw permits authenticated users, including self-registered subscribers, to access and read other users' course-progress records. Specifically, the plugin fails to properly verify...
PoC for CVE-2026-82195
The 10Web Booster plugin for WordPress prior to version 2.34.0 contains an access control vulnerability that allows unauthenticated users to gain access to the routine responsible for issuing the shared secret for cloud connections. This flaw enables unauthorized users to not only view the shared...
PoC for CVE-2026-80513
The wpForo Forum plugin for WordPress, prior to version 3.1.6, is vulnerable to PHP Object Injection due to inadequate restrictions on deserialized user-supplied profile field values. This loophole enables authenticated users with Subscriber-level access or higher to instantiate arbitrary classes...
PoC for CVE-2026-80338
The CMB2 WordPress plugin before version 2.13.0 lacks necessary capability checks on specific AJAX actions. This flaw permits users with minimal permissions, such as Subscribers, to create or modify arbitrary WordPress options, potentially leading to the corruption of critical site settings. Such...
PoC for CVE-2026-74991
The WPForms plugin for WordPress, prior to version 2.0.2, is vulnerable due to a lack of validation on Stripe payment objects during public form submissions. As a result, unauthenticated users can exploit this weakness to initiate full refunds and cancel subscriptions associated with payments mad...
Discovered 7 hours ago
PoC for CVE-2026-96898
A path traversal vulnerability has been identified in the yhx070424 ShopXO application, specifically within the Ueditor Upload Interface located in the file config/ueditor.php up to version 2.2.7. This flaw allows an attacker to manipulate the 'path_type' argument, possibly leading to unauthorize...
PoC for CVE-2026-96892
A significant flaw has been detected in the Edimax BR-6428nC version 1.16 that affects the functionality of the 'websRedirect' in the 'goform' handler. This vulnerability arises from the manipulation of the 'submit-url' argument, potentially allowing attackers to execute an open redirect attack r...
Discovered 8 hours ago
PoC for CVE-2026-87902
An unauthenticated attacker can exploit a vulnerability in WordPress that allows `get_page_template()` to inadvertently resolve and include a chosen local `.php` file located outside of the active theme directories. When specific server conditions and configurations of the active theme are met, t...
PoC for CVE-2026-96884
A security flaw has been identified in MantisZip versions up to 0.4.5, specifically within the Path.Combine function of MainWindow.UI.cs in the Preview component. This vulnerability allows attackers to manipulate file paths, leading to unauthorized access to sensitive data through path traversal....
PoC for CVE-2026-96882
A vulnerability exists in the TaleLin lin-cms-spring-boot product, specifically in the searchBook function of the BookController component. This flaw permits unauthorized access to sensitive operations, making it possible for an attacker to exploit the system remotely. The exploit is publicly ava...
PoC for CVE-2026-96881
A vulnerability has been identified in the TaleLin lin-cms-spring-boot framework, specifically within the book Endpoint's getBooks function located in BookController.java. This issue can lead to improper authorization, potentially allowing remote attackers to manipulate access controls. The vulne...
PoC for CVE-2024-37054
A significant security vulnerability exists within the MLflow platform developed by Databricks. This issue arises from the deserialization of untrusted data in versions 0.9.0 and later. Attackers exploit this vulnerability by uploading a malicious PyFunc model that, once interacted with, can exec...
Discovered 9 hours ago
PoC for CVE-2026-96880
A vulnerability exists in the TaleLin lin-cms-spring-boot application, specifically in the book endpoint located in the BookController.java file. The flaw arises from improper validation of the ID argument in the getBook function, allowing unauthorized access to resources. This vulnerability can ...
PoC for CVE-2026-96810
A cross site scripting vulnerability exists in the Add User Handler of Huanzi QCH Base Admin, affecting versions up to 52816b760cd53244989fd664bbb2b3d4edbfdbf1. This vulnerability is triggered through the manipulation of the Username argument in the Save function within the CommonController.java ...
PoC for CVE-2026-96803
A security vulnerability has been identified in java110 MicroCommunity, specifically within the fallBack API Endpoint in the BusinessApi.java file. An attacker can manipulate the 'fallBackSql' argument, leading to SQL injection vulnerabilities that could be exploited remotely. The affected versio...
PoC for CVE-2026-89274
The WP Recipe Maker plugin for WordPress is vulnerable due to a flaw that allows unauthorized execution of registered shortcodes on recipe pages. This arises from the method 'WPRM_Metadata::sanitize_metadata()' which processes every scalar field of the recipe's metadata, including 'reviewBody', w...
PoC for CVE-2026-96777
A security flaw exists in Forma LMS versions up to 4.1.43, specifically within the Multi-User-Selector AJAX Endpoint. The vulnerability is triggered through the UserselectorAdmController::getDataTask function found in the /appCore/ajax.adm_server.php file. Malicious users can exploit this flaw by...
PoC for CVE-2026-93349
The Frictionless Data Package through version 5.20.0rc1 contains a vulnerability that allows remote attackers to execute arbitrary operating system commands. This exploitation occurs through the 'explore' console command when a user interacts with a crafted Data Package descriptor. Attackers can ...
Discovered 10 hours ago
PoC for CVE-2026-96773
A weakness has been discovered in Intelliants Subrion CMS version 4.2.1 and earlier, specifically within the login functionality found in the 'front/login.php' file. This flaw allows an attacker to manipulate the $_SERVER['HTTP_REFERER'] argument, leading to an open redirect scenario. Such an att...
PoC for CVE-2026-96772
A security flaw has been identified in Intelliants Subrion CMS, specifically related to the handling of the /actions.json?action=assign-owner file. An improper manipulation of the argument 'q' can lead to unauthorized information disclosure, potentially exposing sensitive data. The attack can be ...
Discovered 11 hours ago
PoC for CVE-2026-96762
A vulnerability has been identified in the kvcache-ai Mooncake product affecting versions up to 0.3.12 and 0.3.13.post1. This flaw exists within the UnmountSegment function of the RPC Path Handler, where improper handling of the client_id and segment_id arguments leads to potential authorization ...
PoC for CVE-2026-43499
A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...
PoC for CVE-2026-19125
The EthPress – Web3 Login plugin for WordPress presents a serious vulnerability that allows unauthenticated attackers to bypass authentication measures. This flaw originates from the verify_login() function in app/Login.php, which lacks a required return statement in the event of signature verifi...
PoC for CVE-2026-96739
A vulnerability has been identified in SEMCMS up to version 4.2 related to the upload_json.php file in the KindEditor Upload Interface. This flaw allows attackers to manipulate the imgFile argument, facilitating cross-site scripting attacks. These attacks can be conducted remotely, enabling attac...
Discovered 12 hours ago
PoC for CVE-2026-96680
A significant vulnerability exists in the ByteDance Coze Scraper Extension up to version 2.0.2, specifically within the external message handler's function chrome.runtime.onMessageExternal.addListener. This weakness allows an attacker to manipulate URL parameters, leading to unauthorized access d...
PoC for CVE-2026-96678
A security flaw has been identified in the Avatar Upload component of the weiqingwen spring-boot-forum, specifically within the validate function of the NewUserFormValidator.java file. Attackers can leverage this vulnerability by manipulating the Username argument, potentially conducting remote a...
PoC for CVE-2026-96676
A vulnerability exists in the Fast FAC1900R product, specifically within the 'get_alias_name' function of the uhttpd component. This vulnerability allows for a stack-based buffer overflow that can be exploited remotely. Attackers could potentially manipulate this flaw to execute arbitrary code, l...
Discovered 13 hours ago
PoC for CVE-2026-96604
A significant SQL injection vulnerability exists in the Search Module of SoftNews Media Group's DataLife Engine version 18.0. This flaw is traced to the strip_data function within the search.php file, where improper handling of user input can lead to malicious exploitation. Attackers can execute ...
PoC for CVE-2026-96603
A vulnerability has been identified in the Abdurrab5 online makeup store, specifically within the Admin Handler's confirm_logged_in/confirm_user function located in functions.php. This vulnerability stems from improper argument handling of the adminid parameter, leading to potential missing autho...
PoC for CVE-2026-96602
A security flaw has been identified in the Abdurrab5 online makeup store, specifically within the customerSignin.php file. This vulnerability affects the Customer Login Handler component and allows an attacker to manipulate the username and password arguments, potentially leading to SQL injection...
Discovered 14 hours ago
PoC for CVE-2026-96601
A vulnerability exists in the Abdurrab5 online makeup store's Admin Login Handler, specifically within the index.php file. This issue allows for SQL injection via manipulation of the id/password parameters, potentially leading to unauthorized access to sensitive data. The exploit can be executed ...
PoC for CVE-2026-87902
An unauthenticated attacker can exploit a vulnerability in WordPress that allows `get_page_template()` to inadvertently resolve and include a chosen local `.php` file located outside of the active theme directories. When specific server conditions and configurations of the active theme are met, t...
PoC for CVE-2026-96556
A significant flaw has been identified in Neethuharii CafeManagement, specifically within the addcashier function of the AddCashierCode.php file. This vulnerability arises from the manipulation of parameters such as uname, pass, role, and status, potentially leading to unauthorized access. Attack...
Discovered 15 hours ago
PoC for CVE-2026-96552
A vulnerability exists within the sfturing hosp_order that involves the User Password Handler, specifically in the MD5.getMD5 function of the MD5.java file. This vulnerability allows for the creation of a one-way hash without the inclusion of a salt, which can expose user passwords to potential a...
PoC for CVE-2026-96551
A cross-site request forgery vulnerability exists in the Sfturing Hosp_Order system, specifically within the CommonUserController.java file. This flaw allows attackers to execute unauthorized commands on behalf of authenticated users from a remote location. As there is no versioning for the affec...
PoC for CVE-2026-94127
A significant vulnerability exists in F5 BIG-IP APM when specific configurations involving OAuth profiles are applied to a virtual server. This issue can potentially allow an unauthenticated attacker to execute arbitrary code remotely, which poses a serious risk to system integrity and security. ...
PoC for CVE-2026-96550
A vulnerability found in the Sfturing Hosp_Order product affects the getProperties function within the MailUtil.java file. This vulnerability leads to the cleartext transmission of sensitive information, which can be exploited remotely. The complexity of successfully executing an attack is high, ...
Discovered 16 hours ago
PoC for CVE-2026-96549
A vulnerability discovered in the sfturing hosp_order software permits the cleartext storage of sensitive information, exposing critical data to unauthorized local access. This flaw resides within the CommonUserServiceImpl.java file and can be exploited only from a local environment. The vulnerab...