Publicly Disclosed
PoC Exploits

đź”´ Alway take caution when working with PoC Exploits đź”´

Discovered just now...

PoC for CVE-2020-25213

WordpressFile Manager🟣 EPSS 94%10CRITICAL
Remote Code Execution in File Manager Plugin for WordPress

The File Manager plugin for WordPress prior to version 6.9 contains a vulnerability that permits remote attackers to upload and execute arbitrary PHP code. The issue arises from the renaming of an insecure example elFinder connector file to have a .php extension. This flaw facilitates attackers t...

Discovered 1 hour ago

PoC for CVE-2026-25253

OpenclawOpenclaw8.8HIGH
WebSocket Vulnerability in OpenClaw by OpenClaw AI

An identified vulnerability in OpenClaw products before version 2026.1.29 allows the software to retrieve a gateway URL from a query string. This triggers an automatic WebSocket connection, which then sends a sensitive token value without user interaction. This flaw may expose users to unauthoriz...

Discovered 2 hours ago

PoC for CVE-2025-68664

Langchain-aiLangchain9.3CRITICAL
Serialization Injection Vulnerability in LangChain Framework

The LangChain framework, designed for building agents and LLM-powered applications, contains a serialization injection vulnerability in its dumps() and dumpd() functions. This flaw arises from the handling of user-controlled data, specifically when dictionaries containing 'lc' keys are serialized...

Discovered 4 hours ago

PoC for CVE-2026-31431

LinuxLinux7.8HIGH
Vulnerability in Linux Kernel Affecting Crypto Operations

A vulnerability has been identified in the Linux kernel's crypto subsystem, specifically within the algif_aead component. This issue arises from an unnecessary complexity in operating in-place, which has been reverted for improved security and performance. The change eliminates the need for in-pl...

Discovered 5 hours ago

PoC for CVE-2025-4396

WordPressRelevanssi Premium🟣 EPSS 22%7.5HIGH
SQL Injection Vulnerability in Relevanssi Search Plugin for WordPress

The Relevanssi – A Better Search plugin for WordPress presents a vulnerability that allows time-based SQL injection through the cats and tags query parameters. This issue affects all versions up to and including 4.24.4 for free and 2.27.4 for premium users. The vulnerability arises from inadequat...

PoC for CVE-2024-47176

OpenprintingCups-browsed🟣 EPSS 88%5.3MEDIUM
CUPS 'cups-browsed' Vulnerability Allows Remote Execution of Arbitr...

The CUPS printing system, which is widely used for managing print jobs, has a vulnerability in its cups-browsed component that allows for network printing functionality such as auto-discovery of print services. This component binds to INADDR_ANY:631, which leads to a scenario where it will accept...

PoC for CVE-2021-47953

OpencartOpencart5.3MEDIUM
Cross-Site Request Forgery in OpenCart by OpenCart

OpenCart version 3.0.3.7 is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability that enables attackers to modify user passwords. By sending carefully crafted requests to the account/password endpoint, an attacker can manipulate authenticated users into executing actions without their...

PoC for CVE-2021-47951

WordPressPicture Gallery5.1MEDIUM
Stored Cross-Site Scripting Vulnerability in WordPress Picture Gall...

The Picture Gallery plugin for WordPress, version 1.4.2, is susceptible to a stored cross-site scripting (XSS) vulnerability. This security flaw allows authenticated users to utilize the Edit Content URL field in the Access Control settings to inject malicious JavaScript code. The injected script...

PoC for CVE-2021-47950

AmppsAdvanced Guestbook5.1MEDIUM
Persistent Cross-Site Scripting Vulnerability in Advanced Guestbook...

Advanced Guestbook version 2.4.4 contains a persistent cross-site scripting vulnerability that affects the smilies administration interface. Authenticated attackers can exploit this flaw by injecting malicious scripts through the s_emotion parameter. When administrators access the smilies tab, an...

PoC for CVE-2021-47949

CyberpanelCyberpanel8.7HIGH
Command Execution Vulnerability in CyberPanel by CyberPanel Technol...

CyberPanel 2.1 is affected by a command execution vulnerability that enables authenticated attackers to exploit symlink attacks via the filemanager controller endpoint. By manipulating the completeStartingPath parameter in POST requests directed to /filemanager/controller, adversaries can create ...

PoC for CVE-2021-47948

WordPressPayments Plugin Getpaid5.1MEDIUM
HTML Injection Vulnerability in GetPaid Plugin for WordPress

The GetPaid Plugin for WordPress, version 2.4.6, is vulnerable to an HTML injection flaw that allows authenticated users to inject arbitrary HTML code into the Help Text field within payment forms. This exploitation can lead to the insertion of malicious content, including scripts and images, whi...

PoC for CVE-2021-47947

ProjectsendProjectsend5.1MEDIUM
Stored Cross-Site Scripting in Projectsend by Projectsend Team

Projectsend r1295 has a vulnerability that allows authenticated attackers to exploit a stored cross-site scripting flaw. By submitting specially crafted input through the 'name' parameter in files-edit.php, attackers can embed malicious JavaScript. This script executes in the browsers of users wh...

PoC for CVE-2021-47946

OpencartOpencart6.9MEDIUM
Cross-Site Request Forgery Vulnerability in OpenCart by OpenCart

OpenCart 3.0.36 is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability that can be exploited by attackers to manipulate user account details. This issue resides in the /account/edit endpoint, permitting unauthorized alterations to victim account information. By luring users into visi...

PoC for CVE-2021-47945

ArgusArgus Surveillance Dvr8.5HIGH
Unquoted Service Path Vulnerability in Argus Surveillance DVR from ...

The Argus Surveillance DVR 4.0 is susceptible to a local privilege escalation vulnerability due to an unquoted service path in the DVRWatchdog service. Attackers can exploit this flaw by placing a malicious executable in the Program Files directory. Upon starting the service, the malicious execut...

PoC for CVE-2021-47944

MemonoNotepad8.7HIGH
Denial of Service Vulnerability in memono Notepad by memono

memono Notepad version 4.2 is susceptible to a denial of service vulnerability that can be exploited by attackers to crash the application. By pasting excessively long character buffers—around 350,000 repeated characters—into the note fields, attackers can cause the application to become unstable...

PoC for CVE-2021-47943

TextpatternTextpattern Cms8.7HIGH
Remote Code Execution Vulnerability in TextPattern CMS 4.8.7

TextPattern CMS 4.8.7 has a significant flaw that allows authenticated users to upload malicious PHP files through a file upload feature. This vulnerability enables attackers to execute arbitrary commands on the server by leveraging the content management system's file handling capabilities. By u...

PoC for CVE-2021-47943

TextpatternTextpattern Cms8.7HIGH
Remote Code Execution Vulnerability in TextPattern CMS 4.8.7

TextPattern CMS 4.8.7 has a significant flaw that allows authenticated users to upload malicious PHP files through a file upload feature. This vulnerability enables attackers to execute arbitrary commands on the server by leveraging the content management system's file handling capabilities. By u...

PoC for CVE-2021-47941

WordPressSurvey & Poll8.8HIGH
SQL Injection Vulnerability in Survey & Poll Plugin for WordPress

The Survey & Poll plugin for WordPress, specifically version 1.5.7.3, is susceptible to an SQL injection vulnerability. This issue permits unauthenticated attackers to execute arbitrary SQL queries through the wp_sap cookie parameter. By crafting malicious SQL payloads, an attacker can potentiall...

PoC for CVE-2021-47940

WordPressDownload From Files9.3CRITICAL
Arbitrary File Upload Vulnerability in Download From Files Plugin b...

The Download From Files plugin for WordPress, up to version 1.48, is vulnerable to an arbitrary file upload issue that can be exploited by unauthenticated attackers. By sending POST requests to the admin-ajax.php endpoint with specifically crafted payloads, attackers can manipulate the allowExt p...

PoC for CVE-2021-47939

EvoEvolution Cms8.7HIGH
Remote Code Execution Vulnerability in Evolution CMS by Evolution

Evolution CMS version 3.1.6 has a security flaw that enables authenticated users with module creation permissions to inject malicious PHP code, leading to potential remote code execution. By crafting crafted POST requests to /manager/index.php with harmful code in the 'post' parameter, an attacke...

PoC for CVE-2021-47938

ImpresscmsImpresscms8.7HIGH
Remote Code Execution in ImpressCMS 1.4.2 by Authenticated Users

ImpressCMS 1.4.2 has a vulnerability in the autotasks administrative interface that enables authenticated users to execute arbitrary PHP code. This is accomplished by injecting malicious code into the sat_code parameter. When attackers authenticate and send a POST request to /modules/system/admin...

PoC for CVE-2021-47937

E107E107 Cms8.7HIGH
Remote Code Execution in e107 CMS by Unauthorized Theme Installation

The e107 CMS version 2.3.0 is susceptible to a remote code execution vulnerability, granting authenticated users with theme installation permissions the ability to exploit the system. By uploading specially crafted theme files through the theme.php endpoint, attackers can deploy web shells in the...

PoC for CVE-2021-47935

SentrySentry8.7HIGH
Remote Code Execution Flaw in Sentry 8.2.0 by Sentry

Sentry 8.2.0 is vulnerable to a remote code execution attack that can be exploited by authenticated superusers. By injecting malicious pickle-serialized objects into the audit log entry data parameter, attackers can send specially crafted POST requests to the admin audit log endpoint. This exploi...

PoC for CVE-2021-47936

OpencatsOpencats9.3CRITICAL
Remote Code Execution Vulnerability in OpenCATS by OpenCATS

OpenCATS version 0.9.4 is susceptible to a remote code execution vulnerability that enables unauthenticated attackers to execute arbitrary commands on the server. This exploit occurs when malicious PHP files, disguised as resume attachments, are uploaded through the careers job application endpoi...

PoC for CVE-2021-47933

WordPressMstore Api9.3CRITICAL
Arbitrary File Upload Vulnerability in MStore API by WordPress

The MStore API version 2.0.6 for WordPress is susceptible to an arbitrary file upload vulnerability. Unauthenticated attackers can exploit this weakness by crafting POST requests directed at the REST API endpoint, specifically the config_file endpoint. This flaw allows attackers to upload malicio...

PoC for CVE-2021-47932

WordPressThecartpress9.3CRITICAL
Unauthenticated Privilege Escalation in TheCartPress by WordPress

TheCartPress version 1.5.3.6 for WordPress contains a vulnerability that permits attackers to escalate privileges without authentication. By sending specially crafted POST requests to the AJAX handler, specifically through the tcp_register_and_login_ajax action with the tcp_role parameter set to ...

PoC for CVE-2021-47930

BalbooaBalbooa Joomla Forms B...8.8HIGH
Unauthenticated SQL Injection in Balbooa Joomla Forms Builder

The Balbooa Joomla Forms Builder 2.0.6 is susceptible to an unauthenticated SQL injection vulnerability in its form submission handler. This flaw enables remote attackers to send specially crafted POST requests containing malicious JSON payloads in the 'id' field parameter. Exploiting this vulner...

PoC for CVE-2021-47931

ExponentcmsExponent Cms5.1MEDIUM
Stored Cross-Site Scripting Vulnerability in Exponent CMS by Exponent

Exponent CMS version 2.6 is susceptible to a stored cross-site scripting vulnerability that enables authenticated attackers to inject malicious scripts through the Title and Text Block parameters in the text editing endpoint. This flaw permits the insertion of iframe payloads that can execute arb...

PoC for CVE-2021-47929

WordPressFilterable Portfolio G...5.1MEDIUM
Stored Cross-Site Scripting in Filterable Portfolio Gallery by Word...

The Filterable Portfolio Gallery plugin version 1.0 for WordPress contains a stored XSS vulnerability that allows authenticated users to inject malicious JavaScript. By entering harmful payloads into the title field, attackers can execute JavaScript code, such as image tags with onerror attribute...

PoC for CVE-2021-47928

OpencartextensionsExtension Tmd Vendor S...8.8HIGH
Blind SQL Injection in Opencart TMD Vendor System

The Opencart TMD Vendor System 3.x is susceptible to a blind SQL injection flaw that enables unauthorized attackers to manipulate SQL queries via the product_id parameter. By leveraging time-based or content-based blind techniques, an attacker can extract sensitive information, such as usernames,...

PoC for CVE-2021-47927

WordPressWP Symposium Pro5.1MEDIUM
Stored Cross-Site Scripting in WP Symposium Pro by WordPress

WP Symposium Pro version 2021.10 is vulnerable to a stored cross-site scripting attack due to inadequate sanitization of user inputs, specifically in the forum name parameter. This flaw allows authenticated users to inject malicious JavaScript payloads via POST requests to the admin setup page, p...

PoC for CVE-2021-47926

WordPressContact Form To Email5.1MEDIUM
Stored Cross-Site Scripting in Contact Form to Email by DWBooster

Contact Form to Email version 1.3.24 contains a stored XSS vulnerability that permits authenticated attackers to inject harmful JavaScript code into the form name field. When other logged-in users visit the form management page, the malicious scripts execute, potentially leading to session hijack...

PoC for CVE-2021-47925

CmdbuildCmdbuild5.1MEDIUM
Stored Cross-Site Scripting Vulnerabilities in CMDBuild by Tecnoteca

CMDBuild 3.3.2 is affected by multiple stored cross-site scripting vulnerabilities that enable authenticated attackers to insert arbitrary web scripts or HTML. This can be exploited through malicious inputs in the card creation and file upload processes. Specifically, XSS payloads can be introduc...

PoC for CVE-2021-47924

WordPressUltimate Product Catalog5.1MEDIUM
Stored Cross-Site Scripting in Ultimate Product Catalog by Etoile W...

A stored cross-site scripting (XSS) vulnerability has been identified in version 5.8.2 of the Ultimate Product Catalog, allowing authenticated users to inject malicious HTML or JavaScript into the product's price field. This vulnerability can be exploited through crafted POST requests to the post...

PoC for CVE-2021-47922

WordPressSlider By Soliloquy5.1MEDIUM
Stored Cross-Site Scripting in Slider by Soliloquy Affects WordPres...

Slider by Soliloquy version 2.6.2 contains a vulnerability that allows authenticated attackers to exploit the title parameter to inject malicious JavaScript payloads. This can lead to the execution of unauthorized scripts in the browsers of users interacting with both administrative and frontend ...

PoC for CVE-2021-47923

OpencartOpencart9.3CRITICAL
Session Fixation Vulnerability in OpenCart by OpenCart

OpenCart 3.0.3.8 is susceptible to a session fixation vulnerability, whereby attackers can manipulate the OCSESSID cookie to inject arbitrary values. By doing so, they can hijack user sessions, potentially granting unauthorized access to user accounts and confidential information. This flaw empha...

PoC for CVE-2021-47910

WordPressAccesspress Social Icons5.1MEDIUM
Stored Cross-Site Scripting Vulnerability in AccessPress Social Ico...

AccessPress Social Icons version 1.8.2 is vulnerable to a stored cross-site scripting (XSS) attack. The vulnerability allows authenticated users to inject malicious JavaScript payloads through the 'icon title' field. Once the payload is stored, it can be executed when other users access the plugi...

PoC for CVE-2021-47907

RocketsoftRocket Lms5.1MEDIUM
Persistent Cross-Site Scripting Vulnerability in Rocket LMS by Rock...

Rocket LMS version 1.1 is susceptible to a persistent cross-site scripting (XSS) vulnerability found in its support ticket module. This flaw permits authenticated users to inject malicious HTML/JavaScript payloads through the title parameter of the support ticket. Such payloads can be triggered w...

Discovered 6 hours ago

PoC for CVE-2022-50970

WordPressWordPress Plugin AaWP5.1MEDIUM
Reflected Cross-Site Scripting Vulnerability in AAWP WordPress Plugin

The AAWP WordPress plugin version 3.16 is susceptible to a reflected cross-site scripting (XSS) vulnerability. This flaw allows authenticated users to be targeted by attackers who can manipulate the 'tab' parameter within the aawp-settings admin page. By crafting specific URLs containing maliciou...

PoC for CVE-2022-50969

UbidauctionUbidauction5.1MEDIUM
Reflected Cross-Site Scripting in uBidAuction by AppHP

uBidAuction 2.0.1 is susceptible to a reflected cross-site scripting vulnerability in its backend mailingLog/manage module. This issue arises because the parameters date_created, date_from, date_to, and created_at in the filter functionality are not effectively sanitized. As a result, attackers c...

PoC for CVE-2022-50969

UbidauctionUbidauction5.1MEDIUM
Reflected Cross-Site Scripting in uBidAuction by AppHP

uBidAuction 2.0.1 is susceptible to a reflected cross-site scripting vulnerability in its backend mailingLog/manage module. This issue arises because the parameters date_created, date_from, date_to, and created_at in the filter functionality are not effectively sanitized. As a result, attackers c...

PoC for CVE-2022-50961

WordPressIp2location Country Bl...5.1MEDIUM
Stored XSS in IP2Location Country Blocker Plugin by WordPress

The IP2Location Country Blocker plugin for WordPress version 2.26.7 is susceptible to a stored cross-site scripting vulnerability. This flaw allows authenticated users to inject arbitrary JavaScript code via the Frontend Settings interface. Specifically, attackers can exploit the URL field in the...

PoC for CVE-2022-50960

WordPressInternational Sms For ...5.1MEDIUM
Reflected Cross-Site Scripting Vulnerability in WordPress Plugin by...

The International Sms For Contact Form 7 Integration plugin for WordPress version 1.2 has a reflected cross-site scripting vulnerability. This issue arises from unsafe handling of the 'page' parameter in the admin settings interface, allowing attackers to inject arbitrary JavaScript code. When ex...

PoC for CVE-2022-50959

WordPressContact Form Builder5.1MEDIUM
Reflected Cross-Site Scripting in WordPress Contact Form Builder

The WordPress Contact Form Builder version 1.6.1 is susceptible to a reflected cross-site scripting vulnerability. This flaw allows unauthenticated attackers to manipulate the form_id parameter, injecting malicious scripts through crafted URLs targeting code_generator.php. Successful exploitation...

PoC for CVE-2022-50958

WordPressJetpack5.1MEDIUM
Reflected Cross-Site Scripting Vulnerability in Jetpack Plugin by W...

The Jetpack plugin for WordPress version 9.1 is susceptible to a reflected cross-site scripting (XSS) vulnerability. This occurs when attackers exploit the post_id parameter, enabling them to inject malicious scripts into URLs that target the grunion-form-view.php endpoint. By manipulating this p...

PoC for CVE-2022-50957

Avatar UploaderAvatar Uploader5.1MEDIUM
Reflected Cross-Site Scripting Vulnerability in Drupal Avatar Uploa...

The Drupal avatar_uploader version 7.x-1.0-beta8 is vulnerable to a reflected cross-site scripting attack. Unauthenticated attackers can exploit this vulnerability by manipulating the 'file' parameter in URLs. This allows arbitrary JavaScript code injection, which executes in the browsers of unsu...

PoC for CVE-2022-50956

WordPressAmministrazione-aperta6.9MEDIUM
Local File Read Vulnerability in Amministrazione-Aperta Plugin for ...

The Amministrazione-Aperta plugin for WordPress version 3.7.3 has a local file read vulnerability that enables unauthenticated attackers to exploit insufficient input validation in the 'open' parameter of dispatcher.php. By manipulating file paths through the 'open' GET parameter, attackers can r...

PoC for CVE-2022-50955

WordPressCurtain5.3MEDIUM
Cross-Site Request Forgery Vulnerability in WordPress Plugin Curtai...

The Curtain plugin for WordPress version 1.0.2 is susceptible to cross-site request forgery (CSRF), enabling attackers to manipulate site maintenance settings. By sending specially crafted requests, malicious actors can deceive authenticated administrators into toggling the maintenance mode state...

PoC for CVE-2022-50949

WordPressVideos Sync PDF5.1MEDIUM
Stored Cross-Site Scripting Vulnerability in WordPress Plugin Video...

The Videos Sync PDF plugin for WordPress, version 1.7.4, contains a vulnerability that allows authenticated users to exploit unsanitized parameters, leading to stored cross-site scripting. This vulnerability enables attackers to inject malicious scripts via the plugin's options panel, which can e...

PoC for CVE-2022-50954

WordPressCab-fare-calculator6.9MEDIUM
Local File Inclusion Vulnerability in cab-fare-calculator Plugin by...

The cab-fare-calculator plugin version 1.0.3 for WordPress is vulnerable to local file inclusion, allowing unauthenticated users to access arbitrary files on the server. By exploiting the controller parameter in tblight.php, attackers can introduce path traversal sequences, enabling them to inclu...