Publicly Disclosed
PoC Exploits

đź”´ Alway take caution when working with PoC Exploits đź”´

Discovered 2 hours ago

PoC for CVE-2025-47947

Owasp-modsecurityModsecurity7.5HIGH
Denial of Service Vulnerability in ModSecurity by OWASP

ModSecurity, an open source web application firewall engine utilized with Apache, IIS, and Nginx, presents a vulnerability that can lead to a denial of service condition under specific circumstances. This occurs in versions up to and including 2.9.8 when processing requests with the content type ...

PoC for CVE-2026-104123

SourcecodesterOnline Reviewer Manage...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Online Reviewer Manag...

A vulnerability has been identified in the SourceCodester Online Reviewer Management System version 1.0. Specifically, the issue arises from the file located at /reviewer_0/admins/assessments/activities/btn_functions.php, where manipulation of the 'Title' argument leads to SQL injection. This typ...

Discovered 3 hours ago

PoC for CVE-2026-104120

ModelcontextprotocolMcp-server-fetch6.9MEDIUM
Server-Side Request Forgery Vulnerability in ModelContextProtocol's...

A security flaw has been identified in ModelContextProtocol's Fetch Tool, affecting versions up to 2026.6.4. The vulnerability resides in the fetch_url function within the server.py file of the mcp-server-fetch and mcp-server-everything components. Attackers can manipulate the url/path argument, ...

PoC for CVE-2026-104054

CalcomCal.diy5.3MEDIUM
Authorization Flaw in Calcom Cal.diy - PBAC Permission Engine

A vulnerability has been identified in Calcom's Cal.diy product, specifically in versions up to 6.2.0. The flaw resides in the function doesUserIdHaveAccessToBooking within the PBAC Permission Engine, which fails to properly enforce access controls. This oversight allows an attacker to initiate u...

Discovered 4 hours ago

PoC for CVE-2026-104052

ItsourcecodePet Shop Management Sy...5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Pet Shop Management System

A SQL injection vulnerability has been identified in the itsourcecode Pet Shop Management System version 1.0. This issue arises from an unknown function in the file admin_reject_completed.php, where improper handling of the ID argument allows attackers to manipulate SQL queries. As a result, it i...

Discovered 5 hours ago

PoC for CVE-2026-90817

Vanderbilt Univer...Redcap9.8CRITICAL
Unauthenticated Remote Code Execution in REDCap by VENDOR

An unauthenticated Remote Code Execution vulnerability affects REDCap, enabling attackers to exploit the survey passthrough routing and Data Import processing. By manipulating HTTP requests, a malicious user can target an unintended controller route from a public survey context and provide a craf...

Discovered 6 hours ago

PoC for CVE-2026-103766

MacwarriorClipbucket-v58.6HIGH
SQL Injection Vulnerability in ClipBucket Product by MacWarrior

ClipBucket versions 5 through 5.5.3-#197 are susceptible to an SQL injection vulnerability that potentially allows authenticated users with ad_manager_access permission to manipulate SQL queries via the delete parameter in admin_area/ads_manager.php. By leveraging time-based blind payloads, attac...

Discovered 7 hours ago

PoC for CVE-2026-26026

GLPI ProjectGlpi9.1CRITICAL
Template Injection Vulnerability in GLPI IT Management Software

GLPI, an open-source asset and IT management software, is susceptible to template injection through administrator actions, allowing for remote code execution. This vulnerability affects versions 11.0.0 to 11.0.5 and has been resolved in version 11.0.6. Users of affected versions are advised to up...

PoC for CVE-2026-102425

Balbooa.comBalbooa Forms Extensio...9.5CRITICAL
Remote Code Execution Risk in Balbooa Forms by Joomla Extension

The Balbooa Forms extension for Joomla has a vulnerability that allows unauthenticated remote code execution (RCE) due to improper handling of PHP code submission. This issue arises when the product supports administrator-defined PHP code that executes after a public form submission. By manipulat...

Discovered 9 hours ago

PoC for CVE-2026-88771

Citrix NetscalerAdc9.5CRITICAL
Improper Input Validation in Citrix NetScaler ADC and Gateway

An improper input validation vulnerability exists in Citrix NetScaler ADC and NetScaler Gateway, enabling unauthenticated attackers to execute arbitrary commands. This potentially compromises system integrity and security, allowing unauthorized control over the affected product.

Discovered 10 hours ago

PoC for CVE-2026-88789

ApacheApache Camel Quarkus8.6HIGH
Improper XML External Entity Handling in Apache Camel Quarkus

A vulnerability in the Apache Camel Quarkus XSLT support extension allows attackers to read local files or issue requests to internal network locations through XML external entity declarations. This weakness exists due to the extension's use of an outdated TransformerFactory that does not adhere ...

Discovered 13 hours ago

PoC for CVE-2026-103690

ItsourcecodeLeave Management System5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Leave Management System...

A vulnerability exists in itsourcecode Leave Management System version 1.0 that allows for SQL injection through manipulation of the LEAVEID argument in the controller.php file. Attackers can exploit this flaw remotely, potentially leading to unauthorized access and data manipulation. The exploit...

PoC for CVE-2026-43499

LinuxLinux7.8HIGH
Linux Kernel Vulnerability in rtmutex Component Affecting Multiple ...

A vulnerability exists in the Linux kernel's rtmutex component where the remove_waiter() function incorrectly utilizes current instead of waiter::task during a dequeue operation within various mutex handling paths. This mismanagement leads to multiple issues, including potential use-after-free vu...

Discovered 15 hours ago

PoC for CVE-2026-103687

RhuksterDom-sanitizer6.9MEDIUM
SVG Sanitization Flaw in Rhukster DOM-Sanitizer Affects Multiple Ve...

A vulnerability exists in the Rhukster DOM-Sanitizer component related to SVG sanitization. The flaw lies in the handling of the function 'url' in the src/DOMSanitizer.php file, which creates an incomplete blacklist for input validation. This allows a potential attacker to exploit the vulnerabili...

PoC for CVE-2024-58388

Sharp CorporationMultiple Multifunction...8.7HIGH
Unauthenticated Local File Inclusion Vulnerability in Sharp Multifu...

Sharp and Toshiba Tec multifunction printers are susceptible to an unauthenticated local file inclusion vulnerability. This issue arises from improper validation of user input in the installed_emanual_down.html endpoint. By manipulating the path parameter, attackers can execute directory traversa...

PoC for CVE-2026-103686

RhuksterDom-sanitizer5.1MEDIUM
Cross-Site Scripting Vulnerability in rhukster dom-sanitizer URL Va...

A security flaw exists in rhukster's dom-sanitizer component, specifically in the URL validation functionality. The issue lies within the DOMSanitizer::isDangerousUrl method, which can be exploited for cross-site scripting attacks. This vulnerability can allow attackers to initiate remote exploit...

Discovered 16 hours ago

PoC for CVE-2024-55591

FortinetFortiOS🟣 EPSS 94%9.6CRITICAL
Remote Attackers Can Gain Super-Admin Privileges via Crafted Reques...

A vulnerability exists in FortiOS and FortiProxy that allows a remote attacker to exploit an authentication bypass through crafted requests targeting the Node.js websocket module. This weakness could enable unauthorized users to attain super-admin privileges, compromising system security. Users o...

Discovered 18 hours ago

PoC for CVE-2026-88771

Citrix NetscalerAdc9.5CRITICAL
Improper Input Validation in Citrix NetScaler ADC and Gateway

An improper input validation vulnerability exists in Citrix NetScaler ADC and NetScaler Gateway, enabling unauthenticated attackers to execute arbitrary commands. This potentially compromises system integrity and security, allowing unauthorized control over the affected product.

Discovered 19 hours ago

PoC for CVE-2026-59310

VmwareCloud Foundation9.8CRITICAL
Directory Traversal Vulnerability in VMware vCenter by VMware

VMware vCenter features a directory traversal vulnerability in its Syslog server component. This flaw allows attackers with network access to exploit the vulnerability, potentially leading to unauthorized execution of arbitrary code. Proper safeguards and patching are essential to mitigate the ri...

PoC for CVE-2026-103585

The Wikimedia Fou...Mediawiki Mediasearch ...1.2LOW
XSS Vulnerability in Wikimedia Foundation's MediaWiki MediaSearch E...

A Cross-Site Scripting (XSS) vulnerability exists in the MediaWiki MediaSearch extension, allowing attackers to inject malicious scripts through improperly neutralized HTML tags in web pages. This affects versions 1.46, 1.45, and 1.43, posing a risk to users by enabling the execution of harmful s...

PoC for CVE-2026-103584

The Wikimedia Fou...Mediawiki Commonsmetad...1.1LOW
Cross-Site Scripting Vulnerability in Wikimedia Foundation MediaWik...

The Wikimedia Foundation MediaWiki CommonsMetadata extension is susceptible to a Cross-Site Scripting vulnerability due to improper neutralization of script-related HTML tags. This flaw permits attackers to inject malicious scripts into web pages viewed by users, which can lead to unauthorized ac...

Discovered 23 hours ago

PoC for CVE-2026-103544

Datadrivenconstru...Openconstructionerp5.3MEDIUM
Improper Access Control in OpenConstructionERP by DataDrivenConstru...

A significant vulnerability affects the OpenConstructionERP software, specifically in the Al Provider Configuration Handler. An unknown function within the ai_client.py file can lead to improper access control, allowing data elements to be exposed to unauthorized sessions. This vulnerability is r...

PoC for CVE-2026-92412

WordPressFive Star Restaurant R...7.1HIGH
Cross-Site Scripting Risks in Five Star Restaurant Reviews Plugin b...

The Five Star Restaurant Reviews plugin for WordPress, prior to version 2.3.14, is vulnerable to Cross-Site Scripting (XSS). This vulnerability arises from improper escaping of user-supplied input, allowing unauthenticated attackers to inject malicious scripts. As a result, any user, including lo...

PoC for CVE-2026-90972

WordPressWP Fusion Lite5.4MEDIUM
Unauthorized Data Exposure in WP Fusion Lite Plugin

The WP Fusion Lite plugin for WordPress prior to version 3.48.0 has a significant security flaw where it fails to conduct proper capability checks on two of its admin AJAX handlers. This oversight enables any authenticated subscriber to access other users' email addresses, leading to unauthorized...

PoC for CVE-2026-96255

WordPressPayments For Hubtel7.5HIGH
Unrestricted Access to Sensitive Payment Data in Hubtel WordPress P...

The Payments for Hubtel WordPress plugin prior to version 1.0.2 has a serious flaw that permits unauthorized public access to a debug log. This log stores sensitive information, including the API credentials for the payment gateway, in an unsecured plain text format. As a result, unauthenticated ...

PoC for CVE-2026-96200

WordPressPayments For Hubtel5.3MEDIUM
Security Flaw in Payments for Hubtel Plugin Paves Way for Unauthori...

The Payments for Hubtel WordPress plugin prior to version 1.0.2 is susceptible to a vulnerability that lacks verification of payment notifications received through its payment callback mechanism. This oversight permits unauthenticated attackers to falsely mark arbitrary orders as paid, leading to...

PoC for CVE-2026-90974

WordPressWP Fusion Lite6.5MEDIUM
Authentication Bypass in WP Fusion Lite Plugin Affects WordPress Users

The WP Fusion Lite plugin for WordPress, prior to version 3.48.0, is susceptible to an authentication bypass vulnerability. This flaw allows unauthenticated users to access critical settings within the WordPress admin area. By exploiting this weakness, attackers can manipulate the site's CRM inte...

PoC for CVE-2026-96173

WordPressPayments For Hubtel5.3MEDIUM
Authorization Flaw in Payments for Hubtel Plugin Enhances Attack Ex...

The Payments for Hubtel WordPress plugin, prior to version 1.0.2, is susceptible to an authorization flaw that fails to validate whether the requester is authorized to access order information. This vulnerability permits unauthenticated attackers to redirect public payment-callback requests, ther...

PoC for CVE-2026-89296

WordPressPro Like Button8.6HIGH
SQL Injection Vulnerability in Pro Like Button Plugin for WordPress

The Pro Like Button plugin for WordPress prior to version 2.0 contains a vulnerability that fails to properly sanitize and escape input parameters used in SQL queries. This flaw allows unauthenticated attackers to manipulate the queries, potentially executing arbitrary SQL commands. As a result, ...

PoC for CVE-2026-81809

WordPressPaytm Payment Gateway7.5HIGH
SQL Injection Vulnerability in Paytm Payment Gateway Plugin for Wor...

The Paytm Payment Gateway WordPress plugin versions before 2.8.9 is susceptible to SQL injection due to improper data escaping from payment callbacks. Malicious users can exploit this vulnerability, particularly when the gateway operates without the required credentials, enabling them to manipula...

PoC for CVE-2026-87973

WordPressIf-so Dynamic Content3.1LOW
JavaScript Injection Vulnerability in If-So Dynamic Content Plugin ...

The If-So Dynamic Content plugin for WordPress prior to version 1.10.2 is susceptible to a JavaScript injection vulnerability. This issue arises because the plugin fails to properly sanitize conversion names before saving them and does not escape content during the rendering of the analytics page...

PoC for CVE-2026-86610

WordPressDownload Manager6.4MEDIUM
Stored Cross-Site Scripting Vulnerability in Download Manager Plugi...

The Download Manager plugin for WordPress prior to version 3.3.71 has a vulnerability that arises from inadequate sanitization of user inputs. This allows users with the Author role or higher to exploit the system by injecting malicious scripts into the package settings. When a visitor accesses t...

PoC for CVE-2026-87970

WordPressIf-so Dynamic Content4.7MEDIUM
Improper Validation in If-So Dynamic Content Plugin for WordPress

The If-So Dynamic Content plugin for WordPress prior to version 1.10.2 is susceptible to an improper input validation vulnerability. This flaw arises from the plugin's failure to adequately escape user-supplied values in AJAX responses. As a consequence, unauthenticated attackers can inject and e...

PoC for CVE-2026-101148

WordPressBackupsheep WordPress ...10CRITICAL
Unauthenticated Site Backup Issues in BackupSheep WordPress Plugin

The BackupSheep WordPress Backup Plugin, prior to version 1.8, fails to impose adequate validation checks on its integration key, mistakenly allowing an unset or blank key to be treated as valid. This loophole enables unauthenticated users to access sensitive functionalities, such as creating and...

PoC for CVE-2026-19253

WordPressCache Enabler8.7HIGH
Improper URL Validation in Cache Enabler Plugin for WordPress

The Cache Enabler WordPress plugin, prior to version 1.8.17, contains a vulnerability that allows unauthenticated users to exploit the URL handling in its cache purge process. By failing to validate a user-supplied URL, the plugin can generate a filesystem path that extends beyond its intended ca...

PoC for CVE-2026-81739

WordPressPaytm Payment Gateway7.5HIGH
Unsecured Payment Gateway Plugin for WordPress Exposes Administrato...

The Paytm Payment Gateway plugin for WordPress prior to version 2.8.9 is vulnerable due to the lack of proper sanitization and escaping of payment callback data. This allows unauthenticated users to manipulate the data stored on admin pages, potentially injecting malicious scripts. Furthermore, t...

PoC for CVE-2026-101147

WordPressFeatured Image From Ur...8.8HIGH
Cross-Site Request Forgery in Featured Image from URL Plugin for Wo...

The Featured Image from URL (FIFU) plugin for WordPress is susceptible to Cross-Site Request Forgery due to improper enforcement of the REST API nonce in versions prior to 6.0.8 and 8.2.8 for the Premium variant. This security flaw enables attackers to exploit the vulnerability through crafted UR...

PoC for CVE-2026-103543

ItsourcecodeLeave Management System5.3MEDIUM
SQL Injection Vulnerability in itsourcecode Leave Management System...

A vulnerability exists in the itsourcecode Leave Management System 1.0 that allows attackers to exploit an unknown function within the /module/leavetype/controller.php file. By manipulating the LEAVTID argument, an attacker can execute SQL injection attacks remotely. This vulnerability has been d...

PoC for CVE-2026-103542

Formtools.orgForm Tools5.3MEDIUM
Server-Side Request Forgery Vulnerability in Form Tools by Formtool...

A security flaw has been identified in Form Tools, specifically within the smart_fill function located in the AJAX Endpoint's actions.php file. This vulnerability allows attackers to manipulate the 'url' argument, leading to server-side request forgery (SSRF). It poses a significant risk as the a...

Discovered 1 day ago

PoC for CVE-2026-103541

Formtools.orgForm Tools5.3MEDIUM
Unrestricted File Upload Vulnerability in Form Tools by formtools.org

A vulnerability was discovered in Form Tools that allows for unrestricted file uploads due to a flaw in the uploadFile function within the Ajax Handler component. This issue is present in versions up to 3.1.1. The flaw enables remote attackers to exploit the vulnerability and upload arbitrary fil...

PoC for CVE-2026-103540

Formtools.orgForm Tools5.3MEDIUM
Server-Side Template Injection Vulnerability in FormTools by formto...

A security vulnerability has been identified in the Form Tools application, specifically impacting versions up to 3.1.1. This flaw affects the function 'Clients::updateClientSettingsTab' within the Client Settings component, located in 'global/code/Clients.class.php'. The issue arises from the im...

PoC for CVE-2026-103539

ZongxrSupermarket5.3MEDIUM
Missing Authentication Vulnerability in ZongXR SuperMarket Product

A vulnerability has been identified in the ZongXR SuperMarket version 1.0.0.0, specifically within the Instant Buy component. This weakness allows for a manipulation of the 'Username' argument during the execution of the 'startBuy' function located in the InstantBuyController.java file. As a resu...

PoC for CVE-2026-103538

ZongxrSupermarket6.9MEDIUM
Authentication Vulnerability in ZongXR SuperMarket Product

A significant security vulnerability has been identified in the ZongXR SuperMarket version 1.0.0.0, specifically within the Order Deletion Endpoint function. This flaw arises from improper handling of the orderId parameter in the OrderController.deleteOrder method, leading to a situation where au...

PoC for CVE-2026-103536

ZongxrSupermarket6.9MEDIUM
Missing Authentication Flaw in ZongXR Supermarket's Order Processin...

A significant security flaw has been identified in the ZongXR Supermarket application, specifically within the OrderController component. The issue lies in the addOrder function, located in the order/src/main/java/com/supermarket/order/controller/OrderController.java file. This vulnerability allo...

PoC for CVE-2026-103446

The Wikimedia Fou...Mediawiki Wikilambda E...7.4HIGH
Authorization Bypass Vulnerability in Wikimedia Foundation's MediaW...

An authorization bypass vulnerability exists in the WikiLambda extension of MediaWiki, allowing unauthorized users to bypass authentication mechanisms. This flaw is triggered by user-controlled keys, enabling potentially malicious actions. The vulnerability affects the MediaWiki WikiLambda extens...

PoC for CVE-2026-103445

The Wikimedia Fou...Mediawiki Page Forms E...1.2LOW
Stored XSS Vulnerability in MediaWiki Page_Forms Extension by Wikim...

The MediaWiki Page_Forms extension from Wikimedia Foundation contains a vulnerability that allows for stored cross-site scripting (XSS). This issue arises from the improper neutralization of script-related HTML tags within web pages, potentially enabling attackers to inject malicious scripts that...

PoC for CVE-2026-103442

The Wikimedia Fou...Mediawiki Centralauth ...7.2HIGH
Code Injection Vulnerability in MediaWiki CentralAuth Extension by ...

A vulnerability exists in the MediaWiki CentralAuth extension that allows external entities to manipulate system or configuration settings, leading to potential code injection. This issue impacts versions 1.46, 1.45, and 1.43. Users of affected versions are encouraged to update their installation...

PoC for CVE-2026-103441

The Wikimedia Fou...Mediawiki Wikibase Ext...7.2HIGH
Deserialization Vulnerability in Wikimedia Foundation MediaWiki Wik...

A deserialization of untrusted data vulnerability exists in the Wikimedia Foundation MediaWiki Wikibase extension, potentially enabling the execution of executable code in files that are not typically executable. This issue raises significant security concerns as it affects multiple versions of t...

PoC for CVE-2026-103440

The Wikimedia Fou...Mediawiki Pagetriage E...1.2LOW
Sensitive Information Exposure in MediaWiki PageTriage by Wikimedia...

A vulnerability in the MediaWiki PageTriage extension enables the exposure of sensitive information through improper data queries. Attackers can potentially elicit data that should be protected, impacting user privacy and system integrity. This issue affects specific versions of the PageTriage ex...

PoC for CVE-2026-103437

The Wikimedia Fou...Mediawiki Readinglists...1.1LOW
Reflected XSS Vulnerability in Wikimedia Foundation’s MediaWiki Rea...

A reflected XSS vulnerability exists in the MediaWiki ReadingLists extension developed by Wikimedia Foundation. This vulnerability stems from improper neutralization of script-related HTML tags in web pages, allowing attackers to execute malicious scripts in the context of a user's browser. Users...