Publicly Disclosed
PoC Exploits

🔴 Alway take caution when working with PoC Exploits 🔴

Discovered 6 hours ago

PoC for CVE-2026-13432

WordPressThumbpress
Unauthorized Deactivation of ThumbPress Plugin by Authenticated Users

The ThumbPress WordPress plugin prior to version 6.2.2 is susceptible to a security flaw where it fails to verify user capabilities on specific AJAX actions. This omission allows authenticated users with subscriber permissions or higher to deactivate the plugin. Consequently, this can lead to con...

PoC for CVE-2026-8825

WordPressElementor Website Builder
Insufficient User Permissions in Elementor Website Builder Plugin f...

The Elementor Website Builder plugin for WordPress prior to version 4.1.4 contains a flaw that allows authenticated users with Contributor-level access or higher to improperly access private post data through its REST endpoints. This vulnerability permits these users to retrieve sensitive informa...

PoC for CVE-2026-9833

WordPressTag Groups Is The Adva...
Cross-Site Scripting Vulnerability in Tag Groups Plugin for WordPress

The Tag Groups plugin for WordPress versions prior to 2.2.0 is susceptible to a Cross-Site Scripting (XSS) vulnerability due to improper escaping of AJAX parameters. This flaw allows unauthenticated attackers to execute arbitrary JavaScript in the browser of any logged-in user with Editor level a...

PoC for CVE-2026-13142

WordPressSocial Login, Passkeys...
Passwordless Email OTP Vulnerability in Social Login by WordPress

The Social Login, Passkeys, Magic Link & Email OTP plugin for WordPress versions prior to 1.4.1 is vulnerable due to a lack of rate limiting and absence of lockout mechanisms for its passwordless email one-time-password verification. This oversight allows attackers to exploit the security weaknes...

PoC for CVE-2026-13156

WordPressMailersend
Local File Deletion Vulnerability in MailerSend WordPress Plugin by...

The MailerSend WordPress plugin prior to version 1.0.8 lacks a necessary nonce check for its configuration-delete action. While it verifies the manage_options capability, it fails to validate the nonce, allowing an attacker to potentially trick a logged-in administrator into visiting a maliciousl...

PoC for CVE-2026-13147

WordPressKirki
Server-Side Request Forgery Vulnerability in Kirki WordPress Plugin...

The Kirki WordPress plugin prior to version 6.0.12 is susceptible to a sever-side request forgery (SSRF) vulnerability. This issue arises because the plugin does not adequately validate URLs provided by users, potentially allowing unauthenticated attackers to initiate HTTP requests to arbitrary s...

PoC for CVE-2026-12973

WordPressPayplus Payment Gateway
Authorization Bypass in PayPlus Payment Gateway Plugin for WordPress

The PayPlus Payment Gateway plugin for WordPress has a security flaw that allows unauthenticated users to exploit AJAX actions, leading to unauthorized access to sensitive WooCommerce order information. By bypassing necessary authorization and order-ownership checks, attackers could potentially r...

PoC for CVE-2026-12972

WordPressPayplus Payment Gateway
Authorization Vulnerability in PayPlus Payment Gateway Plugin for W...

The PayPlus Payment Gateway plugin for WordPress, prior to version 8.2.2, has a vulnerability that permits unauthenticated users to access certain AJAX actions without proper authorization checks. This oversight allows an attacker to manipulate payment-related metadata associated with arbitrary W...

PoC for CVE-2026-12592

WordPressSlimstat Analytics
Cross-Site Scripting Vulnerability in SlimStat Analytics WordPress ...

The SlimStat Analytics plugin for WordPress allows unauthenticated users to inject malicious scripts due to improper handling of guested geolocation values in admin analytics reports. This shortcoming can lead to the execution of XSS payloads when an administrator views these reports, particularl...

PoC for CVE-2026-12970

WordPressLearnpress
Reflected Cross-Site Scripting Vulnerability in LearnPress WordPres...

A vulnerability exists in the LearnPress WordPress plugin, where certain search parameters are not adequately escaped before being rendered in HTML attributes. This oversight can lead to reflected cross-site scripting (XSS) attacks, which may execute malicious scripts in the browsers of users, pa...

PoC for CVE-2026-12723

WordPressKirki
Authorization Bypass Vulnerability in Kirki WordPress Plugin

The Kirki WordPress plugin prior to version 6.0.12 contains a significant vulnerability in that it fails to implement necessary authorization checks on one of its REST routes. This oversight permits unauthenticated users to not only overwrite existing comments but also to create comments that are...

PoC for CVE-2026-12724

WordPressKirki
Injection Vulnerability in Kirki WordPress Plugin Affects Unauthori...

The Kirki WordPress plugin prior to version 6.0.12 is vulnerable due to inadequate sanitization and escaping of the email subject and body inputs. This flaw enables unauthorized users to inject arbitrary HTML code into the password-reset emails sent to registered users, thereby exposing them to p...

PoC for CVE-2026-12898

WordPressAll-in-one WP Migratio...
Improper Input Validation in All-in-One WP Migration and Backup Plu...

The All-in-One WP Migration and Backup plugin for WordPress prior to version 7.106 contains an improper input validation flaw. This vulnerability allows unauthenticated attackers to create or append log files in arbitrary locations outside of the intended storage directory. The plugin fails to pr...

PoC for CVE-2026-10755

WordPressAll In One Seo
Access Control Vulnerability in All in One SEO Plugin by WordPress

The All in One SEO plugin for WordPress prior to version 4.9.9 has a security issue where it fails to properly restrict access to certain AI integration REST API endpoints. This flaw allows users with minimum privileges, such as Contributors, the potential to overwrite or reset critical site-wide...

PoC for CVE-2026-11349

WordPressModern Event Calendar Pro
Unauthenticated SQL Injection Risk in Modern Event Calendar Pro and...

The Modern Event Calendar Pro and Lite plugins for WordPress are vulnerable due to improper sanitization and escaping of request parameters used in SQL statements during an AJAX action. This weakness allows unauthenticated users to exploit the vulnerabilities, leading to unauthorized access to da...

PoC for CVE-2026-11868

WordPressWP Travel
Unauthorized Cancellation Vulnerability in WP Travel Plugin by Word...

The WP Travel plugin for WordPress prior to version 11.7.1 is susceptible to an unauthorized action vulnerability that permits unauthenticated users to cancel any booking on the site. The plugin fails to implement necessary capability and ownership checks during the booking cancellation process, ...

PoC for CVE-2026-10724

WordPressReviews Feed
Execution of Arbitrary Shortcodes in Reviews Feed Plugin for WordPress

The Reviews Feed, a plugin for WordPress, fails to sanitize WordPress shortcodes present in third-party review content before rendering them via its dynamic block. This oversight permits unauthenticated attackers to execute arbitrary shortcodes on any pages displaying the feed, potentially compro...

PoC for CVE-2026-10081

WordPressUnlimited Elements For...
Stored XSS Vulnerability in Unlimited Elements For Elementor Plugin

The Unlimited Elements for Elementor WordPress plugin, prior to version 2.0.11, fails to properly sanitize or escape content fetched from the Google Serp API. This vulnerability allows unauthenticated attackers to submit malicious reviews to a targeted business's Google listing. When these review...

Discovered 9 hours ago

PoC for CVE-2026-63030

WordPressWordPress9.8CRITICAL
SQL Injection and Remote Code Execution in WordPress REST API

A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...

Discovered 10 hours ago

PoC for CVE-2026-45585

MicrosoftWindows 11 Version 24h26.8MEDIUM
Security Feature Bypass in Windows by Microsoft

A security feature bypass vulnerability exists in Microsoft Windows, referred to as 'YellowKey.' This flaw could allow unauthorized access to restricted features, compromising system integrity. A proof of concept has been publicly released, contrary to established security practices. Users are ad...

Discovered 17 hours ago

PoC for CVE-2025-64512

PDFminerPDFminer.six8.6HIGH
Arbitrary Code Execution in Pdfminer.six by Malicious PDF Files

Pdfminer.six, an open-source library for extracting information from PDF documents, is vulnerable to arbitrary code execution due to improper handling of malicious pickle files embedded in specially crafted PDF files. Specifically, the issue arises from the `CMapDB._load_data()` function that uti...

PoC for CVE-2026-33017

Langflow-aiLangflow🟣 EPSS 98%9.3CRITICAL
Authentication Bypass in Langflow Tool for AI-Powered Workflows

Langflow, a tool for constructing and deploying AI-driven agents and workflows, is susceptible to a vulnerability in the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint in versions before 1.9.0. This vulnerability enables an attacker to build public flows without authentication, leveraging ...

Discovered 18 hours ago

PoC for CVE-2026-63030

WordPressWordPress9.8CRITICAL
SQL Injection and Remote Code Execution in WordPress REST API

A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...

Discovered 21 hours ago

PoC for CVE-2026-63030

WordPressWordPress9.8CRITICAL
SQL Injection and Remote Code Execution in WordPress REST API

A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...

PoC for CVE-2026-63030

WordPressWordPress9.8CRITICAL
SQL Injection and Remote Code Execution in WordPress REST API

A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...

Discovered 22 hours ago

PoC for CVE-2026-46215

LinuxLinux7.8HIGH
Race Condition Vulnerability in Linux Kernel Affecting Multiple Pro...

A race condition has been identified in the Linux kernel related to the handling of device resources, specifically within the Direct Rendering Manager (DRM). This vulnerability arises during the prime swap operation where a single object can spawn two ID references. A concurrent operation, such a...

Discovered 1 day ago

PoC for CVE-2026-16229

ItsourcecodeCourier Management System5.3MEDIUM
Cross Site Scripting Vulnerability in itsourcecode Courier Manageme...

A flaw has been identified in the itsourcecode Courier Management System that can be exploited through remote manipulation of the 'page' argument in the /index.php file. This vulnerability allows attackers to execute cross site scripting attacks, potentially leading to unauthorized actions on beh...

PoC for CVE-2026-16228

SourcecodesterClass And Exam Timetab...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Class and Exam Timeta...

A security vulnerability has been identified in the SourceCodester Class and Exam Timetabling System version 1.0, specifically within the /edit_schoolyr.php file. This flaw allows attackers to manipulate the ID argument, leading to SQL injection attacks that can be executed remotely. As a result,...

PoC for CVE-2026-16227

SourcecodesterClass And Exam Timetab...6.9MEDIUM
SQL Injection Vulnerability in SourceCodester Class and Exam Timeta...

A security flaw has been identified in version 1.0 of the SourceCodester Class and Exam Timetabling System. This vulnerability resides within an unspecified function of the /edit_subject.php file, where it is possible for an attacker to manipulate the ID argument. This manipulation can lead to un...

PoC for CVE-2026-16225

DavenardellaSnap75.3MEDIUM
Out-of-Bounds Write Vulnerability in Snap7 by Davenardella

A significant security flaw exists in Snap7 by Davenardella affecting the function TSnap7Peer::NegotiatePDULength within the s7_peer.cpp file. The vulnerability arises from improper handling of the PDULength argument, leading to an out-of-bounds write condition. This flaw can be exploited remotel...

PoC for CVE-2026-46420

ShivammathurSetup-PHP5.6MEDIUM
Command Injection Vulnerability in setup-php by Shivam Mathur

The setup-php action, which simplifies the configuration of PHP environments on GitHub Actions, is vulnerable to command injection due to its handling of PHP version resolution from certain repository-controlled files. Specifically, from versions 2.25.0 to 2.37.0, inadequate validation of version...

PoC for CVE-2026-16223

1panel-devCordyscrm5.3MEDIUM
Server-Side Request Forgery in 1Panel-dev CordysCRM by 1Panel-dev

A vulnerability exists in 1Panel-dev CordysCRM versions up to 1.4.1, specifically within the getSqlBotSrc function of the IntegrationConfigService.java file. This flaw allows an attacker to manipulate the appSecret argument, potentially leading to unauthorized server-side requests being executed....

PoC for CVE-2026-16222

1panel-devCordyscrm5.3MEDIUM
Server-Side Request Forgery Vulnerability in 1Panel-dev CordysCRM

A potential security vulnerability exists within 1Panel-dev CordysCRM, specifically affecting the TokenService component found in the backend/crm/src/main/java/cn/cordys/crm/integration/sso/service directory. By manipulating the mkAddress argument, an attacker may execute server-side request forg...

PoC for CVE-2026-60137

WordPressWordPress5.9MEDIUM
SQL Injection Vulnerability in WordPress Core Affecting Multiple Ve...

A vulnerability in WordPress allows for potential SQL Injection due to improper sanitization of the author__not_in parameter in WP_Query. When untrusted input is passed to this parameter via a plugin or theme, it could lead to unauthorized database queries. Affected versions include WordPress 6.8...

PoC for CVE-2026-16220

Code-projectsOnline Examination System5.3MEDIUM
Cross-Site Scripting Vulnerability in Online Examination System by ...

The Online Examination System version 1.0 developed by Code-Projects contains a cross-site scripting vulnerability in the /account.php file, particularly when manipulating the 'eid/n/t' argument. This weakness allows an attacker to execute arbitrary JavaScript in the context of the user's browser...

PoC for CVE-2026-63030

WordPressWordPress9.8CRITICAL
SQL Injection and Remote Code Execution in WordPress REST API

A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...

PoC for CVE-2026-16219

CroogoCms5.3MEDIUM
Path Traversal Vulnerability in Croogo CMS Admin File Manager

A vulnerability has been identified in Croogo CMS versions up to 4.0.7, specifically within the FileManager::isEditable function located in FileManager/src/Utility/FileManager.php. This flaw allows an attacker to perform path traversal attacks, which can lead to unauthorized access to sensitive f...

PoC for CVE-2026-16217

GuohongzeAdminset5.3MEDIUM
Authorization Bypass in Guohongze Adminset Delivery Deployment Endp...

A security vulnerability has been identified in the Guohongze Adminset version up to 0.61, specifically within the Delivery Deployment Endpoint's deli.py file. The vulnerability lies in how the project_id argument is processed, potentially allowing unauthorized access. This issue can be exploited...

PoC for CVE-2026-63030

WordPressWordPress9.8CRITICAL
SQL Injection and Remote Code Execution in WordPress REST API

A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...

PoC for CVE-2026-16216

Geex-artsDjango-jet5.3MEDIUM
Cross-Site Request Forgery Vulnerability in Geex-Arts Django-Jet OA...

A vulnerability has been discovered in the OAuth Handler of Geex-Arts Django-Jet, affecting versions up to 1.0.8. This issue allows remote attackers to manipulate the handler and potentially execute cross-site request forgery attacks. Although the problem was reported early, the vendor has not ta...

PoC for CVE-2026-63030

WordPressWordPress9.8CRITICAL
SQL Injection and Remote Code Execution in WordPress REST API

A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...

PoC for CVE-2026-60137

WordPressWordPress5.9MEDIUM
SQL Injection Vulnerability in WordPress Core Affecting Multiple Ve...

A vulnerability in WordPress allows for potential SQL Injection due to improper sanitization of the author__not_in parameter in WP_Query. When untrusted input is passed to this parameter via a plugin or theme, it could lead to unauthorized database queries. Affected versions include WordPress 6.8...

PoC for CVE-2026-16212

AwestoDjango-shop2.3LOW
Race Condition Vulnerability in awesto django-shop by Awesto

A race condition vulnerability has been discovered in awesto django-shop, specifically affecting version 1.2.4. This vulnerability resides in the Purchase Stock Handler component located in shop/models/inventory.py. The flaw can be exploited remotely, indicating a potential risk to users of the s...

PoC for CVE-2021-3129

FacadeIgnition🟣 EPSS 100%9.8CRITICAL
Remote Code Execution Vulnerability in Ignition for Laravel

Ignition versions prior to 2.5.2, as utilized in Laravel, may expose applications to remote code execution vulnerabilities. Attackers can exploit this weakness by leveraging insecure file handling functions, particularly when applications are run in debug mode. This allows unauthenticated attacke...

PoC for CVE-2026-16211

AllegroAllegro2.1LOW
Race Condition in Allegro's Hostname Allocation Handler

A vulnerability has been identified in Allegro's Ralph, specifically in the Hostname Allocation Handler. The issue resides in the AssetLastHostname.increment_hostname function of the assets.py file. By manipulating the argument counter, an attacker could potentially exploit a race condition. Thou...

PoC for CVE-2026-16210

NeWPanjingSimpleui6.9MEDIUM
Missing Authentication Vulnerability in newpanjing SimpleUI AjaxAdm...

A vulnerability exists in the AjaxAdmin component of newpanjing SimpleUI (version 2026.01.13), where the function 'self.get_action' located in simpleui/admin.py allows for missing authentication. This flaw may enable unauthorized remote exploitation, posing a significant risk to users. The projec...

PoC for CVE-2026-16209

GerapyGerapy6.9MEDIUM
Missing Authentication in Gerapy Project Upload Endpoint by Gerapy

A vulnerability exists in Gerapy versions up to 0.9.13, specifically in the Project Upload Endpoint. This issue arises from a missing authentication mechanism in the file gerapy/server/core/views.py. Attackers can remotely exploit this vulnerability to manipulate the endpoint without proper verif...

PoC for CVE-2026-63030

WordPressWordPress9.8CRITICAL
SQL Injection and Remote Code Execution in WordPress REST API

A confusion issue in the REST API batch endpoint of WordPress versions 6.9.x prior to 6.9.5 and 7.0.x prior to 7.0.2 could facilitate an exploit. This vulnerability, when combined with an existing SQL Injection flaw in the author__not_in WP_Query feature, can allow attackers to execute unauthoriz...

PoC for CVE-2026-16205

PluckCms4.8MEDIUM
Cross-Site Scripting Vulnerability in Pluck CMS Albums Module

A potential cross-site scripting (XSS) vulnerability exists in the Albums Module of Pluck CMS versions up to 4.7.21. The issue arises from improper handling of user input in the htmlspecialchars_decode function within the file data/modules/albums/albums.admin.php. By manipulating the argument Inf...

PoC for CVE-2026-16204

ZevornRt-claw5.3MEDIUM
Code Injection Vulnerability in zevorn rt-claw Telegram-to-AI Tool ...

A security flaw has been identified in the zevorn rt-claw product, specifically in the Telegram-to-AI Tool Execution Flow's tool_run_script_execute function. This vulnerability allows for remote code injection due to inadequate input validation in the script handling mechanism found in claw/servi...