<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>web — PoC Archive</title><link>https://poc.intelseclab.com/pocs/web/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 16 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/pocs/web/index.xml" rel="self" type="application/rss+xml"/><item><title>PHP bcmath bccomp() Out-of-Bounds Write (CVE-2026-17544)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-16_cve-2026-17544-php-bcmath-oob-write/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-16_cve-2026-17544-php-bcmath-oob-write/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-17544 / GHSA-x692-q9x7-8c3f. Status: Patched (PHP 8.4.24 / 8.5.9). Affects: PHP (ext/bcmath). Tags: php, bcmath, oob-write, stack-smashing, rce, cwe-787, CVE-2026-17544.</description><category>web</category><category>Critical</category><category>php</category><category>bcmath</category><category>oob-write</category><category>stack-smashing</category><category>rce</category><category>cwe-787</category><category>CVE-2026-17544</category></item><item><title>nginx PCRE Capture Variable Heap Overflow to Pre-Auth RCE (CVE-2026-42533)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-16_cve-2026-42533-nginx-pcre-heap-overflow-rce/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-16_cve-2026-42533-nginx-pcre-heap-overflow-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-42533. Status: Patched. Affects: nginx 1.30.1 (and likely earlier versions). Tags: nginx, pcre, heap-overflow, rce, preauth, info-leak, capture-variable, map-directive, aslr-bypass, CVE-2026-42533.</description><category>web</category><category>Critical</category><category>nginx</category><category>pcre</category><category>heap-overflow</category><category>rce</category><category>preauth</category><category>info-leak</category><category>capture-variable</category><category>map-directive</category><category>aslr-bypass</category><category>CVE-2026-42533</category></item><item><title>Apache Traffic Server Internal @Header Metadata Spoofing (CVE-2026-33267)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-16_cve-2026-33267-apache-trafficserver-header-spoof/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-16_cve-2026-33267-apache-trafficserver-header-spoof/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-33267 / GHSA-jrh6-9hgv-mqm7. Status: Patched (9.2.15 / 10.1.4). Affects: Apache Traffic Server. Tags: apache, traffic-server, ats, header-injection, metadata-spoof, cache-poisoning, acl-bypass, plugin, CVE-2026-33267.</description><category>web</category><category>Critical</category><category>apache</category><category>traffic-server</category><category>ats</category><category>header-injection</category><category>metadata-spoof</category><category>cache-poisoning</category><category>acl-bypass</category><category>plugin</category><category>CVE-2026-33267</category></item><item><title>WordPress — Pre-Auth XSS to RCE Chain via Login Page Parser Differential (CVE-2026-64638, "XSS2Shell")</title><link>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2026-64638-wordpress-xss2shell-pre-auth-xss-to-rce/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2026-64638-wordpress-xss2shell-pre-auth-xss-to-rce/</guid><description>High severity (CVSS 8.9) — web · CVE-2026-64638. Status: Patched. Affects: WordPress Core, wp-login.php failed-login error message, KSES sanitizer vs PHP strip_tags(). Tags: wordpress, wordpress-core, pre-auth, xss, reflected-xss, xss2shell, rce, parser-differential, dom-clobbering, some, jsonp, rest-api, application-password, plugin-upload, CWE-79, CWE-94, cms.</description><category>web</category><category>High</category><category>wordpress</category><category>wordpress-core</category><category>pre-auth</category><category>xss</category><category>reflected-xss</category><category>xss2shell</category><category>rce</category><category>parser-differential</category><category>dom-clobbering</category><category>some</category><category>jsonp</category><category>rest-api</category><category>application-password</category><category>plugin-upload</category><category>CWE-79</category><category>CWE-94</category><category>cms</category></item><item><title>TeamCity — Unauthenticated RCE via Agent Polling Deserialization (CVE-2026-63077)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2026-63077-teamcity-preauth-rce/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2026-63077-teamcity-preauth-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-63077. Status: Patched. Affects: JetBrains TeamCity (on-premises CI/CD server), agent polling subsystem. Tags: jetbrains, teamcity, preauth-rce, xstream, deserialization, hsqldb, polyglot, jsp, CWE-502, agent-polling, ci-cd.</description><category>web</category><category>Critical</category><category>jetbrains</category><category>teamcity</category><category>preauth-rce</category><category>xstream</category><category>deserialization</category><category>hsqldb</category><category>polyglot</category><category>jsp</category><category>CWE-502</category><category>agent-polling</category><category>ci-cd</category></item><item><title>Oracle E-Business Suite Pre-Authentication RCE Chain (CVE-2025-61882)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2025-61882-oracle-ebs-preauth-rce/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2025-61882-oracle-ebs-preauth-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-61882 (Oracle Security Alert, out-of-band, October 2025). Status: Patched (Oracle out-of-band Security Alert, October 2025). Affects: Oracle E-Business Suite — Oracle Concurrent Processing product, BI Publisher Integration component (reached via the /OA_HTML/ web tier: configurator/UiServlet and ieshostedsurvey.jsp). Tags: oracle-ebs, oracle-concurrent-processing, bi-publisher-integration, pre-auth, rce, ssrf, crlf-injection, request-smuggling, path-traversal, auth-bypass, xslt, java, cisa-kev, ransomware, cl0p, watchtowr.</description><category>web</category><category>Critical</category><category>oracle-ebs</category><category>oracle-concurrent-processing</category><category>bi-publisher-integration</category><category>pre-auth</category><category>rce</category><category>ssrf</category><category>crlf-injection</category><category>request-smuggling</category><category>path-traversal</category><category>auth-bypass</category><category>xslt</category><category>java</category><category>cisa-kev</category><category>ransomware</category><category>cl0p</category><category>watchtowr</category></item><item><title>GitLab Unauthenticated RCE via Workhorse Pre-Auth Upload into ExifTool DjVu Injection (CVE-2021-22205)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2021-22205-gitlab-exiftool-preauth-rce/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2021-22205-gitlab-exiftool-preauth-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2021-22205 (chains CVE-2021-22204 in ExifTool). Status: Patched (GitLab 13.8.8, 13.9.6, 13.10.3). Affects: GitLab Community Edition and Enterprise Edition (via bundled ExifTool, invoked by GitLab Workhorse). Tags: gitlab, exiftool, djvu, rce, preauth, unauthenticated, workhorse, perl, qx, reverse-shell, metadata-injection, kev, ransomware, python, cve-2021-22205, cve-2021-22204.</description><category>web</category><category>Critical</category><category>gitlab</category><category>exiftool</category><category>djvu</category><category>rce</category><category>preauth</category><category>unauthenticated</category><category>workhorse</category><category>perl</category><category>qx</category><category>reverse-shell</category><category>metadata-injection</category><category>kev</category><category>ransomware</category><category>python</category><category>cve-2021-22205</category><category>cve-2021-22204</category></item><item><title>Gitea — diffpatch API Git Hook Remote Code Execution (CVE-2026-60004)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2026-60004-gitea-diffpatch-githook-rce/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2026-60004-gitea-diffpatch-githook-rce/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-60004. Status: Patched. Affects: Gitea (self-hosted Git service), diffpatch API endpoint, Git three-way merge fallback. Tags: gitea, git, diffpatch, git-hook, post-index-change, three-way-merge, bare-repository, CWE-94, authenticated-rce, self-hosted, code-hosting.</description><category>web</category><category>High</category><category>gitea</category><category>git</category><category>diffpatch</category><category>git-hook</category><category>post-index-change</category><category>three-way-merge</category><category>bare-repository</category><category>CWE-94</category><category>authenticated-rce</category><category>self-hosted</category><category>code-hosting</category></item><item><title>CyberPanel Pre-Auth Remote Code Execution via getresetstatus Command Injection (CVE-2024-51378)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2024-51378-cyberpanel-preauth-rce/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2024-51378-cyberpanel-preauth-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2024-51378. Status: Patched (commit 1c0c6cb; CyberPanel 2.3.8 and later). Affects: CyberPanel (aka Cyber Panel), by CyberPersons — Django-based hosting control panel. Tags: cyberpanel, rce, command-injection, preauth, unauthenticated, options-method, secmiddleware-bypass, statusfile, kev, ransomware, psaux, python, httpx, cve-2024-51378.</description><category>web</category><category>Critical</category><category>cyberpanel</category><category>rce</category><category>command-injection</category><category>preauth</category><category>unauthenticated</category><category>options-method</category><category>secmiddleware-bypass</category><category>statusfile</category><category>kev</category><category>ransomware</category><category>psaux</category><category>python</category><category>httpx</category><category>cve-2024-51378</category></item><item><title>Microweber CMS Unauthenticated Path Traversal → Arbitrary File Read (CVE-2026-65694)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2026-65694-microweber-path-traversal/</link><pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2026-65694-microweber-path-traversal/</guid><description>High severity (CVSS 7.5) — web · CVE-2026-65694 (VulnCheck advisory). Status: Unpatched. Affects: Microweber CMS — ServeStaticFileContoller::serveFromUserfiles(). Tags: microweber, path-traversal, cwe-22, unauthenticated, arbitrary-file-read, laravel, query-string-override.</description><category>web</category><category>High</category><category>microweber</category><category>path-traversal</category><category>cwe-22</category><category>unauthenticated</category><category>arbitrary-file-read</category><category>laravel</category><category>query-string-override</category></item><item><title>IBM Langflow OSS Unauthenticated RCE via Auto-Login + validate/code Chain (CVE-2026-9198)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2026-9198-langflow-auto-login-validate-code-rce/</link><pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2026-9198-langflow-auto-login-validate-code-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-9198. Status: Weaponized. Affects: IBM Langflow OSS (visual AI/agent-flow builder). Tags: langflow, ibm, auto-login, code-injection, cwe-94, unauthenticated, rce, python-exec, ai-agent-framework.</description><category>web</category><category>Critical</category><category>langflow</category><category>ibm</category><category>auto-login</category><category>code-injection</category><category>cwe-94</category><category>unauthenticated</category><category>rce</category><category>python-exec</category><category>ai-agent-framework</category></item><item><title>Craft CMS Pre-Auth Remote Code Execution via Session Poisoning + Yii2 PhpManager Gadget (CVE-2025-32432)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2025-32432-craftcms-preauth-rce/</link><pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2025-32432-craftcms-preauth-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-32432. Status: Patched (Craft CMS 5.6.17+). Affects: Craft CMS (craftcms/cms). Tags: craftcms, rce, preauth, session-poisoning, php-deserialization, yii2, phpfpm, unauthenticated, go, cve-2025-32432.</description><category>web</category><category>Critical</category><category>craftcms</category><category>rce</category><category>preauth</category><category>session-poisoning</category><category>php-deserialization</category><category>yii2</category><category>phpfpm</category><category>unauthenticated</category><category>go</category><category>cve-2025-32432</category></item><item><title>Apache Tika PDF Parser XXE via Crafted XFA Form (CVE-2025-54988)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2025-54988-apache-tika-xfa-xxe/</link><pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2025-54988-apache-tika-xfa-xxe/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-54988 (GHSA-p72g-pv48-7w9x, Apache JIRA TIKA-4459). Status: Weaponized. Affects: Apache Tika - tika-parser-pdf-module (and legacy tika-parsers). Tags: apache-tika, xxe, xfa, pdf-parsing, cwe-611, ssrf, file-disclosure, tika-server.</description><category>web</category><category>Critical</category><category>apache-tika</category><category>xxe</category><category>xfa</category><category>pdf-parsing</category><category>cwe-611</category><category>ssrf</category><category>file-disclosure</category><category>tika-server</category></item><item><title>Alibaba Fastjson 1.x checkAutoType Bypass to Remote Code Execution via jar:http SSRF and fd-Reread Trick (CVE-2026-16723)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2026-16723-fastjson-rce/</link><pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2026-16723-fastjson-rce/</guid><description>Critical severity (CVSS 9) — web · CVE-2026-16723. Status: PoC (no vendor patch, Fastjson 1.x line unpatched). Affects: Alibaba Fastjson (Java JSON library), packaged inside a Spring Boot executable fat-JAR. Tags: fastjson, deserialization, rce, java, spring-boot, autotype-bypass, jar-protocol, ssrf.</description><category>web</category><category>Critical</category><category>fastjson</category><category>deserialization</category><category>rce</category><category>java</category><category>spring-boot</category><category>autotype-bypass</category><category>jar-protocol</category><category>ssrf</category></item><item><title>Rails Active Storage Arbitrary File Read to RCE via libvips Unfuzzed Loaders (CVE-2026-66066)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-66066-rails-activestorage-libvips-rce/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-66066-rails-activestorage-libvips-rce/</guid><description>Critical severity (CVSS 9.5) — web · CVE-2026-66066 (GHSA-xr9x-r78c-5hrm). Status: Weaponized. Affects: Ruby on Rails — Active Storage (image variant processing via :vips/libvips). Tags: ruby-on-rails, active-storage, libvips, arbitrary-file-read, marshal-deserialization, rce, unauthenticated, cwe-22.</description><category>web</category><category>Critical</category><category>ruby-on-rails</category><category>active-storage</category><category>libvips</category><category>arbitrary-file-read</category><category>marshal-deserialization</category><category>rce</category><category>unauthenticated</category><category>cwe-22</category></item><item><title>MISP Core `deleteSelection` Broken Access Control — Bulk Deletion of Foreign Event Reports &amp; Sharing Groups (CVE-2026-56423)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-56423-misp-core-deleteselection-broken-access-control/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-56423-misp-core-deleteselection-broken-access-control/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-56423. Status: Weaponized — contributor-level bulk hard-delete of a foreign organizations Event Report confirmed against a real MISP core build; denied on the patched build. Affects: MISP (Malware Information Sharing Platform) Core — EventReportsController::deleteSelection and SharingGroupsController::deleteSelection. Tags: misp, misp-core, broken-access-control, cwe-862, bulk-deletion, authenticated, threat-intel-platform.</description><category>web</category><category>High</category><category>misp</category><category>misp-core</category><category>broken-access-control</category><category>cwe-862</category><category>bulk-deletion</category><category>authenticated</category><category>threat-intel-platform</category></item><item><title>Microsoft SharePoint Server WS-Federation SecurityContextToken Deserialization → Unauthenticated RCE (CVE-2026-50522)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-50522-sharepoint-preauth-rce/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-50522-sharepoint-preauth-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-50522. Status: Weaponized — public PoC confirmed used in real attacks within hours of release (watchTowr honeypot telemetry). Affects: Microsoft SharePoint Server (on-premises). Tags: sharepoint, deserialization, binaryformatter, ws-federation, unauthenticated, rce, kev, actively-exploited, microsoft.</description><category>web</category><category>Critical</category><category>sharepoint</category><category>deserialization</category><category>binaryformatter</category><category>ws-federation</category><category>unauthenticated</category><category>rce</category><category>kev</category><category>actively-exploited</category><category>microsoft</category></item><item><title>Joomla Helix Ultimate Framework — Unauthenticated Arbitrary File Deletion (CVE-2026-57830)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-57830-joomla-helix-ultimate-file-deletion/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-57830-joomla-helix-ultimate-file-deletion/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2026-57830. Status: Weaponized. Affects: Helix Ultimate Framework (plg_system_helixultimate), the JoomShaper Joomla template framework bundled with virtually every JoomShaper Joomla template. Tags: joomla, helix-ultimate, joomshaper, arbitrary-file-deletion, cwe-862, unauthenticated, csrf-token-only-check.</description><category>web</category><category>Critical</category><category>joomla</category><category>helix-ultimate</category><category>joomshaper</category><category>arbitrary-file-deletion</category><category>cwe-862</category><category>unauthenticated</category><category>csrf-token-only-check</category></item><item><title>Joomla Balbooa Forms Unauthenticated Arbitrary File Upload → RCE (CVE-2026-56291)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-56291-joomla-balbooa-forms-file-upload-rce/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-56291-joomla-balbooa-forms-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-56291. Status: Weaponized. Affects: Balbooa Forms (com_baforms) — third-party Joomla! extension by balbooa.com. Tags: joomla, balbooa-forms, file-upload, webshell, unauthenticated, rce, kev, actively-exploited, cwe-434.</description><category>web</category><category>Critical</category><category>joomla</category><category>balbooa-forms</category><category>file-upload</category><category>webshell</category><category>unauthenticated</category><category>rce</category><category>kev</category><category>actively-exploited</category><category>cwe-434</category></item><item><title>GitLab Notebook-Diff Oj Parser Memory-Corruption Chain → Unauthenticated-Reach RCE (No CVE Yet)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_gitlab-oj-json-parser-rce-chain/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_gitlab-oj-json-parser-rce-chain/</guid><description>Critical severity — web · N/A (no CVE assigned as of 2026-07-27 — researcher disclosure via depthfirst.com blog, covered by The Hacker News). Status: Weaponized. Affects: GitLab Community/Enterprise Edition — Jupyter notebook diff rendering (backed by the Oj native Ruby JSON parser gem). Tags: gitlab, oj-gem, json-parser, rce, aslr-bypass, ruby, deserialization, no-cve-yet.</description><category>web</category><category>Critical</category><category>gitlab</category><category>oj-gem</category><category>json-parser</category><category>rce</category><category>aslr-bypass</category><category>ruby</category><category>deserialization</category><category>no-cve-yet</category></item><item><title>Crawl4AI JsonCssExtractionStrategy AST Sandbox Escape → Unauthenticated RCE (CVE-2026-53753)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-53753-crawl4ai-sandbox-escape-rce/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-53753-crawl4ai-sandbox-escape-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-53753 (GHSA-qxjp-w3pj-48m7). Status: Weaponized — full end-to-end command execution reproduced against the official unclecode/crawl4ai:0.8.6 image. Affects: Crawl4AI — open-source LLM-friendly web crawler/scraper, Docker API server. Tags: crawl4ai, sandbox-escape, rce, python, ast-bypass, unauthenticated, llm-tooling, ai-security.</description><category>web</category><category>Critical</category><category>crawl4ai</category><category>sandbox-escape</category><category>rce</category><category>python</category><category>ast-bypass</category><category>unauthenticated</category><category>llm-tooling</category><category>ai-security</category></item><item><title>Budibase Unauthenticated NoSQL Operator Injection (CVE-2026-54350)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-54350-budibase-nosql-injection/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-54350-budibase-nosql-injection/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-54350 (GHSA-8qv3-p479-cj62). Status: Weaponized — reproduced end-to-end against a real budibase/budibase:3.39.0 instance. Affects: Budibase (open-source low-code application platform) — POST /api/v2/queries/:queryId. Tags: budibase, nosql-injection, mongodb, unauthenticated, low-code, json-injection.</description><category>web</category><category>Critical</category><category>budibase</category><category>nosql-injection</category><category>mongodb</category><category>unauthenticated</category><category>low-code</category><category>json-injection</category></item><item><title>Apache APISIX `jwe-decrypt` Integrity-Check Bypass → Unauthenticated Gateway Auth Bypass (CVE-2026-49230)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-49230-apisix-jwe-decrypt-auth-bypass/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-49230-apisix-jwe-decrypt-auth-bypass/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2026-49230. Status: Weaponized. Affects: Apache APISIX — jwe-decrypt auth plugin (apisix/plugins/jwe-decrypt.lua). Tags: apache-apisix, jwe, jwt, integrity-bypass, cwe-354, unauthenticated, api-gateway, lua.</description><category>web</category><category>Critical</category><category>apache-apisix</category><category>jwe</category><category>jwt</category><category>integrity-bypass</category><category>cwe-354</category><category>unauthenticated</category><category>api-gateway</category><category>lua</category></item><item><title>wp2shell — WordPress Core Pre-Auth SQLi → Row Forgery → Admin Creation → RCE (CVE-2026-63030 + CVE-2026-60137)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-63030-cve-2026-60137-wp2shell-wordpress-core-preauth-rce/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-63030-cve-2026-60137-wp2shell-wordpress-core-preauth-rce/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2026-63030 (REST /batch/v1 route confusion, CVSS 7.5), CVE-2026-60137 (author__not_in SQL injection, CVSS 9.1); GHSA-ff9f-jf42-662q, GHSA-fpp7-x2x2-2mjf. Status: Weaponized — full pre-auth RCE confirmed against stock-default WordPress core, no plugins/misconfiguration required. Affects: WordPress core (REST API /batch/v1, WP_Query::author__not_in). Tags: wordpress, wp-core, sql-injection, route-confusion, cwe-89, cwe-436, unauthenticated, remote, privilege-escalation, rce, oembed, changeset.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wp-core</category><category>sql-injection</category><category>route-confusion</category><category>cwe-89</category><category>cwe-436</category><category>unauthenticated</category><category>remote</category><category>privilege-escalation</category><category>rce</category><category>oembed</category><category>changeset</category></item><item><title>SimpleHelp OIDC Authentication Bypass via Unverified JWT Signature (CVE-2026-48558)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-48558-simplehelp-oidc-auth-bypass/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-48558-simplehelp-oidc-auth-bypass/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-48558. Status: Weaponized — forges valid privileged sessions with no credentials. Affects: SimpleHelp — remote support / RMM (remote monitoring and management) platform, OIDC authentication flow. Tags: simplehelp, rmm, oidc, jwt, alg-none, cwe-347, authentication-bypass, unauthenticated, remote, kev, actively-exploited, ransomware.</description><category>web</category><category>Critical</category><category>simplehelp</category><category>rmm</category><category>oidc</category><category>jwt</category><category>alg-none</category><category>cwe-347</category><category>authentication-bypass</category><category>unauthenticated</category><category>remote</category><category>kev</category><category>actively-exploited</category><category>ransomware</category></item><item><title>LLaMA-Factory WebUI Remote Code Execution via Hardcoded `trust_remote_code` (CVE-2026-58116)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-58116-llamafactory-trust-remote-code-rce/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-58116-llamafactory-trust-remote-code-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-58116. Status: Weaponized — confirmed code execution via the exact sink LLaMA-Factory reaches. Affects: LLaMA-Factory ([hiyouga/LLaMA-Factory](https://github.com/hiyouga/LLaMA-Factory)) — WebUI Chat and Training interfaces. Tags: llamafactory, llm-training, webui, trust-remote-code, huggingface, transformers, cwe-94, unauthenticated-within-webui, remote-code-execution, ai-supply-chain.</description><category>web</category><category>Critical</category><category>llamafactory</category><category>llm-training</category><category>webui</category><category>trust-remote-code</category><category>huggingface</category><category>transformers</category><category>cwe-94</category><category>unauthenticated-within-webui</category><category>remote-code-execution</category><category>ai-supply-chain</category></item><item><title>Langflow Responses API IDOR — Execute Another User's Flow (CVE-2026-55255)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-55255-langflow-responses-api-idor/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-55255-langflow-responses-api-idor/</guid><description>High severity (CVSS 8.4) — web · CVE-2026-55255 (GHSA-qrpv-q767-xqq2). Status: Weaponized — confirmed cross-user flow execution via a minimal request-only PoC. Affects: Langflow — open-source platform for building and deploying AI-powered agents and workflows (langflow-ai/langflow), OpenAI-compatible Responses API. Tags: langflow, ai-agent-framework, idor, cwe-639, authenticated, remote, cross-tenant, kev.</description><category>web</category><category>High</category><category>langflow</category><category>ai-agent-framework</category><category>idor</category><category>cwe-639</category><category>authenticated</category><category>remote</category><category>cross-tenant</category><category>kev</category></item><item><title>Adobe ColdFusion RDS Path Traversal → Arbitrary File Read/Write → RCE (CVE-2026-48282)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-48282-coldfusion-rds-path-traversal-rce/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-48282-coldfusion-rds-path-traversal-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-48282 (Adobe APSB26-68). Status: Weaponized — arbitrary file read/write, directory browsing, webshell deployment, and command execution all confirmed. Affects: Adobe ColdFusion — Remote Development Service (RDS), /CFIDE/main/ide.cfm. Tags: coldfusion, adobe, rds, path-traversal, cwe-22, unauthenticated, remote, webshell, kev, actively-exploited.</description><category>web</category><category>Critical</category><category>coldfusion</category><category>adobe</category><category>rds</category><category>path-traversal</category><category>cwe-22</category><category>unauthenticated</category><category>remote</category><category>webshell</category><category>kev</category><category>actively-exploited</category></item><item><title>Flowise Enterprise Authentication Bypass via Hardcoded Default JWT Secrets (CVE-2026-56271)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-12_cve-2026-56271-flowise-hardcoded-jwt-authbypass/</link><pubDate>Sun, 12 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-12_cve-2026-56271-flowise-hardcoded-jwt-authbypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-56271 (GHSA-cc4f-hjpj-g9p8). Status: Weaponized (functional PoC forges valid admin JWTs and confirms bypass against real endpoints). Affects: Flowise — open-source low-code LLM/agent orchestration platform (enterprise edition, passport authentication middleware). Tags: flowise, ai-gateway, llm-orchestration, jwt, hardcoded-secret, authentication-bypass, cwe-321, unauthenticated, remote, privilege-escalation.</description><category>web</category><category>Critical</category><category>flowise</category><category>ai-gateway</category><category>llm-orchestration</category><category>jwt</category><category>hardcoded-secret</category><category>authentication-bypass</category><category>cwe-321</category><category>unauthenticated</category><category>remote</category><category>privilege-escalation</category></item><item><title>Crawl4AI Docker API Server Arbitrary File Write via `output_path` (CVE-2026-56260)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-12_cve-2026-56260-crawl4ai-output-path-arbitrary-write/</link><pubDate>Sun, 12 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-12_cve-2026-56260-crawl4ai-output-path-arbitrary-write/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2026-56260 (GHSA-365w-hqf6-vxfg). Status: PoC — lab (vulnerable-app/) demonstrates genuine unrestricted arbitrary file write; the bundled poc.py scanner is deliberately conservative (writes only to a randomized safe /tmp marker) so it is safe to run against real/production targets. See Notes.. Affects: Crawl4AI — open-source LLM-friendly web crawler/scraper (unclecode/crawl4ai), Docker API server mode. Tags: crawl4ai, ai-web-crawler, docker-api, path-traversal, arbitrary-file-write, cwe-22, unauthenticated, remote, denial-of-service.</description><category>web</category><category>Critical</category><category>crawl4ai</category><category>ai-web-crawler</category><category>docker-api</category><category>path-traversal</category><category>arbitrary-file-write</category><category>cwe-22</category><category>unauthenticated</category><category>remote</category><category>denial-of-service</category></item><item><title>ZKTeco BioTime v8.5.5 Unauthenticated Path Traversal / Arbitrary File Read via iclock API (CVE-2023-38950)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2023-38950-zkteco-biotime-path-traversal/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2023-38950-zkteco-biotime-path-traversal/</guid><description>High severity (CVSS 7.5) — web · CVE-2023-38950. Status: Weaponized (public PoC, in CISA KEV). Affects: ZKTeco BioTime (web-based time &amp; attendance / access control management platform). Tags: zkteco, biotime, path-traversal, arbitrary-file-read, cwe-22, unauthenticated, remote, iclock-api, kev.</description><category>web</category><category>High</category><category>zkteco</category><category>biotime</category><category>path-traversal</category><category>arbitrary-file-read</category><category>cwe-22</category><category>unauthenticated</category><category>remote</category><category>iclock-api</category><category>kev</category></item><item><title>Unauthenticated Arbitrary File Upload RCE in iCagenda for Joomla (CVE-2026-48939)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2026-48939-icagenda-joomla-file-upload-rce/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2026-48939-icagenda-joomla-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-48939. Status: Weaponized (public PoC available, actively exploited in the wild, in CISA KEV since 2026-07-10). Affects: iCagenda — events/calendar extension (component) for Joomla. Tags: joomla, icagenda, file-upload, rce, cwe-434, unauthenticated, remote, kev, cms, php, access-control-bypass.</description><category>web</category><category>Critical</category><category>joomla</category><category>icagenda</category><category>file-upload</category><category>rce</category><category>cwe-434</category><category>unauthenticated</category><category>remote</category><category>kev</category><category>cms</category><category>php</category><category>access-control-bypass</category></item><item><title>Sitecore XP Report.ashx Insecure Deserialization RCE (CVE-2021-42237)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2021-42237-sitecore-xp-deserialization-rce/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2021-42237-sitecore-xp-deserialization-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2021-42237 (Sitecore advisory SC2021-003-499266). Status: Weaponized (public PoC + Metasploit module, in CISA KEV, known ransomware campaign use). Affects: Sitecore Experience Platform (XP). Tags: sitecore, deserialization, rce, cms, unauthenticated, remote, kev, known-ransomware-use, cwe-502.</description><category>web</category><category>Critical</category><category>sitecore</category><category>deserialization</category><category>rce</category><category>cms</category><category>unauthenticated</category><category>remote</category><category>kev</category><category>known-ransomware-use</category><category>cwe-502</category></item><item><title>Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Windows WMI Config Wizard (CVE-2021-25296)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2021-25296-nagios-xi-windowswmi-command-injection/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2021-25296-nagios-xi-windowswmi-command-injection/</guid><description>High severity (CVSS 8.8) — web · CVE-2021-25296. Status: Weaponized (public Metasploit module + nuclei templates, in CISA KEV). Affects: Nagios XI — Windows WMI monitoring configuration wizard. Tags: nagios-xi, os-command-injection, authenticated, config-wizard, windowswmi, cwe-78, kev, metasploit.</description><category>web</category><category>High</category><category>nagios-xi</category><category>os-command-injection</category><category>authenticated</category><category>config-wizard</category><category>windowswmi</category><category>cwe-78</category><category>kev</category><category>metasploit</category></item><item><title>Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Switch Config Wizard (CVE-2021-25297)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2021-25297-nagios-xi-switch-command-injection/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2021-25297-nagios-xi-switch-command-injection/</guid><description>High severity (CVSS 8.8) — web · CVE-2021-25297. Status: Weaponized (public Metasploit module + nuclei templates, in CISA KEV). Affects: Nagios XI — Switch (SNMP) monitoring configuration wizard. Tags: nagios-xi, os-command-injection, authenticated, config-wizard, switch, cwe-78, kev, metasploit.</description><category>web</category><category>High</category><category>nagios-xi</category><category>os-command-injection</category><category>authenticated</category><category>config-wizard</category><category>switch</category><category>cwe-78</category><category>kev</category><category>metasploit</category></item><item><title>Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Cloud-VM Config Wizard (CVE-2021-25298)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2021-25298-nagios-xi-cloudvm-command-injection/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2021-25298-nagios-xi-cloudvm-command-injection/</guid><description>High severity (CVSS 8.8) — web · CVE-2021-25298. Status: Weaponized (public Metasploit module + nuclei templates, in CISA KEV). Affects: Nagios XI — Cloud/VM monitoring configuration wizard (DigitalOcean provider sub-option). Tags: nagios-xi, os-command-injection, authenticated, config-wizard, cloud-vm, cwe-78, kev, metasploit.</description><category>web</category><category>High</category><category>nagios-xi</category><category>os-command-injection</category><category>authenticated</category><category>config-wizard</category><category>cloud-vm</category><category>cwe-78</category><category>kev</category><category>metasploit</category></item><item><title>LiteLLM Proxy Pre-Authentication SQL Injection via Error-Handling Callback (CVE-2026-42208)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2026-42208-litellm-sqli-proxy-authbypass/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2026-42208-litellm-sqli-proxy-authbypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-42208 (GHSA-r75f-5x8p-qvmc). Status: Weaponized (public working PoC + Docker lab, actively exploited in the wild within 36 hours of disclosure). Affects: LiteLLM Proxy — open-source LLM/AI gateway (22,000+ GitHub stars) fronting OpenAI, Anthropic, and other model provider APIs. Tags: litellm, ai-gateway, llm-proxy, sql-injection, cwe-89, unauthenticated, remote, blind-sqli, kev-adjacent, credential-theft.</description><category>web</category><category>Critical</category><category>litellm</category><category>ai-gateway</category><category>llm-proxy</category><category>sql-injection</category><category>cwe-89</category><category>unauthenticated</category><category>remote</category><category>blind-sqli</category><category>kev-adjacent</category><category>credential-theft</category></item><item><title>Gitea Docker Image Reverse-Proxy Authentication Bypass — "One Header, Any User" (CVE-2026-20896)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2026-20896-gitea-docker-reverse-proxy-auth-bypass/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2026-20896-gitea-docker-reverse-proxy-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-20896 (GHSA-f75j-4cw6-rmx4). Status: Weaponized (public PoC + detector script, actively exploited in the wild per Sysdig). Affects: Gitea — official Docker images (gitea/gitea), both root and rootless variants. Tags: gitea, docker, authentication-bypass, reverse-proxy, header-spoofing, unauthenticated, remote, cwe-290, actively-exploited.</description><category>web</category><category>Critical</category><category>gitea</category><category>docker</category><category>authentication-bypass</category><category>reverse-proxy</category><category>header-spoofing</category><category>unauthenticated</category><category>remote</category><category>cwe-290</category><category>actively-exploited</category></item><item><title>XWiki SolrSearch Macro Unauthenticated Groovy RCE (CVE-2025-24893)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-24893-xwiki-solrsearch-groovy-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-24893-xwiki-solrsearch-groovy-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-24893. Status: Weaponized. Affects: XWiki (SolrSearch macro, Main.SolrSearch). Tags: xwiki, groovy, rce, unauthenticated, cwe-94, code-injection, reverse-shell, python, wiki.</description><category>web</category><category>Critical</category><category>xwiki</category><category>groovy</category><category>rce</category><category>unauthenticated</category><category>cwe-94</category><category>code-injection</category><category>reverse-shell</category><category>python</category><category>wiki</category></item><item><title>WP移行専用プラグイン for CPI &lt;= 1.0.2 - Unauthenticated Arbitrary File Upload RCE (CVE-2025-11170)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-11170-cpi-plugin-file-upload-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-11170-cpi-plugin-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-11170. Status: Weaponized. Affects: WP移行専用プラグイン for CPI (cpi-wp-migration, a CPI/site-migration import plugin for WordPress). Tags: wordpress, cpi-wp-migration, unauthenticated-file-upload, rce, admin-ajax, cwe-434, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>cpi-wp-migration</category><category>unauthenticated-file-upload</category><category>rce</category><category>admin-ajax</category><category>cwe-434</category><category>python</category></item><item><title>WP Directory Kit Auto-Login Authentication Bypass to Full Site Takeover (CVE-2025-13390)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13390-wp-directory-kit-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13390-wp-directory-kit-auth-bypass/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-13390. Status: Weaponized. Affects: WP Directory Kit (WordPress plugin). Tags: wordpress, wp-directory-kit, authentication-bypass, predictable-token, account-takeover, webshell-upload, python, cwe-287.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wp-directory-kit</category><category>authentication-bypass</category><category>predictable-token</category><category>account-takeover</category><category>webshell-upload</category><category>python</category><category>cwe-287</category></item><item><title>WordPress WPAMS Plugin Arbitrary File Upload to RCE (CVE-2025-39401)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-39401-wpams-arbitrary-file-upload-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-39401-wpams-arbitrary-file-upload-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-39401. Status: Weaponized. Affects: WPAMS (WordPress Apartment/Property Management System) plugin by mojoomla. Tags: wordpress, wpams, mojoomla, arbitrary-file-upload, webshell, rce, unauthenticated, python, multithreaded, cwe-434.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wpams</category><category>mojoomla</category><category>arbitrary-file-upload</category><category>webshell</category><category>rce</category><category>unauthenticated</category><category>python</category><category>multithreaded</category><category>cwe-434</category></item><item><title>WordPress Simple Link Directory Unauthenticated Password Reset to Admin Takeover (CVE-2025-49901)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-49901-simple-link-directory-password-reset-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-49901-simple-link-directory-password-reset-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-49901. Status: Weaponized. Affects: WordPress "Simple Link Directory" plugin (qc-simple-link-directory by quantumcloud). Tags: wordpress, wordpress-plugin, simple-link-directory, qc-opd, authentication-bypass, password-reset, broken-authentication, cwe-288, username-enumeration, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wordpress-plugin</category><category>simple-link-directory</category><category>qc-opd</category><category>authentication-bypass</category><category>password-reset</category><category>broken-authentication</category><category>cwe-288</category><category>username-enumeration</category><category>python</category></item><item><title>WordPress Service Finder Bookings ≤ 6.0 Authentication Bypass via `original_user_id` Cookie (CVE-2025-5947)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-5947-servicefinder-bookings-cookie-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-5947-servicefinder-bookings-cookie-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-5947. Status: Weaponized. Affects: WordPress plugin "Service Finder Bookings" (sf-booking). Tags: wordpress, service-finder-bookings, sf-booking, authentication-bypass, cookie-forgery, privilege-escalation, cwe-639.</description><category>web</category><category>Critical</category><category>wordpress</category><category>service-finder-bookings</category><category>sf-booking</category><category>authentication-bypass</category><category>cookie-forgery</category><category>privilege-escalation</category><category>cwe-639</category></item><item><title>WordPress Mobile Builder Plugin JWT Authentication Bypass to Admin Account Creation (CVE-2025-68860)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-68860-wp-jwt-admin-forge/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-68860-wp-jwt-admin-forge/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-68860. Status: Weaponized. Affects: WordPress "Mobile Builder" plugin. Tags: wordpress, mobile-builder, jwt, authentication-bypass, hardcoded-secret, privilege-escalation, rest-api, python, cwe-288.</description><category>web</category><category>Critical</category><category>wordpress</category><category>mobile-builder</category><category>jwt</category><category>authentication-bypass</category><category>hardcoded-secret</category><category>privilege-escalation</category><category>rest-api</category><category>python</category><category>cwe-288</category></item><item><title>WooCommerce Dynamic Pricing &amp; Discounts (WC Designer Pro) Unauthenticated File Upload RCE (CVE-2025-6440)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-6440-woocommerce-dynamic-pricing-file-upload-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-6440-woocommerce-dynamic-pricing-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-6440. Status: Weaponized. Affects: WordPress WooCommerce Dynamic Pricing &amp; Discounts plugin (wc-designer-pro). Tags: wordpress, woocommerce, wc-designer-pro, dynamic-pricing, file-upload, rce, unauthenticated, wp-ajax, cwe-434, nuclei.</description><category>web</category><category>Critical</category><category>wordpress</category><category>woocommerce</category><category>wc-designer-pro</category><category>dynamic-pricing</category><category>file-upload</category><category>rce</category><category>unauthenticated</category><category>wp-ajax</category><category>cwe-434</category><category>nuclei</category></item><item><title>Wing FTP Server NULL-Byte Lua Injection Unauthenticated RCE (CVE-2025-47812)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-47812-wingftp-null-byte-lua-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-47812-wingftp-null-byte-lua-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-47812. Status: Weaponized. Affects: Wing FTP Server, web administration/login interface (loginok.html, session mechanism). Tags: wingftp, ftp-server, null-byte-injection, lua-injection, unauthenticated-rce, session-file, cwe-94, cwe-158, python.</description><category>web</category><category>Critical</category><category>wingftp</category><category>ftp-server</category><category>null-byte-injection</category><category>lua-injection</category><category>unauthenticated-rce</category><category>session-file</category><category>cwe-94</category><category>cwe-158</category><category>python</category></item><item><title>Webkul Medical Prescription Attachment for WooCommerce — Unrestricted File Upload to Web Shell (CVE-2025-29009)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-29009-woocommerce-medical-prescription-file-upload/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-29009-woocommerce-medical-prescription-file-upload/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-29009. Status: Weaponized. Affects: Webkul "Medical Prescription Attachment Plugin for WooCommerce" (WordPress plugin). Tags: wordpress, woocommerce, medical-prescription-attachment, unrestricted-file-upload, webshell, cwe-434, unauthenticated, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>woocommerce</category><category>medical-prescription-attachment</category><category>unrestricted-file-upload</category><category>webshell</category><category>cwe-434</category><category>unauthenticated</category><category>python</category></item><item><title>WavePlayer Unauthenticated Arbitrary File Upload to RCE (CVE-2025-12057)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-12057-waveplayer-webshell-upload/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-12057-waveplayer-webshell-upload/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-12057. Status: Weaponized. Affects: WavePlayer (WordPress plugin). Tags: wordpress, waveplayer, arbitrary-file-upload, unauthenticated, rce, webshell, ajax, nonce, php, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>waveplayer</category><category>arbitrary-file-upload</category><category>unauthenticated</category><category>rce</category><category>webshell</category><category>ajax</category><category>nonce</category><category>php</category><category>python</category></item><item><title>TNC Toolbox: Web Performance Unauthenticated cPanel Credential Exposure (CVE-2025-12539)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-12539-tnc-toolbox-cpanel-creds-exposure/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-12539-tnc-toolbox-cpanel-creds-exposure/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-12539. Status: Weaponized. Affects: TNC Toolbox: Web Performance (WordPress plugin). Tags: wordpress, tnc-toolbox, sensitive-information-exposure, unauthenticated, cpanel, credential-theft, privilege-escalation, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>tnc-toolbox</category><category>sensitive-information-exposure</category><category>unauthenticated</category><category>cpanel</category><category>credential-theft</category><category>privilege-escalation</category><category>python</category></item></channel></rss>