<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Authenticated — PoC Archive</title><link>https://poc.intelseclab.com/tags/authenticated/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 27 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/authenticated/index.xml" rel="self" type="application/rss+xml"/><item><title>MISP Core `deleteSelection` Broken Access Control — Bulk Deletion of Foreign Event Reports &amp; Sharing Groups (CVE-2026-56423)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-56423-misp-core-deleteselection-broken-access-control/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-56423-misp-core-deleteselection-broken-access-control/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-56423. Status: Weaponized — contributor-level bulk hard-delete of a foreign organizations Event Report confirmed against a real MISP core build; denied on the patched build. Affects: MISP (Malware Information Sharing Platform) Core — EventReportsController::deleteSelection and SharingGroupsController::deleteSelection. Tags: misp, misp-core, broken-access-control, cwe-862, bulk-deletion, authenticated, threat-intel-platform.</description><category>web</category><category>High</category><category>misp</category><category>misp-core</category><category>broken-access-control</category><category>cwe-862</category><category>bulk-deletion</category><category>authenticated</category><category>threat-intel-platform</category></item><item><title>Langflow Responses API IDOR — Execute Another User's Flow (CVE-2026-55255)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-55255-langflow-responses-api-idor/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-55255-langflow-responses-api-idor/</guid><description>High severity (CVSS 8.4) — web · CVE-2026-55255 (GHSA-qrpv-q767-xqq2). Status: Weaponized — confirmed cross-user flow execution via a minimal request-only PoC. Affects: Langflow — open-source platform for building and deploying AI-powered agents and workflows (langflow-ai/langflow), OpenAI-compatible Responses API. Tags: langflow, ai-agent-framework, idor, cwe-639, authenticated, remote, cross-tenant, kev.</description><category>web</category><category>High</category><category>langflow</category><category>ai-agent-framework</category><category>idor</category><category>cwe-639</category><category>authenticated</category><category>remote</category><category>cross-tenant</category><category>kev</category></item><item><title>Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Windows WMI Config Wizard (CVE-2021-25296)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2021-25296-nagios-xi-windowswmi-command-injection/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2021-25296-nagios-xi-windowswmi-command-injection/</guid><description>High severity (CVSS 8.8) — web · CVE-2021-25296. Status: Weaponized (public Metasploit module + nuclei templates, in CISA KEV). Affects: Nagios XI — Windows WMI monitoring configuration wizard. Tags: nagios-xi, os-command-injection, authenticated, config-wizard, windowswmi, cwe-78, kev, metasploit.</description><category>web</category><category>High</category><category>nagios-xi</category><category>os-command-injection</category><category>authenticated</category><category>config-wizard</category><category>windowswmi</category><category>cwe-78</category><category>kev</category><category>metasploit</category></item><item><title>Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Switch Config Wizard (CVE-2021-25297)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2021-25297-nagios-xi-switch-command-injection/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2021-25297-nagios-xi-switch-command-injection/</guid><description>High severity (CVSS 8.8) — web · CVE-2021-25297. Status: Weaponized (public Metasploit module + nuclei templates, in CISA KEV). Affects: Nagios XI — Switch (SNMP) monitoring configuration wizard. Tags: nagios-xi, os-command-injection, authenticated, config-wizard, switch, cwe-78, kev, metasploit.</description><category>web</category><category>High</category><category>nagios-xi</category><category>os-command-injection</category><category>authenticated</category><category>config-wizard</category><category>switch</category><category>cwe-78</category><category>kev</category><category>metasploit</category></item><item><title>Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Cloud-VM Config Wizard (CVE-2021-25298)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2021-25298-nagios-xi-cloudvm-command-injection/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2021-25298-nagios-xi-cloudvm-command-injection/</guid><description>High severity (CVSS 8.8) — web · CVE-2021-25298. Status: Weaponized (public Metasploit module + nuclei templates, in CISA KEV). Affects: Nagios XI — Cloud/VM monitoring configuration wizard (DigitalOcean provider sub-option). Tags: nagios-xi, os-command-injection, authenticated, config-wizard, cloud-vm, cwe-78, kev, metasploit.</description><category>web</category><category>High</category><category>nagios-xi</category><category>os-command-injection</category><category>authenticated</category><category>config-wizard</category><category>cloud-vm</category><category>cwe-78</category><category>kev</category><category>metasploit</category></item><item><title>pgAdmin 4 Query Tool Authenticated eval() RCE (CVE-2025-2945)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-2945-pgadmin-eval-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-2945-pgadmin-eval-rce/</guid><description>Critical severity (CVSS 9.9) — web · CVE-2025-2945. Status: Weaponized. Affects: pgAdmin 4 (web-based PostgreSQL administration tool). Tags: pgadmin, postgresql, rce, eval-injection, code-injection, cwe-95, python, authenticated, sqleditor.</description><category>web</category><category>Critical</category><category>pgadmin</category><category>postgresql</category><category>rce</category><category>eval-injection</category><category>code-injection</category><category>cwe-95</category><category>python</category><category>authenticated</category><category>sqleditor</category></item><item><title>Zyxel VMG3625-T50B Authenticated Command Injection to Root SSH Access (CVE-2026-1459)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-1459-zyxel-router-command-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-1459-zyxel-router-command-injection/</guid><description>High severity — network · CVE-2026-1459. Status: PoC. Affects: Zyxel VMG3625-T50B (and similar) router firmware. Tags: zyxel, router, firmware, command-injection, cgi-bin, ssh, authenticated, iot.</description><category>network</category><category>High</category><category>zyxel</category><category>router</category><category>firmware</category><category>command-injection</category><category>cgi-bin</category><category>ssh</category><category>authenticated</category><category>iot</category></item><item><title>ZoneMinder — Second-Order SQL Injection via Event Rename (CVE-2026-27470)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27470-zoneminder-second-order-sqli/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27470-zoneminder-second-order-sqli/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-27470. Status: Weaponized. Affects: ZoneMinder. Tags: zoneminder, sql-injection, second-order-sqli, authenticated, credential-extraction, cwe-89, php.</description><category>web</category><category>High</category><category>zoneminder</category><category>sql-injection</category><category>second-order-sqli</category><category>authenticated</category><category>credential-extraction</category><category>cwe-89</category><category>php</category></item><item><title>Wyze Cam Pan v3 / TUTK SDK — tutk_packet_alloc Heap Overflow (CVE-2026-38698)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-38698-wyze-cam-tutk-heap-overflow/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-38698-wyze-cam-tutk-heap-overflow/</guid><description>Critical severity — network · CVE-2026-38698. Status: PoC. Affects: TUTK SDK (as used in Wyze Cam Pan v3 and other TUTK-based IoT cameras). Tags: tutk-sdk, iot, camera, heap-overflow, av-server, wyze, authenticated, p2p.</description><category>network</category><category>Critical</category><category>tutk-sdk</category><category>iot</category><category>camera</category><category>heap-overflow</category><category>av-server</category><category>wyze</category><category>authenticated</category><category>p2p</category></item><item><title>Wing FTP Server Admin Session Poisoning via Lua loadfile() RCE (CVE-2026-44403)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-44403-wingftp-session-poisoning-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-44403-wingftp-session-poisoning-rce/</guid><description>High severity — web · CVE-2026-44403. Status: PoC. Affects: Wing FTP Server (WebAdmin console). Tags: wingftp, lua, session-poisoning, loadfile, rce, webadmin, authenticated.</description><category>web</category><category>High</category><category>wingftp</category><category>lua</category><category>session-poisoning</category><category>loadfile</category><category>rce</category><category>webadmin</category><category>authenticated</category></item><item><title>WeGIA Authenticated Error-Based SQL Injection Exploitation Helper (CVE-2026-23723)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23723-wegia-sql-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23723-wegia-sql-injection/</guid><description>High severity — web · CVE-2026-23723 / GHSA-xfmp-2hf9-gfjp. Status: Weaponized. Affects: WeGIA (Web Gestão Integrada de Associações). Tags: wegia, sql-injection, authenticated, sqlmap, php, session-hijack, database-dump, error-based.</description><category>web</category><category>High</category><category>wegia</category><category>sql-injection</category><category>authenticated</category><category>sqlmap</category><category>php</category><category>session-hijack</category><category>database-dump</category><category>error-based</category></item><item><title>Weblate Arbitrary File Read via ssh-keyscan Host Argument Injection — CVE-2026-24126</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24126-weblate-ssh-keyscan-file-read/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24126-weblate-ssh-keyscan-file-read/</guid><description>High severity (CVSS 6.5) — web · CVE-2026-24126. Status: PoC. Affects: Weblate (self-hosted translation platform). Tags: weblate, argument-injection, command-injection, ssh-keyscan, arbitrary-file-read, authenticated, python, cwe-88.</description><category>web</category><category>High</category><category>weblate</category><category>argument-injection</category><category>command-injection</category><category>ssh-keyscan</category><category>arbitrary-file-read</category><category>authenticated</category><category>python</category><category>cwe-88</category></item><item><title>Veno File Manager Path Traversal to Arbitrary File Read (CVE-2026-37066)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-37066-veno-file-manager-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-37066-veno-file-manager-path-traversal/</guid><description>High severity — web · CVE-2026-37066. Status: PoC. Affects: Veno File Manager Project. Tags: veno-file-manager, path-traversal, arbitrary-file-read, authenticated, superadmin, cwe-22.</description><category>web</category><category>High</category><category>veno-file-manager</category><category>path-traversal</category><category>arbitrary-file-read</category><category>authenticated</category><category>superadmin</category><category>cwe-22</category></item><item><title>Veno File Manager Arbitrary PHP File Overwrite (CVE-2026-37068)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-37068-veno-file-manager-arbitrary-file-write/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-37068-veno-file-manager-arbitrary-file-write/</guid><description>Critical severity — web · CVE-2026-37068. Status: Weaponized. Affects: Veno File Manager Project. Tags: veno-file-manager, arbitrary-file-write, rce, authenticated, superadmin, cwe-434.</description><category>web</category><category>Critical</category><category>veno-file-manager</category><category>arbitrary-file-write</category><category>rce</category><category>authenticated</category><category>superadmin</category><category>cwe-434</category></item><item><title>Veno File Manager Arbitrary File Deletion (CVE-2026-37065)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-37065-veno-file-manager-file-deletion/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-37065-veno-file-manager-file-deletion/</guid><description>High severity — web · CVE-2026-37065. Status: PoC. Affects: Veno File Manager Project. Tags: veno-file-manager, arbitrary-file-deletion, authenticated, superadmin, cwe-22.</description><category>web</category><category>High</category><category>veno-file-manager</category><category>arbitrary-file-deletion</category><category>authenticated</category><category>superadmin</category><category>cwe-22</category></item><item><title>Veno File Manager 4.4.9 — Authenticated Arbitrary File Read (CVE-2026-37070)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-37070-veno-file-manager-file-read/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-37070-veno-file-manager-file-read/</guid><description>Medium severity — web · CVE-2026-37070. Status: PoC. Affects: Veno File Manager Project. Tags: file-manager, incorrect-access-control, arbitrary-file-read, php, authenticated, veno-file-manager.</description><category>web</category><category>Medium</category><category>file-manager</category><category>incorrect-access-control</category><category>arbitrary-file-read</category><category>php</category><category>authenticated</category><category>veno-file-manager</category></item><item><title>Veno File Manager 4.4.9 — Arbitrary File Rename to Privilege Escalation (CVE-2026-37071)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-37071-veno-file-manager-rename-privesc/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-37071-veno-file-manager-rename-privesc/</guid><description>High severity — web · CVE-2026-37071. Status: PoC. Affects: Veno File Manager Project. Tags: file-manager, privilege-escalation, arbitrary-file-rename, php, authenticated, veno-file-manager.</description><category>web</category><category>High</category><category>file-manager</category><category>privilege-escalation</category><category>arbitrary-file-rename</category><category>php</category><category>authenticated</category><category>veno-file-manager</category></item><item><title>Tandoor Recipes Authenticated Local File Disclosure via Recipe Import (CVE-2026-25964)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25964-tandoor-recipes-lfi/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25964-tandoor-recipes-lfi/</guid><description>Medium severity (CVSS 4.9) — web · CVE-2026-25964 (GHSA-6485-jr28-52xx). Status: PoC. Affects: Tandoor Recipes (self-hosted recipe manager, Django-based). Tags: path-traversal, local-file-disclosure, tandoor-recipes, django, rest-api, authenticated, cwe-22, arbitrary-file-read.</description><category>web</category><category>Medium</category><category>path-traversal</category><category>local-file-disclosure</category><category>tandoor-recipes</category><category>django</category><category>rest-api</category><category>authenticated</category><category>cwe-22</category><category>arbitrary-file-read</category></item><item><title>PbootCMS Authenticated RCE via sitecopyright Field (CVE-2026-36239)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-36239-pbootcms-authenticated-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-36239-pbootcms-authenticated-rce/</guid><description>Critical severity — web · CVE-2026-36239. Status: Weaponized. Affects: PbootCMS. Tags: pbootcms, rce, authenticated, code-injection, template-injection, cwe-94.</description><category>web</category><category>Critical</category><category>pbootcms</category><category>rce</category><category>authenticated</category><category>code-injection</category><category>template-injection</category><category>cwe-94</category></item><item><title>OpenWebUI "Tools" Unsandboxed exec() Remote Code Execution — CVE-2026-0766</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0766-openwebui-tool-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0766-openwebui-tool-rce/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-0766 (ZDI-26-032, GHSA-cggw-334c-f4mj). Status: Weaponized. Affects: OpenWebUI (self-hosted LLM web interface). Tags: openwebui, llm, code-injection, exec, tool-creation, cwe-94, rce, authenticated.</description><category>web</category><category>High</category><category>openwebui</category><category>llm</category><category>code-injection</category><category>exec</category><category>tool-creation</category><category>cwe-94</category><category>rce</category><category>authenticated</category></item><item><title>OpenSTAManager Scadenzario Bulk Operations Error-Based SQL Injection — CVE-2026-24418</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24418-openstamanager-sqli-scadenzario/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24418-openstamanager-sqli-scadenzario/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-24418. Status: Weaponized. Affects: OpenSTAManager (devcode-it/openstamanager). Tags: sql-injection, error-based, openstamanager, php, extractvalue, rce, credential-theft, authenticated.</description><category>web</category><category>High</category><category>sql-injection</category><category>error-based</category><category>openstamanager</category><category>php</category><category>extractvalue</category><category>rce</category><category>credential-theft</category><category>authenticated</category></item><item><title>OpenSTAManager Prima Nota Error-Based SQL Injection — CVE-2026-24419</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24419-openstamanager-sqli-prima-nota/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24419-openstamanager-sqli-prima-nota/</guid><description>High severity — web · CVE-2026-24419. Status: PoC. Affects: OpenSTAManager (devcode-it/openstamanager). Tags: sql-injection, error-based, openstamanager, php, extractvalue, credential-theft, authenticated.</description><category>web</category><category>High</category><category>sql-injection</category><category>error-based</category><category>openstamanager</category><category>php</category><category>extractvalue</category><category>credential-theft</category><category>authenticated</category></item><item><title>OpenSTAManager Global Search Amplified Time-Based Blind SQL Injection — CVE-2026-24417</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24417-openstamanager-sqli-search-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24417-openstamanager-sqli-search-dos/</guid><description>High severity — web · CVE-2026-24417. Status: PoC. Affects: OpenSTAManager (devcode-it/openstamanager). Tags: sql-injection, time-based-blind, openstamanager, php, denial-of-service, ajax, authenticated.</description><category>web</category><category>High</category><category>sql-injection</category><category>time-based-blind</category><category>openstamanager</category><category>php</category><category>denial-of-service</category><category>ajax</category><category>authenticated</category></item><item><title>OpenSTAManager Article Pricing Time-Based Blind SQL Injection — CVE-2026-24416</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24416-openstamanager-sqli-article-pricing/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24416-openstamanager-sqli-article-pricing/</guid><description>High severity — web · CVE-2026-24416. Status: PoC. Affects: OpenSTAManager (devcode-it/openstamanager). Tags: sql-injection, time-based-blind, openstamanager, php, ajax, credential-theft, authenticated.</description><category>web</category><category>High</category><category>sql-injection</category><category>time-based-blind</category><category>openstamanager</category><category>php</category><category>ajax</category><category>credential-theft</category><category>authenticated</category></item><item><title>OpenRemote — Expression Injection RCE in Rules Engine (CVE-2026-39842)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-39842-openremote-expression-injection-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-39842-openremote-expression-injection-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-39842 / GHSA-7mqr-33rv-p3mp. Status: Weaponized. Affects: OpenRemote (IoT device/rules management platform). Tags: openremote, iot, nashorn, javascript-injection, rules-engine, rce, authenticated, root.</description><category>web</category><category>Critical</category><category>openremote</category><category>iot</category><category>nashorn</category><category>javascript-injection</category><category>rules-engine</category><category>rce</category><category>authenticated</category><category>root</category></item><item><title>OpenEMR EtherFax Module Authenticated Arbitrary File Read (CVE-2026-24849)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24849-openemr-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24849-openemr-path-traversal/</guid><description>Critical severity (CVSS 6.5) — web · CVE-2026-24849. Status: PoC. Affects: OpenEMR (Fax/SMS module, EtherFax provider). Tags: openemr, path-traversal, arbitrary-file-read, cwe-22, php, healthcare, phi-exposure, authenticated.</description><category>web</category><category>Critical</category><category>openemr</category><category>path-traversal</category><category>arbitrary-file-read</category><category>cwe-22</category><category>php</category><category>healthcare</category><category>phi-exposure</category><category>authenticated</category></item><item><title>Neo4j Bolt Transaction Metadata Log Injection (CVE-2026-1337)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-1337-neo4j-log-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-1337-neo4j-log-injection/</guid><description>Low severity — network · CVE-2026-1337. Status: PoC. Affects: Neo4j graph database (Bolt protocol, query.log). Tags: neo4j, log-injection, bolt-protocol, log-forgery, graph-database, authenticated, ansi-injection.</description><category>network</category><category>Low</category><category>neo4j</category><category>log-injection</category><category>bolt-protocol</category><category>log-forgery</category><category>graph-database</category><category>authenticated</category><category>ansi-injection</category></item><item><title>LiteLLM Guardrail Custom-Code Sandbox Escape to Root RCE (CVE-2026-40217)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40217-litellm-guardrail-sandbox-escape/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40217-litellm-guardrail-sandbox-escape/</guid><description>Critical severity (CVSS 8.8) — web · CVE-2026-40217 (X41-2026-001, GHSA-3926-2jvf-fg29). Status: PoC. Affects: LiteLLM (open-source LLM proxy/gateway), POST /guardrails/test_custom_code endpoint. Tags: litellm, llm-proxy, sandbox-escape, bytecode-manipulation, cwe-913, docker, root-rce, authenticated.</description><category>web</category><category>Critical</category><category>litellm</category><category>llm-proxy</category><category>sandbox-escape</category><category>bytecode-manipulation</category><category>cwe-913</category><category>docker</category><category>root-rce</category><category>authenticated</category></item><item><title>LatePoint Calendar Booking Plugin Contributor-to-Administrator Privilege Escalation (CVE-2026-49083)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-49083-latepoint-privilege-escalation/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-49083-latepoint-privilege-escalation/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-49083. Status: PoC. Affects: LatePoint Calendar Booking plugin for WordPress. Tags: wordpress, latepoint, privilege-escalation, plugin, ajax, python, authenticated.</description><category>web</category><category>High</category><category>wordpress</category><category>latepoint</category><category>privilege-escalation</category><category>plugin</category><category>ajax</category><category>python</category><category>authenticated</category></item><item><title>Krayin CRM — TinyMCE Upload Unrestricted File Upload to RCE (CVE-2026-38526)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-38526-krayin-crm-file-upload-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-38526-krayin-crm-file-upload-rce/</guid><description>Critical severity — web · CVE-2026-38526. Status: Weaponized. Affects: Krayin CRM. Tags: krayin-crm, laravel, unrestricted-file-upload, tinymce, rce, reverse-shell, authenticated.</description><category>web</category><category>Critical</category><category>krayin-crm</category><category>laravel</category><category>unrestricted-file-upload</category><category>tinymce</category><category>rce</category><category>reverse-shell</category><category>authenticated</category></item><item><title>ITFlow Time-Based Blind SQL Injection via agent/ajax.php expires Parameter (CVE-2026-54597)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-54597-itflow-blind-sqli-expires/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-54597-itflow-blind-sqli-expires/</guid><description>High severity — web · CVE-2026-54597. Status: Weaponized. Affects: ITFlow (open-source MSP/IT management platform). Tags: itflow, sql-injection, blind-sqli, time-based, authenticated, cwe-89.</description><category>web</category><category>High</category><category>itflow</category><category>sql-injection</category><category>blind-sqli</category><category>time-based</category><category>authenticated</category><category>cwe-89</category></item><item><title>ITFlow SQL Injection via recurring_invoice_frequency (CVE-2026-54596)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-54596-itflow-sqli-recurring-invoice/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-54596-itflow-sqli-recurring-invoice/</guid><description>High severity — web · CVE-2026-54596. Status: Weaponized. Affects: ITFlow (open-source MSP/IT management platform). Tags: itflow, sql-injection, authenticated, technician-role, cwe-89.</description><category>web</category><category>High</category><category>itflow</category><category>sql-injection</category><category>authenticated</category><category>technician-role</category><category>cwe-89</category></item><item><title>Hustle (WordPress Popup) Authenticated Arbitrary File Upload via Module Import (CVE-2026-0911)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0911-hustle-wordpress-upload/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0911-hustle-wordpress-upload/</guid><description>High severity — web · CVE-2026-0911. Status: PoC. Affects: Hustle (wordpress-popup) plugin by WPMU DEV. Tags: wordpress, hustle, plugin, file-upload, rce, wp_handle_upload, orphan-file, authenticated, cwe-434.</description><category>web</category><category>High</category><category>wordpress</category><category>hustle</category><category>plugin</category><category>file-upload</category><category>rce</category><category>wp_handle_upload</category><category>orphan-file</category><category>authenticated</category><category>cwe-434</category></item><item><title>Group-Office TNEF Attachment Handler OS Command Injection (CVE-2026-25512)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25512-groupoffice-tnef-command-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25512-groupoffice-tnef-command-injection/</guid><description>Critical severity (CVSS 9.4) — web · CVE-2026-25512. Status: Weaponized. Affects: Group-Office groupware/webmail suite. Tags: command-injection, rce, groupware, email, tnef, cwe-78, authenticated, webmail.</description><category>web</category><category>Critical</category><category>command-injection</category><category>rce</category><category>groupware</category><category>email</category><category>tnef</category><category>cwe-78</category><category>authenticated</category><category>webmail</category></item><item><title>Group-Office PHP Deserialization Remote Code Execution (CVE-2026-34838)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-34838-groupoffice-deserialization-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-34838-groupoffice-deserialization-rce/</guid><description>Critical severity — web · CVE-2026-34838 (GHSA-h22j-frrf-5vxq). Status: PoC. Affects: Group-Office groupware suite. Tags: php, deserialization, rce, groupware, gadget-chain, authenticated, group-office, guzzlehttp.</description><category>web</category><category>Critical</category><category>php</category><category>deserialization</category><category>rce</category><category>groupware</category><category>gadget-chain</category><category>authenticated</category><category>group-office</category><category>guzzlehttp</category></item><item><title>Gogs Wiki Arbitrary File Deletion via Path Traversal (CVE-2026-24135)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24135-gogs-wiki-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24135-gogs-wiki-path-traversal/</guid><description>High severity (CVSS 7.5) — web · CVE-2026-24135 (GHSA-jp7c-wj6q-3qf2). Status: PoC. Affects: Gogs self-hosted Git service. Tags: gogs, path-traversal, arbitrary-file-deletion, wiki, git-service, authenticated, go.</description><category>web</category><category>High</category><category>gogs</category><category>path-traversal</category><category>arbitrary-file-deletion</category><category>wiki</category><category>git-service</category><category>authenticated</category><category>go</category></item><item><title>Gogs Organization-Name Path Traversal to RCE via Git Hooks — CVE-2026-52813</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-52813-gogs-path-traversal-hook-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-52813-gogs-path-traversal-hook-rce/</guid><description>Info severity — web · CVE-2026-52813. Status: PoC. Affects: Gogs (self-hosted Git service), organization creation feature. Tags: gogs, path-traversal, git-hooks, rce, authenticated, account-takeover, self-hosted-git.</description><category>web</category><category>Info</category><category>gogs</category><category>path-traversal</category><category>git-hooks</category><category>rce</category><category>authenticated</category><category>account-takeover</category><category>self-hosted-git</category></item><item><title>EspoCRM Authenticated RCE via Formula ACL Bypass + Attachment Path Traversal — CVE-2026-33656</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33656-espocrm-formula-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33656-espocrm-formula-rce/</guid><description>Critical severity — web · CVE-2026-33656. Status: Weaponized. Affects: EspoCRM &lt;= 9.3.3. Tags: espocrm, rce, path-traversal, webshell, htaccess-poisoning, formula-engine, authenticated, crm.</description><category>web</category><category>Critical</category><category>espocrm</category><category>rce</category><category>path-traversal</category><category>webshell</category><category>htaccess-poisoning</category><category>formula-engine</category><category>authenticated</category><category>crm</category></item><item><title>EspoCRM 9.3.3 Stored HTML Injection in Email Notifications — CVE-2026-33657</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33657-espocrm-stored-html-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33657-espocrm-stored-html-injection/</guid><description>Medium severity — web · CVE-2026-33657. Status: PoC. Affects: EspoCRM 9.3.3. Tags: espocrm, html-injection, stored-xss, cwe-80, email-notifications, authenticated, crm, template-injection.</description><category>web</category><category>Medium</category><category>espocrm</category><category>html-injection</category><category>stored-xss</category><category>cwe-80</category><category>email-notifications</category><category>authenticated</category><category>crm</category><category>template-injection</category></item><item><title>EspoCRM 9.3.3 Authenticated SSRF via Alternative IPv4 Loopback Notation — CVE-2026-33534</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33534-espocrm-ssrf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33534-espocrm-ssrf/</guid><description>Medium severity — web · CVE-2026-33534. Status: PoC. Affects: EspoCRM 9.3.3. Tags: espocrm, ssrf, cwe-918, ipv4-obfuscation, authenticated, crm, file-upload, python.</description><category>web</category><category>Medium</category><category>espocrm</category><category>ssrf</category><category>cwe-918</category><category>ipv4-obfuscation</category><category>authenticated</category><category>crm</category><category>file-upload</category><category>python</category></item><item><title>EGroupware Nextmatch Filter Authenticated SQL Injection (CVE-2026-22243)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-22243-egroupware-sqli/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-22243-egroupware-sqli/</guid><description>Critical severity — web · CVE-2026-22243. Status: PoC. Affects: EGroupware (groupware/collaboration suite). Tags: sql-injection, egroupware, php-type-juggling, authenticated, error-based-sqli, nextmatch, json.</description><category>web</category><category>Critical</category><category>sql-injection</category><category>egroupware</category><category>php-type-juggling</category><category>authenticated</category><category>error-based-sqli</category><category>nextmatch</category><category>json</category></item><item><title>Dolibarr selectobject.php Authenticated Local File Inclusion (CVE-2026-34036)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-34036-dolibarr-selectobject-lfi/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-34036-dolibarr-selectobject-lfi/</guid><description>Medium severity — web · CVE-2026-34036. Status: PoC. Affects: Dolibarr ERP/CRM. Tags: dolibarr, lfi, local-file-inclusion, authenticated, crm, ajax, php.</description><category>web</category><category>Medium</category><category>dolibarr</category><category>lfi</category><category>local-file-inclusion</category><category>authenticated</category><category>crm</category><category>ajax</category><category>php</category></item><item><title>Dolibarr ERP/CRM OS Command Injection via MAIN_ODT_AS_PDF (CVE-2026-23500)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23500-dolibarr-command-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23500-dolibarr-command-injection/</guid><description>Critical severity — web · CVE-2026-23500 / GHSA-w5j3-8fcr-h87w. Status: PoC. Affects: Dolibarr ERP/CRM. Tags: dolibarr, os-command-injection, rce, authenticated, php, odt-to-pdf, reverse-shell, erp.</description><category>web</category><category>Critical</category><category>dolibarr</category><category>os-command-injection</category><category>rce</category><category>authenticated</category><category>php</category><category>odt-to-pdf</category><category>reverse-shell</category><category>erp</category></item><item><title>DbGate `loadReader` `functionName` Injection RCE (CVE-2026-48017)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-48017-dbgate-loadreader-functionname-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-48017-dbgate-loadreader-functionname-rce/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-48017 / GHSA-hv83-ggc4-v385. Status: PoC. Affects: DbGate (dbgate-api), a web-based database management GUI. Tags: dbgate, nodejs, code-injection, rce, cwe-94, authenticated, database-gui.</description><category>web</category><category>High</category><category>dbgate</category><category>nodejs</category><category>code-injection</category><category>rce</category><category>cwe-94</category><category>authenticated</category><category>database-gui</category></item><item><title>Chamilo LMS Authenticated RCE via Unrestricted File Upload — CVE-2026-29041</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-29041-chamilo-lms-file-upload-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-29041-chamilo-lms-file-upload-rce/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-29041. Status: Weaponized. Affects: Chamilo LMS. Tags: chamilo, lms, file-upload, rce, webshell, cwe-434, mime-bypass, authenticated.</description><category>web</category><category>High</category><category>chamilo</category><category>lms</category><category>file-upload</category><category>rce</category><category>webshell</category><category>cwe-434</category><category>mime-bypass</category><category>authenticated</category></item><item><title>Casdoor Authenticated Path Traversal to Arbitrary File Write (CVE-2026-6815)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-6815-casdoor-path-traversal-file-write/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-6815-casdoor-path-traversal-file-write/</guid><description>High severity — web · CVE-2026-6815. Status: Weaponized. Affects: Casdoor (open-source identity/access management platform). Tags: casdoor, path-traversal, arbitrary-file-write, rce, dos, authenticated, cwe-22.</description><category>web</category><category>High</category><category>casdoor</category><category>path-traversal</category><category>arbitrary-file-write</category><category>rce</category><category>dos</category><category>authenticated</category><category>cwe-22</category></item><item><title>Cacti Authenticated OS Command Injection via Host Notes Variable (CVE-2026-39949)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-39949-cacti-host-variable-command-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-39949-cacti-host-variable-command-injection/</guid><description>High severity — web · CVE-2026-39949. Status: PoC. Affects: Cacti network monitoring platform. Tags: cacti, command-injection, cwe-78, rrdtool, authenticated, rce, oob, network-monitoring.</description><category>web</category><category>High</category><category>cacti</category><category>command-injection</category><category>cwe-78</category><category>rrdtool</category><category>authenticated</category><category>rce</category><category>oob</category><category>network-monitoring</category></item><item><title>BoidCMS — Authenticated File Upload to RCE via Template Injection (CVE-2026-39387)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-39387-boidcms-file-upload-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-39387-boidcms-file-upload-rce/</guid><description>High severity — web · CVE-2026-39387. Status: Weaponized. Affects: BoidCMS. Tags: boidcms, php, authenticated, file-upload, path-traversal, template-injection, rce.</description><category>web</category><category>High</category><category>boidcms</category><category>php</category><category>authenticated</category><category>file-upload</category><category>path-traversal</category><category>template-injection</category><category>rce</category></item><item><title>Bludit CMS API Unrestricted File Upload to RCE (CVE-2026-25099)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25099-bludit-webshell-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25099-bludit-webshell-rce/</guid><description>High severity — web · CVE-2026-25099. Status: Weaponized. Affects: Bludit CMS (/api/files/&lt;page-key> endpoint). Tags: bludit, cms, file-upload, webshell, rce, php, api-token, cwe-434, authenticated.</description><category>web</category><category>High</category><category>bludit</category><category>cms</category><category>file-upload</category><category>webshell</category><category>rce</category><category>php</category><category>api-token</category><category>cwe-434</category><category>authenticated</category></item><item><title>Apache Superset Authenticated SQL Injection via sqlExpression/where Bypass — CVE-2026-23980</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23980-superset-sqli/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23980-superset-sqli/</guid><description>Medium severity (CVSS 6.5) — web · CVE-2026-23980. Status: PoC. Affects: Apache Superset. Tags: apache-superset, sql-injection, error-based-sqli, postgresql, authenticated, api, python, cwe-89.</description><category>web</category><category>Medium</category><category>apache-superset</category><category>sql-injection</category><category>error-based-sqli</category><category>postgresql</category><category>authenticated</category><category>api</category><category>python</category><category>cwe-89</category></item></channel></rss>