PoC Archive PoC Archive

tag

Backdoor

High
ProFTPD mod_sql Pre-Auth SQL Injection Leading to RCE (CVE-2026-42167)
CVE-2026-42167· ProFTPD (with mod_sql and SQL-backed logging configured) patched
High
Kanboard — Missing Access Control on Plugin Installation Leads to Administrative RCE via Webshell Plugin (CVE-2026-25924)
CVE-2026-25924 / GHSA-grch-p7vf-vc4f· Kanboard (project management application) patched
Critical
SP Page Builder (Joomla) Unauthenticated File Upload RCE (CVE-2026-48908)
CVE-2026-48908 (GHSA-8fwr-8fxr-8v2p)· SP Page Builder extension for Joomla (joomshaper.net) patched