PoC Archive PoC Archive

tag

Cms

WordPress — Pre-Auth XSS to RCE Chain via Login Page Parser Differential (CVE-2026-64638, "XSS2Shell") EPSS 31%
CVE-2026-64638 web Unverified
CVE-2026-64638webHIGH 8.9Unverified2026-08-09Unauthenticated Arbitrary File Upload RCE in iCagenda for Joomla (CVE-2026-48939) KEV EPSS 20%
CVE-2026-48939 web Patched
CVE-2026-48939webCRITICAL 9.8Patched2026-07-11Sitecore XP Report.ashx Insecure Deserialization RCE (CVE-2021-42237) KEV RW EPSS 98%
CVE-2021-42237 (Sitecore advisory SC2021-003-499266) web Patched
CVE-2021-42237webCRITICAL 9.8Patched2026-07-11VvvebJs SVG Upload Stored Cross-Site Scripting — CVE-2026-5615
CVE-2026-5615 web Patched
CVE-2026-5615webHIGH 8.5Patched2026-07-05TypiCMS Core — Stored XSS via Unsanitized SVG File Upload (CVE-2026-27621)
CVE-2026-27621 (GHSA-xfvg-8v67-j7wp) web Patched
CVE-2026-27621webMEDIUMPatched2026-07-05Strapi CMS Admin Account Takeover via Query Filter Bypass — CVE-2026-27886
CVE-2026-27886 web Patched
CVE-2026-27886webCRITICALPatched2026-07-05Joomla Page Builder CK Unauthenticated Arbitrary File Upload RCE — CVE-2026-56290 KEV EPSS 30%
CVE-2026-56290 web Patched
CVE-2026-56290webCRITICAL 9.8Patched2026-07-05Joomla Novarain Framework (nrframework) Unauthenticated Arbitrary File Inclusion — CVE-2026-21627
CVE-2026-21627 web Patched
CVE-2026-21627webCRITICAL 9.5Patched2026-07-05HAXcms Node.js Private Key Disclosure via Broken HMAC (CVE-2026-46395)
CVE-2026-46395 web Patched
CVE-2026-46395webCRITICAL 9.8Patched2026-07-05HAXcms Git.php OS Command Injection (CVE-2026-46394)
CVE-2026-46394 web Patched
CVE-2026-46394webHIGH 7.2Patched2026-07-05Bludit CMS API Unrestricted File Upload to RCE (CVE-2026-25099)
CVE-2026-25099 web Patched
CVE-2026-25099webHIGHPatched2026-07-05Azuriom CMS Broken Access Control — Account Takeover via AzLink Server Token — CVE-2026-54415
CVE-2026-54415 web Patched
CVE-2026-54415webHIGH 3.1Patched2026-07-05ApostropheCMS Import — Malicious Tar Archive Path Traversal (CVE-2026-32731)
CVE-2026-32731 web Patched
CVE-2026-32731webHIGHPatched2026-07-05Unauthenticated RCE in Joomla Content Editor (JCE) Profile Import (CVE-2026-48907) KEV EPSS 78%
CVE-2026-48907 web Patched
CVE-2026-48907webCRITICAL 10Patched2026-07-01SP Page Builder (Joomla) Unauthenticated File Upload RCE (CVE-2026-48908) KEV EPSS 15%
CVE-2026-48908 (GHSA-8fwr-8fxr-8v2p) web Patched
CVE-2026-48908webCRITICAL 10Patched2026-06-30