<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cms — PoC Archive</title><link>https://poc.intelseclab.com/tags/cms/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 09 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/cms/index.xml" rel="self" type="application/rss+xml"/><item><title>WordPress — Pre-Auth XSS to RCE Chain via Login Page Parser Differential (CVE-2026-64638, "XSS2Shell")</title><link>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2026-64638-wordpress-xss2shell-pre-auth-xss-to-rce/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2026-64638-wordpress-xss2shell-pre-auth-xss-to-rce/</guid><description>High severity (CVSS 8.9) — web · CVE-2026-64638. Status: Patched. Affects: WordPress Core, wp-login.php failed-login error message, KSES sanitizer vs PHP strip_tags(). Tags: wordpress, wordpress-core, pre-auth, xss, reflected-xss, xss2shell, rce, parser-differential, dom-clobbering, some, jsonp, rest-api, application-password, plugin-upload, CWE-79, CWE-94, cms.</description><category>web</category><category>High</category><category>wordpress</category><category>wordpress-core</category><category>pre-auth</category><category>xss</category><category>reflected-xss</category><category>xss2shell</category><category>rce</category><category>parser-differential</category><category>dom-clobbering</category><category>some</category><category>jsonp</category><category>rest-api</category><category>application-password</category><category>plugin-upload</category><category>CWE-79</category><category>CWE-94</category><category>cms</category></item><item><title>Unauthenticated Arbitrary File Upload RCE in iCagenda for Joomla (CVE-2026-48939)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2026-48939-icagenda-joomla-file-upload-rce/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2026-48939-icagenda-joomla-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-48939. Status: Weaponized (public PoC available, actively exploited in the wild, in CISA KEV since 2026-07-10). Affects: iCagenda — events/calendar extension (component) for Joomla. Tags: joomla, icagenda, file-upload, rce, cwe-434, unauthenticated, remote, kev, cms, php, access-control-bypass.</description><category>web</category><category>Critical</category><category>joomla</category><category>icagenda</category><category>file-upload</category><category>rce</category><category>cwe-434</category><category>unauthenticated</category><category>remote</category><category>kev</category><category>cms</category><category>php</category><category>access-control-bypass</category></item><item><title>Sitecore XP Report.ashx Insecure Deserialization RCE (CVE-2021-42237)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2021-42237-sitecore-xp-deserialization-rce/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2021-42237-sitecore-xp-deserialization-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2021-42237 (Sitecore advisory SC2021-003-499266). Status: Weaponized (public PoC + Metasploit module, in CISA KEV, known ransomware campaign use). Affects: Sitecore Experience Platform (XP). Tags: sitecore, deserialization, rce, cms, unauthenticated, remote, kev, known-ransomware-use, cwe-502.</description><category>web</category><category>Critical</category><category>sitecore</category><category>deserialization</category><category>rce</category><category>cms</category><category>unauthenticated</category><category>remote</category><category>kev</category><category>known-ransomware-use</category><category>cwe-502</category></item><item><title>VvvebJs SVG Upload Stored Cross-Site Scripting — CVE-2026-5615</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5615-vvvebjs-svg-stored-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5615-vvvebjs-svg-stored-xss/</guid><description>High severity (CVSS 8.5) — web · CVE-2026-5615. Status: PoC. Affects: VvvebJs (drag-and-drop website builder). Tags: vvvebjs, stored-xss, svg-upload, file-upload, cms.</description><category>web</category><category>High</category><category>vvvebjs</category><category>stored-xss</category><category>svg-upload</category><category>file-upload</category><category>cms</category></item><item><title>TypiCMS Core — Stored XSS via Unsanitized SVG File Upload (CVE-2026-27621)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27621-typicms-svg-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27621-typicms-svg-xss/</guid><description>Medium severity — web · CVE-2026-27621 (GHSA-xfvg-8v67-j7wp). Status: PoC. Affects: TypiCMS Core (typicms/core). Tags: typicms, stored-xss, svg-upload, cwe-79, cms, file-upload, laravel, session-hijack.</description><category>web</category><category>Medium</category><category>typicms</category><category>stored-xss</category><category>svg-upload</category><category>cwe-79</category><category>cms</category><category>file-upload</category><category>laravel</category><category>session-hijack</category></item><item><title>Strapi CMS Admin Account Takeover via Query Filter Bypass — CVE-2026-27886</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27886-strapi-account-takeover/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27886-strapi-account-takeover/</guid><description>Critical severity — web · CVE-2026-27886. Status: Weaponized. Affects: Strapi CMS (Content API). Tags: strapi, cms, account-takeover, password-reset, boolean-oracle, api-filter-bypass, authentication.</description><category>web</category><category>Critical</category><category>strapi</category><category>cms</category><category>account-takeover</category><category>password-reset</category><category>boolean-oracle</category><category>api-filter-bypass</category><category>authentication</category></item><item><title>Joomla Page Builder CK Unauthenticated Arbitrary File Upload RCE — CVE-2026-56290</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-56290-joomla-pagebuilderck-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-56290-joomla-pagebuilderck-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-56290. Status: PoC. Affects: Page Builder CK (com_pagebuilderck) — Joomla extension. Tags: joomla, page-builder-ck, com_pagebuilderck, file-upload, unauth-rce, csrf, cms.</description><category>web</category><category>Critical</category><category>joomla</category><category>page-builder-ck</category><category>com_pagebuilderck</category><category>file-upload</category><category>unauth-rce</category><category>csrf</category><category>cms</category></item><item><title>Joomla Novarain Framework (nrframework) Unauthenticated Arbitrary File Inclusion — CVE-2026-21627</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-21627-joomla-nrframework-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-21627-joomla-nrframework-rce/</guid><description>Critical severity (CVSS 9.5) — web · CVE-2026-21627. Status: Weaponized. Affects: plg_system_nrframework (Tassos/Novarain Framework) Joomla plugin, bundled with Convert Forms, Engage Box, Google Structured Data, and other Tassos.gr extensions. Tags: joomla, nrframework, file-inclusion, unauthenticated, arbitrary-file-upload, arbitrary-file-delete, php, cms.</description><category>web</category><category>Critical</category><category>joomla</category><category>nrframework</category><category>file-inclusion</category><category>unauthenticated</category><category>arbitrary-file-upload</category><category>arbitrary-file-delete</category><category>php</category><category>cms</category></item><item><title>HAXcms Node.js Private Key Disclosure via Broken HMAC (CVE-2026-46395)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-46395-haxcms-hmac-key-leak/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-46395-haxcms-hmac-key-leak/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-46395. Status: PoC. Affects: HAXcms Node.js backend (elmsln/HAXcms, haxcms-nodejs) — src/lib/HAXCMS.js. Tags: haxcms, nodejs, hmac, jwt-forgery, cwe-321, cwe-200, key-disclosure, cms.</description><category>web</category><category>Critical</category><category>haxcms</category><category>nodejs</category><category>hmac</category><category>jwt-forgery</category><category>cwe-321</category><category>cwe-200</category><category>key-disclosure</category><category>cms</category></item><item><title>HAXcms Git.php OS Command Injection (CVE-2026-46394)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-46394-haxcms-git-command-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-46394-haxcms-git-command-injection/</guid><description>High severity (CVSS 7.2) — web · CVE-2026-46394. Status: PoC. Affects: HAXcms PHP backend (elmsln/HAXcms) — system/backend/php/lib/Git.php. Tags: haxcms, php, command-injection, cwe-78, git, proc_open, cms.</description><category>web</category><category>High</category><category>haxcms</category><category>php</category><category>command-injection</category><category>cwe-78</category><category>git</category><category>proc_open</category><category>cms</category></item><item><title>Bludit CMS API Unrestricted File Upload to RCE (CVE-2026-25099)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25099-bludit-webshell-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25099-bludit-webshell-rce/</guid><description>High severity — web · CVE-2026-25099. Status: Weaponized. Affects: Bludit CMS (/api/files/&lt;page-key> endpoint). Tags: bludit, cms, file-upload, webshell, rce, php, api-token, cwe-434, authenticated.</description><category>web</category><category>High</category><category>bludit</category><category>cms</category><category>file-upload</category><category>webshell</category><category>rce</category><category>php</category><category>api-token</category><category>cwe-434</category><category>authenticated</category></item><item><title>Azuriom CMS Broken Access Control — Account Takeover via AzLink Server Token — CVE-2026-54415</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-54415-azuriom-account-takeover/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-54415-azuriom-account-takeover/</guid><description>High severity (CVSS 3.1) — web · CVE-2026-54415. Status: PoC. Affects: Azuriom CMS. Tags: azuriom, cms, broken-access-control, cwe-862, cwe-269, privilege-escalation, account-takeover, php, laravel, azlink.</description><category>web</category><category>High</category><category>azuriom</category><category>cms</category><category>broken-access-control</category><category>cwe-862</category><category>cwe-269</category><category>privilege-escalation</category><category>account-takeover</category><category>php</category><category>laravel</category><category>azlink</category></item><item><title>ApostropheCMS Import — Malicious Tar Archive Path Traversal (CVE-2026-32731)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-32731-apostrophecms-tar-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-32731-apostrophecms-tar-path-traversal/</guid><description>High severity — web · CVE-2026-32731. Status: PoC. Affects: ApostropheCMS (site export/import feature). Tags: apostrophecms, cms, path-traversal, tar-slip, arbitrary-file-write, import, node-js.</description><category>web</category><category>High</category><category>apostrophecms</category><category>cms</category><category>path-traversal</category><category>tar-slip</category><category>arbitrary-file-write</category><category>import</category><category>node-js</category></item><item><title>Unauthenticated RCE in Joomla Content Editor (JCE) Profile Import (CVE-2026-48907)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-01_cve-2026-48907-joomla-jce-unauth-rce/</link><pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-01_cve-2026-48907-joomla-jce-unauth-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-48907. Status: Weaponized. Affects: Joomla Content Editor (JCE) extension by Widget Factory. Tags: RCE, unauthenticated, Joomla, JCE, CMS, access-control, webshell, php-webshell, file-upload, CISA-KEV, active-exploitation.</description><category>web</category><category>Critical</category><category>RCE</category><category>unauthenticated</category><category>Joomla</category><category>JCE</category><category>CMS</category><category>access-control</category><category>webshell</category><category>php-webshell</category><category>file-upload</category><category>CISA-KEV</category><category>active-exploitation</category></item><item><title>SP Page Builder (Joomla) Unauthenticated File Upload RCE (CVE-2026-48908)</title><link>https://poc.intelseclab.com/pocs/web/2026-06-30_cve-2026-48908-sp-page-builder-joomla-rce/</link><pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-06-30_cve-2026-48908-sp-page-builder-joomla-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-48908 (GHSA-8fwr-8fxr-8v2p). Status: Weaponized — public PoC with mass-scan support, added to CISA KEV 2026-07-07, confirmed active in-the-wild exploitation. Affects: SP Page Builder extension for Joomla (joomshaper.net). Tags: RCE, unauthenticated, file-upload, PHP-webshell, Joomla, CMS, access-control, Python, CVSS-10, kev, backdoor, cwe-434.</description><category>web</category><category>Critical</category><category>RCE</category><category>unauthenticated</category><category>file-upload</category><category>PHP-webshell</category><category>Joomla</category><category>CMS</category><category>access-control</category><category>Python</category><category>CVSS-10</category><category>kev</category><category>backdoor</category><category>cwe-434</category></item></channel></rss>