<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>CWE-79 — PoC Archive</title><link>https://poc.intelseclab.com/tags/cwe-79/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 09 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/cwe-79/index.xml" rel="self" type="application/rss+xml"/><item><title>WordPress — Pre-Auth XSS to RCE Chain via Login Page Parser Differential (CVE-2026-64638, "XSS2Shell")</title><link>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2026-64638-wordpress-xss2shell-pre-auth-xss-to-rce/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2026-64638-wordpress-xss2shell-pre-auth-xss-to-rce/</guid><description>High severity (CVSS 8.9) — web · CVE-2026-64638. Status: Patched. Affects: WordPress Core, wp-login.php failed-login error message, KSES sanitizer vs PHP strip_tags(). Tags: wordpress, wordpress-core, pre-auth, xss, reflected-xss, xss2shell, rce, parser-differential, dom-clobbering, some, jsonp, rest-api, application-password, plugin-upload, CWE-79, CWE-94, cms.</description><category>web</category><category>High</category><category>wordpress</category><category>wordpress-core</category><category>pre-auth</category><category>xss</category><category>reflected-xss</category><category>xss2shell</category><category>rce</category><category>parser-differential</category><category>dom-clobbering</category><category>some</category><category>jsonp</category><category>rest-api</category><category>application-password</category><category>plugin-upload</category><category>CWE-79</category><category>CWE-94</category><category>cms</category></item><item><title>WP Time Slots Booking Form Unauthenticated Stored XSS (CVE-2026-40791)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40791-wp-time-slots-booking-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40791-wp-time-slots-booking-xss/</guid><description>High severity (CVSS 7.2) — web · CVE-2026-40791. Status: PoC. Affects: WP Time Slots Booking Form (wp-time-slots-booking-form WordPress plugin). Tags: wordpress, wordpress-plugin, stored-xss, unauthenticated, cwe-79, admin-takeover, booking-form.</description><category>web</category><category>High</category><category>wordpress</category><category>wordpress-plugin</category><category>stored-xss</category><category>unauthenticated</category><category>cwe-79</category><category>admin-takeover</category><category>booking-form</category></item><item><title>TypiCMS Core — Stored XSS via Unsanitized SVG File Upload (CVE-2026-27621)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27621-typicms-svg-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27621-typicms-svg-xss/</guid><description>Medium severity — web · CVE-2026-27621 (GHSA-xfvg-8v67-j7wp). Status: PoC. Affects: TypiCMS Core (typicms/core). Tags: typicms, stored-xss, svg-upload, cwe-79, cms, file-upload, laravel, session-hijack.</description><category>web</category><category>Medium</category><category>typicms</category><category>stored-xss</category><category>svg-upload</category><category>cwe-79</category><category>cms</category><category>file-upload</category><category>laravel</category><category>session-hijack</category></item><item><title>School Management System 1.0 — Reflected XSS in register.php (CVE-2026-37750)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-37750-school-management-system-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-37750-school-management-system-xss/</guid><description>Medium severity (CVSS 6.1) — web · CVE-2026-37750. Status: PoC. Affects: School Management System (mahmoudai1) 1.0. Tags: php, reflected-xss, cwe-79, unauthenticated, cookie-theft, school-management-system.</description><category>web</category><category>Medium</category><category>php</category><category>reflected-xss</category><category>cwe-79</category><category>unauthenticated</category><category>cookie-theft</category><category>school-management-system</category></item><item><title>Saleor Rich Text (EditorJS) Field Stored XSS (CVE-2026-22849)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-22849-saleor-richtext-stored-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-22849-saleor-richtext-stored-xss/</guid><description>High severity — web · CVE-2026-22849 (GHSA-8jcj-r5g2-qrpv). Status: PoC. Affects: Saleor (open-source e-commerce platform), rich text fields (EditorJS content on pages/products). Tags: saleor, stored-xss, editorjs, graphql, ecommerce, session-hijacking, cwe-79.</description><category>web</category><category>High</category><category>saleor</category><category>stored-xss</category><category>editorjs</category><category>graphql</category><category>ecommerce</category><category>session-hijacking</category><category>cwe-79</category></item><item><title>oRPC OpenAPI Reference Plugin Stored XSS via Unescaped Spec Embedding (CVE-2026-33331)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33331-orpc-openapi-stored-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33331-orpc-openapi-stored-xss/</guid><description>High severity — web · CVE-2026-33331 (GHSA-7f6v-3gx7-27q8). Status: PoC. Affects: middleapi/orpc — OpenAPI documentation reference plugin (packages/openapi/src/plugins/openapi-reference.ts). Tags: xss, stored-xss, orpc, openapi, cwe-79, javascript, nodejs, docs-page.</description><category>web</category><category>High</category><category>xss</category><category>stored-xss</category><category>orpc</category><category>openapi</category><category>cwe-79</category><category>javascript</category><category>nodejs</category><category>docs-page</category></item><item><title>OpenSTAManager Reflected XSS via `righe` Parameter (CVE-2026-24415)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24415-openstamanager-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24415-openstamanager-xss/</guid><description>Medium severity — web · CVE-2026-24415 (GHSA-jfgp-g7x7-j25j). Status: PoC. Affects: OpenSTAManager (devcode-it/openstamanager). Tags: xss, reflected-xss, openstamanager, cwe-79, session-hijacking, php, unauthenticated-payload.</description><category>web</category><category>Medium</category><category>xss</category><category>reflected-xss</category><category>openstamanager</category><category>cwe-79</category><category>session-hijacking</category><category>php</category><category>unauthenticated-payload</category></item><item><title>Gravity Forms Unauthenticated Reflected XSS via `gform_get_config` `form_ids` Parameter (CVE-2026-4406)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-4406-gravity-forms-reflected-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-4406-gravity-forms-reflected-xss/</guid><description>Medium severity (CVSS 6.1) — web · CVE-2026-4406. Status: PoC. Affects: Gravity Forms (WordPress plugin) by Rocketgenius, Inc.. Tags: wordpress, gravity-forms, xss, reflected-xss, admin-ajax, unauthenticated, cwe-79.</description><category>web</category><category>Medium</category><category>wordpress</category><category>gravity-forms</category><category>xss</category><category>reflected-xss</category><category>admin-ajax</category><category>unauthenticated</category><category>cwe-79</category></item><item><title>ElementsKit Elementor Addons Authenticated Stored XSS via REST API (CVE-2026-2600)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-2600-elementskit-stored-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-2600-elementskit-stored-xss/</guid><description>Medium severity (CVSS 6.4) — web · CVE-2026-2600. Status: Weaponized. Affects: ElementsKit Elementor Addons (WordPress plugin). Tags: wordpress, elementor, stored-xss, rest-api, privilege-escalation, contributor, plugin, cwe-79.</description><category>web</category><category>Medium</category><category>wordpress</category><category>elementor</category><category>stored-xss</category><category>rest-api</category><category>privilege-escalation</category><category>contributor</category><category>plugin</category><category>cwe-79</category></item><item><title>Bookly Booking Form Cookie-Based Stored XSS — CVE-2026-5513</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5513-bookly-cookie-stored-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5513-bookly-cookie-stored-xss/</guid><description>High severity (CVSS 7.2) — web · CVE-2026-5513. Status: PoC. Affects: Bookly — Online Scheduling and Appointment Booking System (WordPress plugin). Tags: wordpress, bookly, stored-xss, cwe-79, cookie-injection, appointment-booking.</description><category>web</category><category>High</category><category>wordpress</category><category>bookly</category><category>stored-xss</category><category>cwe-79</category><category>cookie-injection</category><category>appointment-booking</category></item></channel></rss>