PoC Archive PoC Archive

tag

Cwe-94

Critical
LLaMA-Factory WebUI Remote Code Execution via Hardcoded `trust_remote_code` (CVE-2026-58116)
CVE-2026-58116· LLaMA-Factory ([hiyouga/LLaMA-Factory](https://github.com/hiyouga/LLaMA-Factory)) — WebUI Chat and Training interfaces unpatched
Critical
XWiki SolrSearch Macro Unauthenticated Groovy RCE (CVE-2025-24893)
CVE-2025-24893· XWiki (SolrSearch macro, Main.SolrSearch) unpatched
Critical
Wing FTP Server NULL-Byte Lua Injection Unauthenticated RCE (CVE-2025-47812)
CVE-2025-47812· Wing FTP Server, web administration/login interface (loginok.html, session mechanism) patched
Critical
Sneeit Framework <= 8.3 Unauthenticated RCE via `call_user_func()` — Rogue Admin Creation (CVE-2025-6389)
CVE-2025-6389· Sneeit Framework (WordPress theme framework plugin, sneeit-framework) unpatched
Critical
Oracle Identity Manager `;.wadl` Authentication Bypass + Groovy Script RCE (CVE-2025-61757)
CVE-2025-61757· Oracle Identity Manager (OIM) — applicationmanagement REST API unpatched
Critical
Mongoose `populate()` Match `$where` Bypass Command Injection (CVE-2025-23061)
CVE-2025-23061· Mongoose (Node.js MongoDB ODM) unpatched
Critical
Invision Community Theme Editor Template Injection Unauthenticated RCE (CVE-2025-47916)
CVE-2025-47916· Invision Community, themeeditor front controller (IPS\core\modules\front\system\themeeditor::customCss()) patched
Critical
IngressNightmare: Kubernetes ingress-nginx Admission Controller Shared-Library Injection RCE (CVE-2025-1974)
CVE-2025-1974· Kubernetes ingress-nginx admission controller unpatched
Critical
Flowise CustomMCP Unauthenticated Remote Code Execution via Function() Constructor (CVE-2025-59528)
CVE-2025-59528· Flowise (FlowiseAI/Flowise) patched
Critical
DataEase PostgreSQL JDBC Datasource-Validation Bypass to Remote Code Execution (CVE-2025-49002)
CVE-2025-49002· DataEase (开源数据可视化分析工具 / open-source BI/data-visualization platform by 飞致云/FIT2CLOUD) unpatched
Critical
ACF Extended (ACFE) `prepare_form()` Unauthenticated RCE via Privilege Escalation (CVE-2025-13486)
CVE-2025-13486· Advanced Custom Fields: Extended (ACFE) — WordPress plugin unpatched
Critical
Spring AI SimpleVectorStore SpEL Injection RCE (CVE-2026-22738)
CVE-2026-22738· Spring AI spring-ai-core (SimpleVectorStore) patched
High
Shopware Twig Rendered-View Code Injection Regression (CVE-2026-23498)
CVE-2026-23498· Shopware (shopware/shopware, shopware/core) patched
Critical
PbootCMS Authenticated RCE via sitecopyright Field (CVE-2026-36239)
CVE-2026-36239· PbootCMS unpatched
High
OpenWebUI "Tools" Unsandboxed exec() Remote Code Execution — CVE-2026-0766
CVE-2026-0766 (ZDI-26-032, GHSA-cggw-334c-f4mj)· OpenWebUI (self-hosted LLM web interface) unpatched
High
Kanboard — Missing Access Control on Plugin Installation Leads to Administrative RCE via Webshell Plugin (CVE-2026-25924)
CVE-2026-25924 / GHSA-grch-p7vf-vc4f· Kanboard (project management application) patched
Critical
DbGate Unauthenticated RCE via JSON Script Runner (CVE-2026-47668)
CVE-2026-47668· DbGate (dbgate-serve — web-based database management tool) patched
High
DbGate `loadReader` `functionName` Injection RCE (CVE-2026-48017)
CVE-2026-48017 / GHSA-hv83-ggc4-v385· DbGate (dbgate-api), a web-based database management GUI patched
Critical
Avada Builder Unauthenticated RCE via call_user_func() Allowlist Bypass (CVE-2026-6279)
CVE-2026-6279· Avada Builder (Fusion Builder) WordPress theme/plugin unpatched