<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>CWE-94 — PoC Archive</title><link>https://poc.intelseclab.com/tags/cwe-94/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 09 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/cwe-94/index.xml" rel="self" type="application/rss+xml"/><item><title>WordPress — Pre-Auth XSS to RCE Chain via Login Page Parser Differential (CVE-2026-64638, "XSS2Shell")</title><link>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2026-64638-wordpress-xss2shell-pre-auth-xss-to-rce/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2026-64638-wordpress-xss2shell-pre-auth-xss-to-rce/</guid><description>High severity (CVSS 8.9) — web · CVE-2026-64638. Status: Patched. Affects: WordPress Core, wp-login.php failed-login error message, KSES sanitizer vs PHP strip_tags(). Tags: wordpress, wordpress-core, pre-auth, xss, reflected-xss, xss2shell, rce, parser-differential, dom-clobbering, some, jsonp, rest-api, application-password, plugin-upload, CWE-79, CWE-94, cms.</description><category>web</category><category>High</category><category>wordpress</category><category>wordpress-core</category><category>pre-auth</category><category>xss</category><category>reflected-xss</category><category>xss2shell</category><category>rce</category><category>parser-differential</category><category>dom-clobbering</category><category>some</category><category>jsonp</category><category>rest-api</category><category>application-password</category><category>plugin-upload</category><category>CWE-79</category><category>CWE-94</category><category>cms</category></item><item><title>Gitea — diffpatch API Git Hook Remote Code Execution (CVE-2026-60004)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2026-60004-gitea-diffpatch-githook-rce/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2026-60004-gitea-diffpatch-githook-rce/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-60004. Status: Patched. Affects: Gitea (self-hosted Git service), diffpatch API endpoint, Git three-way merge fallback. Tags: gitea, git, diffpatch, git-hook, post-index-change, three-way-merge, bare-repository, CWE-94, authenticated-rce, self-hosted, code-hosting.</description><category>web</category><category>High</category><category>gitea</category><category>git</category><category>diffpatch</category><category>git-hook</category><category>post-index-change</category><category>three-way-merge</category><category>bare-repository</category><category>CWE-94</category><category>authenticated-rce</category><category>self-hosted</category><category>code-hosting</category></item><item><title>IBM Langflow OSS Unauthenticated RCE via Auto-Login + validate/code Chain (CVE-2026-9198)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2026-9198-langflow-auto-login-validate-code-rce/</link><pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2026-9198-langflow-auto-login-validate-code-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-9198. Status: Weaponized. Affects: IBM Langflow OSS (visual AI/agent-flow builder). Tags: langflow, ibm, auto-login, code-injection, cwe-94, unauthenticated, rce, python-exec, ai-agent-framework.</description><category>web</category><category>Critical</category><category>langflow</category><category>ibm</category><category>auto-login</category><category>code-injection</category><category>cwe-94</category><category>unauthenticated</category><category>rce</category><category>python-exec</category><category>ai-agent-framework</category></item><item><title>LLaMA-Factory WebUI Remote Code Execution via Hardcoded `trust_remote_code` (CVE-2026-58116)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-58116-llamafactory-trust-remote-code-rce/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-58116-llamafactory-trust-remote-code-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-58116. Status: Weaponized — confirmed code execution via the exact sink LLaMA-Factory reaches. Affects: LLaMA-Factory ([hiyouga/LLaMA-Factory](https://github.com/hiyouga/LLaMA-Factory)) — WebUI Chat and Training interfaces. Tags: llamafactory, llm-training, webui, trust-remote-code, huggingface, transformers, cwe-94, unauthenticated-within-webui, remote-code-execution, ai-supply-chain.</description><category>web</category><category>Critical</category><category>llamafactory</category><category>llm-training</category><category>webui</category><category>trust-remote-code</category><category>huggingface</category><category>transformers</category><category>cwe-94</category><category>unauthenticated-within-webui</category><category>remote-code-execution</category><category>ai-supply-chain</category></item><item><title>XWiki SolrSearch Macro Unauthenticated Groovy RCE (CVE-2025-24893)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-24893-xwiki-solrsearch-groovy-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-24893-xwiki-solrsearch-groovy-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-24893. Status: Weaponized. Affects: XWiki (SolrSearch macro, Main.SolrSearch). Tags: xwiki, groovy, rce, unauthenticated, cwe-94, code-injection, reverse-shell, python, wiki.</description><category>web</category><category>Critical</category><category>xwiki</category><category>groovy</category><category>rce</category><category>unauthenticated</category><category>cwe-94</category><category>code-injection</category><category>reverse-shell</category><category>python</category><category>wiki</category></item><item><title>Wing FTP Server NULL-Byte Lua Injection Unauthenticated RCE (CVE-2025-47812)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-47812-wingftp-null-byte-lua-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-47812-wingftp-null-byte-lua-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-47812. Status: Weaponized. Affects: Wing FTP Server, web administration/login interface (loginok.html, session mechanism). Tags: wingftp, ftp-server, null-byte-injection, lua-injection, unauthenticated-rce, session-file, cwe-94, cwe-158, python.</description><category>web</category><category>Critical</category><category>wingftp</category><category>ftp-server</category><category>null-byte-injection</category><category>lua-injection</category><category>unauthenticated-rce</category><category>session-file</category><category>cwe-94</category><category>cwe-158</category><category>python</category></item><item><title>Sneeit Framework &lt;= 8.3 Unauthenticated RCE via `call_user_func()` — Rogue Admin Creation (CVE-2025-6389)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-6389-wordpress-rogue-admin-user-creation/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-6389-wordpress-rogue-admin-user-creation/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-6389. Status: Weaponized. Affects: Sneeit Framework (WordPress theme framework plugin, sneeit-framework). Tags: wordpress, sneeit-framework, rce, call_user_func, unauthenticated, wp_insert_user, privilege-escalation, admin-takeover, cwe-94, wp-ajax-nopriv.</description><category>web</category><category>Critical</category><category>wordpress</category><category>sneeit-framework</category><category>rce</category><category>call_user_func</category><category>unauthenticated</category><category>wp_insert_user</category><category>privilege-escalation</category><category>admin-takeover</category><category>cwe-94</category><category>wp-ajax-nopriv</category></item><item><title>Oracle Identity Manager `;.wadl` Authentication Bypass + Groovy Script RCE (CVE-2025-61757)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-61757-oracle-identity-manager-auth-bypass-groovy-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-61757-oracle-identity-manager-auth-bypass-groovy-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-61757. Status: PoC. Affects: Oracle Identity Manager (OIM) — applicationmanagement REST API. Tags: oracle, identity-manager, oim, authentication-bypass, rce, groovy, wadl, security-filter, cwe-287, cwe-94.</description><category>web</category><category>Critical</category><category>oracle</category><category>identity-manager</category><category>oim</category><category>authentication-bypass</category><category>rce</category><category>groovy</category><category>wadl</category><category>security-filter</category><category>cwe-287</category><category>cwe-94</category></item><item><title>Mongoose `populate()` Match `$where` Bypass Command Injection (CVE-2025-23061)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-23061-mongoose-command-injection/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-23061-mongoose-command-injection/</guid><description>Critical severity (CVSS 9) — web · CVE-2025-23061. Status: Weaponized. Affects: Mongoose (Node.js MongoDB ODM). Tags: mongoose, nodejs, nosql-injection, mongodb, populate, where-operator, command-injection, rce, cwe-943, cwe-94, express.</description><category>web</category><category>Critical</category><category>mongoose</category><category>nodejs</category><category>nosql-injection</category><category>mongodb</category><category>populate</category><category>where-operator</category><category>command-injection</category><category>rce</category><category>cwe-943</category><category>cwe-94</category><category>express</category></item><item><title>Invision Community Theme Editor Template Injection Unauthenticated RCE (CVE-2025-47916)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-47916-invision-community-template-injection-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-47916-invision-community-template-injection-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-47916. Status: Weaponized. Affects: Invision Community, themeeditor front controller (IPS\core\modules\front\system\themeeditor::customCss()). Tags: invision-community, ssti, template-injection, theme-editor, unauthenticated-rce, php, cwe-94, python.</description><category>web</category><category>Critical</category><category>invision-community</category><category>ssti</category><category>template-injection</category><category>theme-editor</category><category>unauthenticated-rce</category><category>php</category><category>cwe-94</category><category>python</category></item><item><title>IngressNightmare: Kubernetes ingress-nginx Admission Controller Shared-Library Injection RCE (CVE-2025-1974)</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-06_cve-2025-1974-ingressnightmare-nginx-admission-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-06_cve-2025-1974-ingressnightmare-nginx-admission-rce/</guid><description>Critical severity (CVSS 9.8) — cloud · CVE-2025-1974. Status: Weaponized. Affects: Kubernetes ingress-nginx admission controller. Tags: kubernetes, ingress-nginx, ingressnightmare, admission-controller, nginx, ssl-engine, shared-library-injection, cluster-secrets, docker, python, c, cwe-94.</description><category>cloud</category><category>Critical</category><category>kubernetes</category><category>ingress-nginx</category><category>ingressnightmare</category><category>admission-controller</category><category>nginx</category><category>ssl-engine</category><category>shared-library-injection</category><category>cluster-secrets</category><category>docker</category><category>python</category><category>c</category><category>cwe-94</category></item><item><title>Flowise CustomMCP Unauthenticated Remote Code Execution via Function() Constructor (CVE-2025-59528)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-59528-flowise-custommcp-function-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-59528-flowise-custommcp-function-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-59528. Status: Weaponized. Affects: Flowise (FlowiseAI/Flowise). Tags: flowise, rce, custommcp, function-constructor, javascript-injection, unauthenticated, llm, node-load-method, cwe-94.</description><category>web</category><category>Critical</category><category>flowise</category><category>rce</category><category>custommcp</category><category>function-constructor</category><category>javascript-injection</category><category>unauthenticated</category><category>llm</category><category>node-load-method</category><category>cwe-94</category></item><item><title>DataEase PostgreSQL JDBC Datasource-Validation Bypass to Remote Code Execution (CVE-2025-49002)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-49002-dataease-postgresql-jdbc-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-49002-dataease-postgresql-jdbc-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-49002. Status: PoC. Affects: DataEase (开源数据可视化分析工具 / open-source BI/data-visualization platform by 飞致云/FIT2CLOUD). Tags: dataease, jdbc, h2-database, runscript, rce, datasource-validate, ssrf-adjacent, cwe-94, python.</description><category>web</category><category>Critical</category><category>dataease</category><category>jdbc</category><category>h2-database</category><category>runscript</category><category>rce</category><category>datasource-validate</category><category>ssrf-adjacent</category><category>cwe-94</category><category>python</category></item><item><title>ACF Extended (ACFE) `prepare_form()` Unauthenticated RCE via Privilege Escalation (CVE-2025-13486)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13486-acf-extended-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13486-acf-extended-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-13486. Status: Weaponized. Affects: Advanced Custom Fields: Extended (ACFE) — WordPress plugin. Tags: wordpress, acf-extended, acfe, call_user_func_array, unauthenticated-rce, privilege-escalation, admin-account-creation, python, cwe-94.</description><category>web</category><category>Critical</category><category>wordpress</category><category>acf-extended</category><category>acfe</category><category>call_user_func_array</category><category>unauthenticated-rce</category><category>privilege-escalation</category><category>admin-account-creation</category><category>python</category><category>cwe-94</category></item><item><title>Spring AI SimpleVectorStore SpEL Injection RCE (CVE-2026-22738)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-22738-spring-ai-spel-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-22738-spring-ai-spel-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-22738. Status: Weaponized. Affects: Spring AI spring-ai-core (SimpleVectorStore). Tags: spring-ai, spel-injection, java, rce, vector-store, unauthenticated, cwe-94, docker-lab.</description><category>web</category><category>Critical</category><category>spring-ai</category><category>spel-injection</category><category>java</category><category>rce</category><category>vector-store</category><category>unauthenticated</category><category>cwe-94</category><category>docker-lab</category></item><item><title>Shopware Twig Rendered-View Code Injection Regression (CVE-2026-23498)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23498-shopware-twig-code-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23498-shopware-twig-code-injection/</guid><description>High severity — web · CVE-2026-23498. Status: PoC. Affects: Shopware (shopware/shopware, shopware/core). Tags: shopware, twig, code-injection, ssti, php, cwe-94, regression, template-sandbox-bypass.</description><category>web</category><category>High</category><category>shopware</category><category>twig</category><category>code-injection</category><category>ssti</category><category>php</category><category>cwe-94</category><category>regression</category><category>template-sandbox-bypass</category></item><item><title>PbootCMS Authenticated RCE via sitecopyright Field (CVE-2026-36239)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-36239-pbootcms-authenticated-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-36239-pbootcms-authenticated-rce/</guid><description>Critical severity — web · CVE-2026-36239. Status: Weaponized. Affects: PbootCMS. Tags: pbootcms, rce, authenticated, code-injection, template-injection, cwe-94.</description><category>web</category><category>Critical</category><category>pbootcms</category><category>rce</category><category>authenticated</category><category>code-injection</category><category>template-injection</category><category>cwe-94</category></item><item><title>OpenWebUI "Tools" Unsandboxed exec() Remote Code Execution — CVE-2026-0766</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0766-openwebui-tool-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0766-openwebui-tool-rce/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-0766 (ZDI-26-032, GHSA-cggw-334c-f4mj). Status: Weaponized. Affects: OpenWebUI (self-hosted LLM web interface). Tags: openwebui, llm, code-injection, exec, tool-creation, cwe-94, rce, authenticated.</description><category>web</category><category>High</category><category>openwebui</category><category>llm</category><category>code-injection</category><category>exec</category><category>tool-creation</category><category>cwe-94</category><category>rce</category><category>authenticated</category></item><item><title>Kanboard — Missing Access Control on Plugin Installation Leads to Administrative RCE via Webshell Plugin (CVE-2026-25924)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25924-kanboard-plugin-webshell/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25924-kanboard-plugin-webshell/</guid><description>High severity (CVSS 8.4) — web · CVE-2026-25924 / GHSA-grch-p7vf-vc4f. Status: Weaponized. Affects: Kanboard (project management application). Tags: kanboard, rce, webshell, plugin-installation, incorrect-authorization, cwe-863, cwe-94, admin-bypass, backdoor.</description><category>web</category><category>High</category><category>kanboard</category><category>rce</category><category>webshell</category><category>plugin-installation</category><category>incorrect-authorization</category><category>cwe-863</category><category>cwe-94</category><category>admin-bypass</category><category>backdoor</category></item><item><title>DbGate Unauthenticated RCE via JSON Script Runner (CVE-2026-47668)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-47668-dbgate-json-script-runner-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-47668-dbgate-json-script-runner-rce/</guid><description>Critical severity (CVSS 3.1) — web · CVE-2026-47668. Status: PoC. Affects: DbGate (dbgate-serve — web-based database management tool). Tags: dbgate, rce, code-injection, javascript-injection, cwe-94, cwe-20, cwe-1188, database-management.</description><category>web</category><category>Critical</category><category>dbgate</category><category>rce</category><category>code-injection</category><category>javascript-injection</category><category>cwe-94</category><category>cwe-20</category><category>cwe-1188</category><category>database-management</category></item><item><title>DbGate `loadReader` `functionName` Injection RCE (CVE-2026-48017)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-48017-dbgate-loadreader-functionname-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-48017-dbgate-loadreader-functionname-rce/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-48017 / GHSA-hv83-ggc4-v385. Status: PoC. Affects: DbGate (dbgate-api), a web-based database management GUI. Tags: dbgate, nodejs, code-injection, rce, cwe-94, authenticated, database-gui.</description><category>web</category><category>High</category><category>dbgate</category><category>nodejs</category><category>code-injection</category><category>rce</category><category>cwe-94</category><category>authenticated</category><category>database-gui</category></item><item><title>Avada Builder Unauthenticated RCE via call_user_func() Allowlist Bypass (CVE-2026-6279)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-6279-avada-builder-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-6279-avada-builder-rce/</guid><description>Critical severity — web · CVE-2026-6279. Status: Weaponized. Affects: Avada Builder (Fusion Builder) WordPress theme/plugin. Tags: wordpress, avada, fusion-builder, rce, call_user_func, unauthenticated, cwe-94.</description><category>web</category><category>Critical</category><category>wordpress</category><category>avada</category><category>fusion-builder</category><category>rce</category><category>call_user_func</category><category>unauthenticated</category><category>cwe-94</category></item></channel></rss>