PoC Archive PoC Archive

tag

Hardcoded-Secret

Critical
Flowise Enterprise Authentication Bypass via Hardcoded Default JWT Secrets (CVE-2026-56271)
CVE-2026-56271 (GHSA-cc4f-hjpj-g9p8)· Flowise — open-source low-code LLM/agent orchestration platform (enterprise edition, passport authentication middleware) patched
Critical
WordPress Mobile Builder Plugin JWT Authentication Bypass to Admin Account Creation (CVE-2025-68860)
CVE-2025-68860· WordPress "Mobile Builder" plugin unpatched