PoC Archive PoC Archive

tag

Incorrect-Authorization

Kanboard — Missing Access Control on Plugin Installation Leads to Administrative RCE via Webshell Plugin (CVE-2026-25924)
CVE-2026-25924 / GHSA-grch-p7vf-vc4f web Patched
CVE-2026-25924 / GHSA-grch-p7vf-vc4fwebHIGH 8.4Patched2026-07-05Gitea OAuth2 Scope Enforcement Bypass via HTTP Basic Auth — CVE-2026-28699
CVE-2026-28699 web Patched
CVE-2026-28699webHIGHPatched2026-07-05