<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>LFI — PoC Archive</title><link>https://poc.intelseclab.com/tags/lfi/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 05 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/lfi/index.xml" rel="self" type="application/rss+xml"/><item><title>WordPress Divi Ajax Filter LFI (CVE-2026-11613)</title><link>https://poc.intelseclab.com/pocs/web/2026-09-05_cve-2026-11613-divi-ajax-filter-lfi/</link><pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-09-05_cve-2026-11613-divi-ajax-filter-lfi/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-11613. Status: PoC. Affects: Divi Ajax Filter plugin for WordPress. Tags: LFI, WordPress, Divi, unauthenticated, Python.</description><category>web</category><category>Critical</category><category>LFI</category><category>WordPress</category><category>Divi</category><category>unauthenticated</category><category>Python</category></item><item><title>ThinkPHP 5.0.24 File Inclusion Leading to Remote Code Execution (CVE-2025-63888)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-63888-thinkphp-file-inclusion-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-63888-thinkphp-file-inclusion-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-63888. Status: Weaponized. Affects: ThinkPHP (top10.org / TopThink PHP framework). Tags: thinkphp, php, file-inclusion, lfi, rce, log-poisoning, webshell, cwe-98, cwe-22.</description><category>web</category><category>Critical</category><category>thinkphp</category><category>php</category><category>file-inclusion</category><category>lfi</category><category>rce</category><category>log-poisoning</category><category>webshell</category><category>cwe-98</category><category>cwe-22</category></item><item><title>Kubio AI Page Builder &lt;= 2.5.1 Unauthenticated Local File Inclusion (CVE-2025-2294)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-2294-kubio-lfi/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-2294-kubio-lfi/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-2294. Status: PoC. Affects: Kubio AI Page Builder (WordPress plugin). Tags: wordpress, kubio, page-builder, lfi, local-file-inclusion, unauthenticated, php, python, cwe-98.</description><category>web</category><category>Critical</category><category>wordpress</category><category>kubio</category><category>page-builder</category><category>lfi</category><category>local-file-inclusion</category><category>unauthenticated</category><category>php</category><category>python</category><category>cwe-98</category></item><item><title>Adobe Magento "SessionReaper" Unauthenticated File Upload / LFI (CVE-2025-54236)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-54236-magento-sessionreaper-lfi/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-54236-magento-sessionreaper-lfi/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2025-54236. Status: PoC. Affects: Adobe Commerce / Magento Open Source — customer/address_file/upload endpoint (dubbed "SessionReaper"). Tags: magento, adobe-commerce, sessionreaper, file-upload, lfi, customer-address, form-key, cwe-434, python.</description><category>web</category><category>Critical</category><category>magento</category><category>adobe-commerce</category><category>sessionreaper</category><category>file-upload</category><category>lfi</category><category>customer-address</category><category>form-key</category><category>cwe-434</category><category>python</category></item><item><title>Termix Stored XSS via Malicious SVG Upload -> LFI / Session Hijack (CVE-2026-22804 / GHSA-m3cv-5hgp-hv35)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-22804-termix-stored-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-22804-termix-stored-xss/</guid><description>High severity — web · CVE-2026-22804 (GHSA-m3cv-5hgp-hv35). Status: Weaponized. Affects: Termix (Electron-based SSH/terminal manager), File Manager component (FileViewer.tsx). Tags: termix, electron, stored-xss, svg-injection, session-hijacking, lfi, file-manager, ssh.</description><category>web</category><category>High</category><category>termix</category><category>electron</category><category>stored-xss</category><category>svg-injection</category><category>session-hijacking</category><category>lfi</category><category>file-manager</category><category>ssh</category></item><item><title>Prodigy Commerce WordPress Plugin — Unauthenticated Local File Inclusion (CVE-2026-0926)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0926-prodigy-commerce-lfi/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0926-prodigy-commerce-lfi/</guid><description>High severity — web · CVE-2026-0926. Status: PoC. Affects: Prodigy Commerce (WordPress plugin). Tags: wordpress, plugin, prodigy-commerce, lfi, local-file-inclusion, unauthenticated, ajax.</description><category>web</category><category>High</category><category>wordpress</category><category>plugin</category><category>prodigy-commerce</category><category>lfi</category><category>local-file-inclusion</category><category>unauthenticated</category><category>ajax</category></item><item><title>Microsoft Exchange Authenticated Arbitrary File Read via EWS Reference Attachment (CVE-2026-45504)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-45504-exchange-file-read/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-45504-exchange-file-read/</guid><description>High severity — web · CVE-2026-45504. Status: PoC. Affects: Microsoft Exchange Server (OWA / EWS). Tags: exchange, owa, ews, file-read, ssrf, ntlm, soap, lfi.</description><category>web</category><category>High</category><category>exchange</category><category>owa</category><category>ews</category><category>file-read</category><category>ssrf</category><category>ntlm</category><category>soap</category><category>lfi</category></item><item><title>Dolibarr selectobject.php Authenticated Local File Inclusion (CVE-2026-34036)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-34036-dolibarr-selectobject-lfi/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-34036-dolibarr-selectobject-lfi/</guid><description>Medium severity — web · CVE-2026-34036. Status: PoC. Affects: Dolibarr ERP/CRM. Tags: dolibarr, lfi, local-file-inclusion, authenticated, crm, ajax, php.</description><category>web</category><category>Medium</category><category>dolibarr</category><category>lfi</category><category>local-file-inclusion</category><category>authenticated</category><category>crm</category><category>ajax</category><category>php</category></item><item><title>Discuz! X5.0 Race Condition + CAPTCHA-Solving Pre-Auth to RCE Chain (CVE-2026-49952)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-49952-discuz-race-condition-captcha-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-49952-discuz-race-condition-captcha-rce/</guid><description>Critical severity — web · CVE-2026-49952 (chain also referenced as KIS-2026-09, KIS-2026-10, KIS-2026-11). Status: PoC. Affects: Discuz! X5.0 (PHP-based forum/CMS software). Tags: discuz, php, forum, race-condition, captcha-bypass, ocr, account-takeover, lfi, webshell, rce, pre-auth.</description><category>web</category><category>Critical</category><category>discuz</category><category>php</category><category>forum</category><category>race-condition</category><category>captcha-bypass</category><category>ocr</category><category>account-takeover</category><category>lfi</category><category>webshell</category><category>rce</category><category>pre-auth</category></item><item><title>BetterDocs Pro Unauthenticated Local File Inclusion to RCE — CVE-2026-7515</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-7515-poc/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-7515-poc/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-7515. Status: PoC. Affects: BetterDocs Pro (WordPress plugin). Tags: wordpress, betterdocs-pro, lfi, path-traversal, log-poisoning, rce, cwe-98, admin-ajax.</description><category>web</category><category>Critical</category><category>wordpress</category><category>betterdocs-pro</category><category>lfi</category><category>path-traversal</category><category>log-poisoning</category><category>rce</category><category>cwe-98</category><category>admin-ajax</category></item></channel></rss>