PoC Archive PoC Archive

tag

PHP

WP Cookie Notice Unauthenticated File Upload RCE (CVE-2026-82970)
CVE-2026-82970 web Unverified
CVE-2026-82970webCRITICAL 10Unverified2026-09-03PHP bcmath bccomp() Out-of-Bounds Write (CVE-2026-17544)
CVE-2026-17544 / GHSA-x692-q9x7-8c3f web Unverified
CVE-2026-17544 / GHSA-x692-q9x7-8c3fwebCRITICAL 9.8Unverified2026-08-16Unauthenticated Arbitrary File Upload RCE in iCagenda for Joomla (CVE-2026-48939) KEV EPSS 20%
CVE-2026-48939 web Patched
CVE-2026-48939webCRITICAL 9.8Patched2026-07-11WavePlayer Unauthenticated Arbitrary File Upload to RCE (CVE-2025-12057)
CVE-2025-12057 web Unverified
CVE-2025-12057webCRITICAL 9.8Unverified2026-07-06ThinkPHP 5.0.24 File Inclusion Leading to Remote Code Execution (CVE-2025-63888)
CVE-2025-63888 web Unverified
CVE-2025-63888webCRITICAL 9.8Unverified2026-07-06Roundcube Webmail Post-Auth RCE via PHP Object Deserialization (CVE-2025-49113) KEV EPSS 99%
CVE-2025-49113 web Patched
CVE-2025-49113webCRITICAL 9.9Patched2026-07-06Pterodactyl Panel Unauthenticated Path Traversal via locale.json Leaking Database Credentials (CVE-2025-49132) EPSS 53%
CVE-2025-49132 web Patched
CVE-2025-49132webCRITICAL 10Patched2026-07-06PPOM for WooCommerce <= 33.0.15 - Unauthenticated Time-Based Blind SQL Injection (CVE-2025-11391)
CVE-2025-11391 web Patched
CVE-2025-11391webCRITICAL 9.8Patched2026-07-06Monsta FTP Pre-Authentication Remote Code Execution via Arbitrary File Upload (CVE-2025-34299) EPSS 73%
CVE-2025-34299 network Patched
CVE-2025-34299networkCRITICAL 9.8Patched2026-07-06Laravel Livewire Remote Code Execution via Known APP_KEY (CVE-2025-54068) KEV EPSS 96%
CVE-2025-54068 web Patched
CVE-2025-54068webCRITICAL 9.8Patched2026-07-06Laravel `files.*` Wildcard Validation Bypass via Polyglot JPEG+PHP Upload (CVE-2025-27515)
CVE-2025-27515 web Patched
CVE-2025-27515webCRITICAL 9.8Patched2026-07-06Kubio AI Page Builder <= 2.5.1 Unauthenticated Local File Inclusion (CVE-2025-2294) EPSS 78%
CVE-2025-2294 web Unverified
CVE-2025-2294webCRITICAL 9.8Unverified2026-07-06Invision Community Theme Editor Template Injection Unauthenticated RCE (CVE-2025-47916) EPSS 84%
CVE-2025-47916 web Patched
CVE-2025-47916webCRITICAL 10Patched2026-07-06GiveWP Unauthenticated PHP Object Injection via Weak Serialized-Data Regex Check (CVE-2025-22777)
CVE-2025-22777 web Patched
CVE-2025-22777webCRITICAL 9.8Patched2026-07-06"Grocery" PHP Application `search_products_itname.php` `sitem_name` Boolean-Based SQL Injection (CVE-2025-65354)
CVE-2025-65354 web Unpatched
CVE-2025-65354webCRITICAL 9.8Unpatched2026-07-06ZoneMinder — Second-Order SQL Injection via Event Rename (CVE-2026-27470)
CVE-2026-27470 web Patched
CVE-2026-27470webHIGH 8.8Patched2026-07-05Xboard / V2Board — Magic Link Token Leak Unauth Account Takeover (CVE-2026-39912)
CVE-2026-39912 web Patched
CVE-2026-39912webCRITICAL 9.1Patched2026-07-05WordPress Contest Gallery Plugin Unauthenticated Blind SQL Injection — CVE-2026-3180
CVE-2026-3180 web Unverified
CVE-2026-3180webHIGHUnverified2026-07-05WeGIA Authenticated Error-Based SQL Injection Exploitation Helper (CVE-2026-23723)
CVE-2026-23723 / GHSA-xfmp-2hf9-gfjp web Patched
CVE-2026-23723 / GHSA-xfmp-2hf9-gfjpwebHIGHPatched2026-07-05Visitor Management System 1.0 — Unrestricted File Upload to RCE (CVE-2026-37748)
CVE-2026-37748 web Unverified
CVE-2026-37748webHIGH 7.2Unverified2026-07-05Veno File Manager 4.4.9 — Unauthenticated LFI to Superadmin Takeover (CVE-2026-37072)
CVE-2026-37072 web Unverified
CVE-2026-37072webCRITICALUnverified2026-07-05Veno File Manager 4.4.9 — Authenticated Arbitrary File Read (CVE-2026-37070)
CVE-2026-37070 web Unverified
CVE-2026-37070webMEDIUMUnverified2026-07-05Veno File Manager 4.4.9 — Arbitrary File Rename to Privilege Escalation (CVE-2026-37071)
CVE-2026-37071 web Unverified
CVE-2026-37071webHIGHUnverified2026-07-05Shopware Twig Rendered-View Code Injection Regression (CVE-2026-23498)
CVE-2026-23498 web Patched
CVE-2026-23498webHIGHPatched2026-07-05School Management System 1.0 — Reflected XSS in register.php (CVE-2026-37750)
CVE-2026-37750 web Unverified
CVE-2026-37750webMEDIUM 6.1Unverified2026-07-05Responsive Filemanager 9.14.0 — Unauthenticated RCE via Duplicate File (CVE-2026-39023)
CVE-2026-39023 web Unpatched
CVE-2026-39023webCRITICALUnpatched2026-07-05OpenXDMoD `user_interface.php` Report Title Command Injection (CVE-2026-45777)
CVE-2026-45777 web Patched
CVE-2026-45777webCRITICALPatched2026-07-05OpenSTAManager Scadenzario Bulk Operations Error-Based SQL Injection — CVE-2026-24418
CVE-2026-24418 web Patched
CVE-2026-24418webHIGH 8.8Patched2026-07-05OpenSTAManager Reflected XSS via `righe` Parameter (CVE-2026-24415)
CVE-2026-24415 (GHSA-jfgp-g7x7-j25j) web Patched
CVE-2026-24415webMEDIUMPatched2026-07-05OpenSTAManager Prima Nota Error-Based SQL Injection — CVE-2026-24419
CVE-2026-24419 web Patched
CVE-2026-24419webHIGHPatched2026-07-05OpenSTAManager Global Search Amplified Time-Based Blind SQL Injection — CVE-2026-24417
CVE-2026-24417 web Patched
CVE-2026-24417webHIGHPatched2026-07-05OpenSTAManager Article Pricing Time-Based Blind SQL Injection — CVE-2026-24416
CVE-2026-24416 web Patched
CVE-2026-24416webHIGHPatched2026-07-05OpenEMR EtherFax Module Authenticated Arbitrary File Read (CVE-2026-24849)
CVE-2026-24849 web Patched
CVE-2026-24849webCRITICAL 6.5Patched2026-07-05Mercator Configuration SSRF Chained to Internal Redis RCE (CVE-2026-49345)
CVE-2026-49345 web Unverified
CVE-2026-49345webCRITICALUnverified2026-07-05MantisBT SOAP `mc_issue_add` Authentication Bypass (Type Juggling) — CVE-2026-30849
CVE-2026-30849 web Patched
CVE-2026-30849webHIGHPatched2026-07-05Joomla Novarain Framework (nrframework) Unauthenticated Arbitrary File Inclusion — CVE-2026-21627
CVE-2026-21627 web Patched
CVE-2026-21627webCRITICAL 9.5Patched2026-07-05InvoicePlane Unauthenticated Path Traversal in Guest Controller (CVE-2026-23491)
CVE-2026-23491 web Patched
CVE-2026-23491webCRITICALPatched2026-07-05HAXcms Git.php OS Command Injection (CVE-2026-46394)
CVE-2026-46394 web Patched
CVE-2026-46394webHIGH 7.2Patched2026-07-05Group-Office PHP Deserialization Remote Code Execution (CVE-2026-34838)
CVE-2026-34838 (GHSA-h22j-frrf-5vxq) web Patched
CVE-2026-34838webCRITICALPatched2026-07-05Gravity Forms Path Traversal → Arbitrary File Deletion (CVE-2026-48866)
CVE-2026-48866 web Patched
CVE-2026-48866webCRITICAL 9.6Patched2026-07-05FOSSBilling Unauthenticated API Key Config Disclosure & Password Reset Token Reuse — CVE-2026-53647
CVE-2026-53647 (also documents chained CVE-2026-53646) web Patched
CVE-2026-53647webMEDIUM 6.9Patched2026-07-05Dolibarr selectobject.php Authenticated Local File Inclusion (CVE-2026-34036)
CVE-2026-34036 web Patched
CVE-2026-34036webMEDIUMPatched2026-07-05Dolibarr ERP/CRM OS Command Injection via MAIN_ODT_AS_PDF (CVE-2026-23500)
CVE-2026-23500 / GHSA-w5j3-8fcr-h87w web Patched
CVE-2026-23500 / GHSA-w5j3-8fcr-h87wwebCRITICALPatched2026-07-05diskover-community — CSRF Leading to Authentication Bypass (CVE-2026-38934)
CVE-2026-38934 web Unverified
CVE-2026-38934webHIGH 8.8Unverified2026-07-05Discuz! X5.0 Race Condition + CAPTCHA-Solving Pre-Auth to RCE Chain (CVE-2026-49952)
CVE-2026-49952 (chain also referenced as KIS-2026-09, KIS-2026-10, KIS-2026-11) web Unverified
CVE-2026-49952webCRITICALUnverified2026-07-05dedoc/scramble Laravel API-Doc Generator Unauthenticated eval() RCE (CVE-2026-44262)
CVE-2026-44262 / [GHSA-4rm2-28vj-fj39](https://github.com/advisories/GHSA-4rm2-28vj-fj39) web Patched
CVE-2026-44262 / [GHSA-4rm2-28vj-fj39]webCRITICALPatched2026-07-05CodeAstro Simple Attendance Management System 1.0 — SQL Injection Auth Bypass (CVE-2026-37749)
CVE-2026-37749 web Unverified
CVE-2026-37749webCRITICAL 9.8Unverified2026-07-05Chamilo LMS Unauthenticated install.ajax.php SSRF + Open Mail Relay — CVE-2026-33715
CVE-2026-33715 / GHSA-mxc9-9335-45mc web Unverified
CVE-2026-33715 / GHSA-mxc9-9335-45mcwebHIGH 7.5Unverified2026-07-05Centreon Multi-Vector RCE — Path Traversal, Command Injection & Blind SQLi (CVE-2026-2749)
CVE-2026-2749 (bundled with related CVE-2026-2750, CVE-2026-2751) web Patched
CVE-2026-2749webCRITICALPatched2026-07-05BoidCMS — Authenticated File Upload to RCE via Template Injection (CVE-2026-39387)
CVE-2026-39387 web Patched
CVE-2026-39387webHIGHPatched2026-07-05Bludit CMS API Unrestricted File Upload to RCE (CVE-2026-25099)
CVE-2026-25099 web Patched
CVE-2026-25099webHIGHPatched2026-07-05Azuriom CMS Broken Access Control — Account Takeover via AzLink Server Token — CVE-2026-54415
CVE-2026-54415 web Patched
CVE-2026-54415webHIGH 3.1Patched2026-07-05AdminPanel 4.0 CSRF File Deletion / Setup-Mode Reset — CVE-2026-30498
CVE-2026-30498 (reserved by MITRE) web Unverified
CVE-2026-30498webHIGHUnverified2026-07-05PHP 8.5.7 StreamBucket-to-SOAP Numeric Cookie Remote Code Execution
None assigned as of 2026-07-03 web Unverified
None assigned as of 2026-07-03webCRITICALUnverified2026-07-03MyBB 1.8.40 Limited Admin CP User-Manager to Full Administrator Privilege Escalation
None assigned as of 2026-07-03 (see Notes — CVE-2026-45115 identifies a separate, already-patched MyBB issue) web Unpatched
None assigned as of 2026-07-03webHIGHUnpatched2026-07-03