<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Python — PoC Archive</title><link>https://poc.intelseclab.com/tags/python/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 09 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/python/index.xml" rel="self" type="application/rss+xml"/><item><title>GitLab Unauthenticated RCE via Workhorse Pre-Auth Upload into ExifTool DjVu Injection (CVE-2021-22205)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2021-22205-gitlab-exiftool-preauth-rce/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2021-22205-gitlab-exiftool-preauth-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2021-22205 (chains CVE-2021-22204 in ExifTool). Status: Patched (GitLab 13.8.8, 13.9.6, 13.10.3). Affects: GitLab Community Edition and Enterprise Edition (via bundled ExifTool, invoked by GitLab Workhorse). Tags: gitlab, exiftool, djvu, rce, preauth, unauthenticated, workhorse, perl, qx, reverse-shell, metadata-injection, kev, ransomware, python, cve-2021-22205, cve-2021-22204.</description><category>web</category><category>Critical</category><category>gitlab</category><category>exiftool</category><category>djvu</category><category>rce</category><category>preauth</category><category>unauthenticated</category><category>workhorse</category><category>perl</category><category>qx</category><category>reverse-shell</category><category>metadata-injection</category><category>kev</category><category>ransomware</category><category>python</category><category>cve-2021-22205</category><category>cve-2021-22204</category></item><item><title>CyberPanel Pre-Auth Remote Code Execution via getresetstatus Command Injection (CVE-2024-51378)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2024-51378-cyberpanel-preauth-rce/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2024-51378-cyberpanel-preauth-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2024-51378. Status: Patched (commit 1c0c6cb; CyberPanel 2.3.8 and later). Affects: CyberPanel (aka Cyber Panel), by CyberPersons — Django-based hosting control panel. Tags: cyberpanel, rce, command-injection, preauth, unauthenticated, options-method, secmiddleware-bypass, statusfile, kev, ransomware, psaux, python, httpx, cve-2024-51378.</description><category>web</category><category>Critical</category><category>cyberpanel</category><category>rce</category><category>command-injection</category><category>preauth</category><category>unauthenticated</category><category>options-method</category><category>secmiddleware-bypass</category><category>statusfile</category><category>kev</category><category>ransomware</category><category>psaux</category><category>python</category><category>httpx</category><category>cve-2024-51378</category></item><item><title>Check Point Security Management / Multi-Domain Server SmartConsole Authentication Bypass via Forged Application Certificate Bind (CVE-2026-16232)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2026-16232-checkpoint-smartconsole-auth-bypass/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2026-16232-checkpoint-smartconsole-auth-bypass/</guid><description>Critical severity (CVSS 9.1) — network · CVE-2026-16232. Status: Patched. Affects: Check Point Security Management Server and Multi-Domain Security Management Server (MDS) — the legacy FWM/CPMI SIC service on TCP 18190 and the CPM SOAP web services on TCP 19009. Tags: check-point, smartconsole, security-management-server, multi-domain-server, cpmi, sic, fwm, authentication-bypass, CWE-287, improper-authentication, privilege-escalation, sso-token-forgery, soap, dle, cisa-kev, bod-26-04, python, firewall-management.</description><category>network</category><category>Critical</category><category>check-point</category><category>smartconsole</category><category>security-management-server</category><category>multi-domain-server</category><category>cpmi</category><category>sic</category><category>fwm</category><category>authentication-bypass</category><category>CWE-287</category><category>improper-authentication</category><category>privilege-escalation</category><category>sso-token-forgery</category><category>soap</category><category>dle</category><category>cisa-kev</category><category>bod-26-04</category><category>python</category><category>firewall-management</category></item><item><title>Crawl4AI JsonCssExtractionStrategy AST Sandbox Escape → Unauthenticated RCE (CVE-2026-53753)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-53753-crawl4ai-sandbox-escape-rce/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-53753-crawl4ai-sandbox-escape-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-53753 (GHSA-qxjp-w3pj-48m7). Status: Weaponized — full end-to-end command execution reproduced against the official unclecode/crawl4ai:0.8.6 image. Affects: Crawl4AI — open-source LLM-friendly web crawler/scraper, Docker API server. Tags: crawl4ai, sandbox-escape, rce, python, ast-bypass, unauthenticated, llm-tooling, ai-security.</description><category>web</category><category>Critical</category><category>crawl4ai</category><category>sandbox-escape</category><category>rce</category><category>python</category><category>ast-bypass</category><category>unauthenticated</category><category>llm-tooling</category><category>ai-security</category></item><item><title>XWiki SolrSearch Macro Unauthenticated Groovy RCE (CVE-2025-24893)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-24893-xwiki-solrsearch-groovy-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-24893-xwiki-solrsearch-groovy-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-24893. Status: Weaponized. Affects: XWiki (SolrSearch macro, Main.SolrSearch). Tags: xwiki, groovy, rce, unauthenticated, cwe-94, code-injection, reverse-shell, python, wiki.</description><category>web</category><category>Critical</category><category>xwiki</category><category>groovy</category><category>rce</category><category>unauthenticated</category><category>cwe-94</category><category>code-injection</category><category>reverse-shell</category><category>python</category><category>wiki</category></item><item><title>XSpeeder SXZOS Pre-Auth eval() Remote Code Execution (CVE-2025-54322)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-54322-xspeeder-sxzos-preauth-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-54322-xspeeder-sxzos-preauth-rce/</guid><description>Critical severity (CVSS 10) — network · CVE-2025-54322. Status: Weaponized. Affects: XSpeeder SXZOS firmware (SD-WAN devices, routers, edge networking equipment). Tags: xspeeder, sxzos, sd-wan, router, firmware, python, django, eval-injection, pre-auth, rce, cwe-95.</description><category>network</category><category>Critical</category><category>xspeeder</category><category>sxzos</category><category>sd-wan</category><category>router</category><category>firmware</category><category>python</category><category>django</category><category>eval-injection</category><category>pre-auth</category><category>rce</category><category>cwe-95</category></item><item><title>Xiongmai XM530 IP Camera ONVIF Authentication Bypass (CVE-2025-65856)</title><link>https://poc.intelseclab.com/pocs/hardware/2026-07-06_cve-2025-65856-onvif-camera-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/hardware/2026-07-06_cve-2025-65856-onvif-camera-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — hardware · CVE-2025-65856. Status: Weaponized. Affects: Xiongmai XM530-based IP camera ONVIF service (tested on model XM530_50X50-WG_8M). Tags: xiongmai, xm530, onvif, ip-camera, iot, auth-bypass, access-control, information-disclosure, rtsp, cwe-306, cwe-287, python, bash, curl.</description><category>hardware</category><category>Critical</category><category>xiongmai</category><category>xm530</category><category>onvif</category><category>ip-camera</category><category>iot</category><category>auth-bypass</category><category>access-control</category><category>information-disclosure</category><category>rtsp</category><category>cwe-306</category><category>cwe-287</category><category>python</category><category>bash</category><category>curl</category></item><item><title>WP移行専用プラグイン for CPI &lt;= 1.0.2 - Unauthenticated Arbitrary File Upload RCE (CVE-2025-11170)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-11170-cpi-plugin-file-upload-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-11170-cpi-plugin-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-11170. Status: Weaponized. Affects: WP移行専用プラグイン for CPI (cpi-wp-migration, a CPI/site-migration import plugin for WordPress). Tags: wordpress, cpi-wp-migration, unauthenticated-file-upload, rce, admin-ajax, cwe-434, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>cpi-wp-migration</category><category>unauthenticated-file-upload</category><category>rce</category><category>admin-ajax</category><category>cwe-434</category><category>python</category></item><item><title>WP Directory Kit Auto-Login Authentication Bypass to Full Site Takeover (CVE-2025-13390)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13390-wp-directory-kit-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13390-wp-directory-kit-auth-bypass/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-13390. Status: Weaponized. Affects: WP Directory Kit (WordPress plugin). Tags: wordpress, wp-directory-kit, authentication-bypass, predictable-token, account-takeover, webshell-upload, python, cwe-287.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wp-directory-kit</category><category>authentication-bypass</category><category>predictable-token</category><category>account-takeover</category><category>webshell-upload</category><category>python</category><category>cwe-287</category></item><item><title>WordPress WPAMS Plugin Arbitrary File Upload to RCE (CVE-2025-39401)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-39401-wpams-arbitrary-file-upload-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-39401-wpams-arbitrary-file-upload-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-39401. Status: Weaponized. Affects: WPAMS (WordPress Apartment/Property Management System) plugin by mojoomla. Tags: wordpress, wpams, mojoomla, arbitrary-file-upload, webshell, rce, unauthenticated, python, multithreaded, cwe-434.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wpams</category><category>mojoomla</category><category>arbitrary-file-upload</category><category>webshell</category><category>rce</category><category>unauthenticated</category><category>python</category><category>multithreaded</category><category>cwe-434</category></item><item><title>WordPress Simple Link Directory Unauthenticated Password Reset to Admin Takeover (CVE-2025-49901)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-49901-simple-link-directory-password-reset-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-49901-simple-link-directory-password-reset-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-49901. Status: Weaponized. Affects: WordPress "Simple Link Directory" plugin (qc-simple-link-directory by quantumcloud). Tags: wordpress, wordpress-plugin, simple-link-directory, qc-opd, authentication-bypass, password-reset, broken-authentication, cwe-288, username-enumeration, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wordpress-plugin</category><category>simple-link-directory</category><category>qc-opd</category><category>authentication-bypass</category><category>password-reset</category><category>broken-authentication</category><category>cwe-288</category><category>username-enumeration</category><category>python</category></item><item><title>WordPress Mobile Builder Plugin JWT Authentication Bypass to Admin Account Creation (CVE-2025-68860)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-68860-wp-jwt-admin-forge/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-68860-wp-jwt-admin-forge/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-68860. Status: Weaponized. Affects: WordPress "Mobile Builder" plugin. Tags: wordpress, mobile-builder, jwt, authentication-bypass, hardcoded-secret, privilege-escalation, rest-api, python, cwe-288.</description><category>web</category><category>Critical</category><category>wordpress</category><category>mobile-builder</category><category>jwt</category><category>authentication-bypass</category><category>hardcoded-secret</category><category>privilege-escalation</category><category>rest-api</category><category>python</category><category>cwe-288</category></item><item><title>Wing FTP Server NULL-Byte Lua Injection Unauthenticated RCE (CVE-2025-47812)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-47812-wingftp-null-byte-lua-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-47812-wingftp-null-byte-lua-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-47812. Status: Weaponized. Affects: Wing FTP Server, web administration/login interface (loginok.html, session mechanism). Tags: wingftp, ftp-server, null-byte-injection, lua-injection, unauthenticated-rce, session-file, cwe-94, cwe-158, python.</description><category>web</category><category>Critical</category><category>wingftp</category><category>ftp-server</category><category>null-byte-injection</category><category>lua-injection</category><category>unauthenticated-rce</category><category>session-file</category><category>cwe-94</category><category>cwe-158</category><category>python</category></item><item><title>Webkul Medical Prescription Attachment for WooCommerce — Unrestricted File Upload to Web Shell (CVE-2025-29009)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-29009-woocommerce-medical-prescription-file-upload/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-29009-woocommerce-medical-prescription-file-upload/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-29009. Status: Weaponized. Affects: Webkul "Medical Prescription Attachment Plugin for WooCommerce" (WordPress plugin). Tags: wordpress, woocommerce, medical-prescription-attachment, unrestricted-file-upload, webshell, cwe-434, unauthenticated, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>woocommerce</category><category>medical-prescription-attachment</category><category>unrestricted-file-upload</category><category>webshell</category><category>cwe-434</category><category>unauthenticated</category><category>python</category></item><item><title>WavePlayer Unauthenticated Arbitrary File Upload to RCE (CVE-2025-12057)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-12057-waveplayer-webshell-upload/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-12057-waveplayer-webshell-upload/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-12057. Status: Weaponized. Affects: WavePlayer (WordPress plugin). Tags: wordpress, waveplayer, arbitrary-file-upload, unauthenticated, rce, webshell, ajax, nonce, php, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>waveplayer</category><category>arbitrary-file-upload</category><category>unauthenticated</category><category>rce</category><category>webshell</category><category>ajax</category><category>nonce</category><category>php</category><category>python</category></item><item><title>TNC Toolbox: Web Performance Unauthenticated cPanel Credential Exposure (CVE-2025-12539)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-12539-tnc-toolbox-cpanel-creds-exposure/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-12539-tnc-toolbox-cpanel-creds-exposure/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-12539. Status: Weaponized. Affects: TNC Toolbox: Web Performance (WordPress plugin). Tags: wordpress, tnc-toolbox, sensitive-information-exposure, unauthenticated, cpanel, credential-theft, privilege-escalation, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>tnc-toolbox</category><category>sensitive-information-exposure</category><category>unauthenticated</category><category>cpanel</category><category>credential-theft</category><category>privilege-escalation</category><category>python</category></item><item><title>ThingsBoard IoT Platform SSRF via SVG Image Upload (CVE-2025-34282)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-34282-thingsboard-ssrf-svg-upload/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-34282-thingsboard-ssrf-svg-upload/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2025-34282. Status: Weaponized. Affects: ThingsBoard IoT Platform (Image Upload Gallery / Widget Library). Tags: thingsboard, ssrf, cwe-918, svg, image-upload, iot, python, widget-library, tenant-admin.</description><category>web</category><category>Critical</category><category>thingsboard</category><category>ssrf</category><category>cwe-918</category><category>svg</category><category>image-upload</category><category>iot</category><category>python</category><category>widget-library</category><category>tenant-admin</category></item><item><title>Tenda AC9 `AdvSetMacMtuWan` Stack-Based Buffer Overflow (CVE-2025-29384)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-29384-tenda-ac9-stack-overflow/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-29384-tenda-ac9-stack-overflow/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-29384. Status: PoC. Affects: Tenda AC9 dual-band wireless router, web management interface (/goform/AdvSetMacMtuWan endpoint). Tags: tenda, ac9, router, stack-buffer-overflow, cwe-121, dos, rce, mips, embedded, iot, python, ruby, metasploit.</description><category>network</category><category>Critical</category><category>tenda</category><category>ac9</category><category>router</category><category>stack-buffer-overflow</category><category>cwe-121</category><category>dos</category><category>rce</category><category>mips</category><category>embedded</category><category>iot</category><category>python</category><category>ruby</category><category>metasploit</category></item><item><title>StoryChief WordPress Plugin Unauthenticated Arbitrary File Upload via Webhook (CVE-2025-7441)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-7441-storychief-webhook-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-7441-storychief-webhook-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-7441. Status: PoC. Affects: StoryChief WordPress plugin. Tags: storychief, wordpress, wordpress-plugin, arbitrary-file-upload, ssrf, remote-code-execution, unauthenticated, webhook, hmac, cwe-434, python.</description><category>web</category><category>Critical</category><category>storychief</category><category>wordpress</category><category>wordpress-plugin</category><category>arbitrary-file-upload</category><category>ssrf</category><category>remote-code-execution</category><category>unauthenticated</category><category>webhook</category><category>hmac</category><category>cwe-434</category><category>python</category></item><item><title>StoreKeeper for WooCommerce Unauthenticated Arbitrary File Upload (CVE-2025-48148)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-48148-storekeeper-woocommerce-webshell-upload/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-48148-storekeeper-woocommerce-webshell-upload/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-48148. Status: Weaponized. Affects: StoreKeeper for WooCommerce (WordPress plugin). Tags: wordpress, woocommerce, storekeeper, arbitrary-file-upload, unauthenticated, webshell, rce, cwe-434, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>woocommerce</category><category>storekeeper</category><category>arbitrary-file-upload</category><category>unauthenticated</category><category>webshell</category><category>rce</category><category>cwe-434</category><category>python</category></item><item><title>SmarterMail Auth Bypass via Password Reset to Pre-Auth RCE (CVE-2025-52691 / WT-2026-0001)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-52691-smartermail-auth-bypass-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-52691-smartermail-auth-bypass-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-52691. Status: Weaponized. Affects: SmarterMail (SmarterTools webmail/mail server). Tags: smartermail, smartertools, webmail, authentication-bypass, password-reset, rce, volume-mounts, pre-auth, watchtowr, python.</description><category>web</category><category>Critical</category><category>smartermail</category><category>smartertools</category><category>webmail</category><category>authentication-bypass</category><category>password-reset</category><category>rce</category><category>volume-mounts</category><category>pre-auth</category><category>watchtowr</category><category>python</category></item><item><title>Simple User Registration WordPress Plugin — Unauthenticated Privilege Escalation (CVE-2025-4334)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-4334-simple-user-registration-privesc/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-4334-simple-user-registration-privesc/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-4334. Status: PoC. Affects: "Simple User Registration" WordPress plugin (registration/form-builder plugin, wpr_submit_form AJAX action). Tags: wordpress, wp-plugin, simple-user-registration, privilege-escalation, unauthenticated, admin-ajax, cwe-269, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wp-plugin</category><category>simple-user-registration</category><category>privilege-escalation</category><category>unauthenticated</category><category>admin-ajax</category><category>cwe-269</category><category>python</category></item><item><title>Simple Business Directory Pro Unauthenticated Password Reset to Admin Takeover (CVE-2025-53580)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-53580-sbd-password-reset-privesc/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-53580-sbd-password-reset-privesc/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-53580. Status: Weaponized. Affects: quantumcloud "Simple Business Directory Pro" WordPress plugin (simple-business-directory-pro). Tags: wordpress, wordpress-plugin, simple-business-directory-pro, password-reset, privilege-escalation, incorrect-privilege-assignment, cwe-266, account-takeover, unauthenticated, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wordpress-plugin</category><category>simple-business-directory-pro</category><category>password-reset</category><category>privilege-escalation</category><category>incorrect-privilege-assignment</category><category>cwe-266</category><category>account-takeover</category><category>unauthenticated</category><category>python</category></item><item><title>SAP NetWeaver Visual Composer Unrestricted File Upload RCE (CVE-2025-31324)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-31324-sap-netweaver-visual-composer-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-31324-sap-netweaver-visual-composer-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-31324. Status: Weaponized. Affects: SAP NetWeaver Application Server (AS) Java — Visual Composer component (VCFRAMEWORK), specifically the Metadata Uploader servlet. Tags: sap-netweaver, visual-composer, metadatauploader, unrestricted-file-upload, java-deserialization, jsp-webshell, rce, cwe-434, cwe-502, python.</description><category>web</category><category>Critical</category><category>sap-netweaver</category><category>visual-composer</category><category>metadatauploader</category><category>unrestricted-file-upload</category><category>java-deserialization</category><category>jsp-webshell</category><category>rce</category><category>cwe-434</category><category>cwe-502</category><category>python</category></item><item><title>Samsung MagicINFO 9 Server Unauthenticated Path Traversal to RCE (CVE-2025-4632)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-4632-magicinfo-path-traversal-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-4632-magicinfo-path-traversal-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-4632. Status: Weaponized. Affects: Samsung MagicINFO 9 Server (digital signage content management server), SWUpdateFileUploader servlet. Tags: samsung, magicinfo, path-traversal, arbitrary-file-upload, unauthenticated-rce, jsp-webshell, cwe-22, cwe-434, python.</description><category>web</category><category>Critical</category><category>samsung</category><category>magicinfo</category><category>path-traversal</category><category>arbitrary-file-upload</category><category>unauthenticated-rce</category><category>jsp-webshell</category><category>cwe-22</category><category>cwe-434</category><category>python</category></item><item><title>RestroPress WordPress Plugin Unauthenticated Information Exposure Leading to JWT Forgery / Account Takeover (CVE-2025-9209)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-9209-restropress-jwt-forgery/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-9209-restropress-jwt-forgery/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-9209. Status: Weaponized. Affects: RestroPress – Online Food Ordering System (WordPress plugin). Tags: restropress, wordpress, wordpress-plugin, information-exposure, jwt, authentication-bypass, account-takeover, rest-api, mass-scanner, cwe-200, cwe-287, python.</description><category>web</category><category>Critical</category><category>restropress</category><category>wordpress</category><category>wordpress-plugin</category><category>information-exposure</category><category>jwt</category><category>authentication-bypass</category><category>account-takeover</category><category>rest-api</category><category>mass-scanner</category><category>cwe-200</category><category>cwe-287</category><category>python</category></item><item><title>Real Spaces WordPress Theme Unauthenticated Privilege Escalation via `imic_agent_register` (CVE-2025-6758)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-6758-realspaces-privesc/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-6758-realspaces-privesc/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-6758. Status: Weaponized. Affects: Real Spaces - Properties Directory Theme for WordPress (imic_agent_register AJAX handler). Tags: wordpress, real-spaces, imic, privilege-escalation, unauthenticated, admin-ajax, role-assignment, cwe-269, cwe-863, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>real-spaces</category><category>imic</category><category>privilege-escalation</category><category>unauthenticated</category><category>admin-ajax</category><category>role-assignment</category><category>cwe-269</category><category>cwe-863</category><category>python</category></item><item><title>React Server Components Flight-Protocol Prototype Pollution RCE — "React2Shell" (CVE-2025-55182)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-55182-react-server-components-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-55182-react-server-components-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-55182. Status: PoC. Affects: React Server Components (RSC) packages using the Flight protocol (commonly deployed via Next.js). Tags: react, react-server-components, rsc, flight-protocol, prototype-pollution, deserialization, unauthenticated-rce, nextjs, nodejs, python.</description><category>web</category><category>Critical</category><category>react</category><category>react-server-components</category><category>rsc</category><category>flight-protocol</category><category>prototype-pollution</category><category>deserialization</category><category>unauthenticated-rce</category><category>nextjs</category><category>nodejs</category><category>python</category></item><item><title>React Native Community CLI Metro Dev Server `/open-url` OS Command Injection (CVE-2025-11953)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-11953-react-native-metro-command-injection/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-11953-react-native-metro-command-injection/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-11953. Status: Weaponized. Affects: @react-native-community/cli / @react-native-community/cli-server-api (Metro Development Server, openURLMiddleware). Tags: react-native, metro, dev-server, cli-server-api, open-url, command-injection, cwe-78, unauthenticated, node.js, python, windows, cross-platform.</description><category>network</category><category>Critical</category><category>react-native</category><category>metro</category><category>dev-server</category><category>cli-server-api</category><category>open-url</category><category>command-injection</category><category>cwe-78</category><category>unauthenticated</category><category>node.js</category><category>python</category><category>windows</category><category>cross-platform</category></item><item><title>Python tarfile `filter="data"` Bypass via PATH_MAX/realpath Confusion (CVE-2025-4517)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-06_cve-2025-4517-tarfile-filter-data-path-max-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-06_cve-2025-4517-tarfile-filter-data-path-max-bypass/</guid><description>Critical severity (CVSS 9.4) — misc · CVE-2025-4517. Status: Weaponized. Affects: Python standard library tarfile module — filter="data" / filter="tar" extraction filters (PEP 706). Tags: python, tarfile, path-traversal, sandbox-bypass, path_max, realpath, symlink, cwe-22, stdlib.</description><category>misc</category><category>Critical</category><category>python</category><category>tarfile</category><category>path-traversal</category><category>sandbox-bypass</category><category>path_max</category><category>realpath</category><category>symlink</category><category>cwe-22</category><category>stdlib</category></item><item><title>PPOM for WooCommerce &lt;= 33.0.15 - Unauthenticated Time-Based Blind SQL Injection (CVE-2025-11391)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-11391-ppom-woocommerce-blind-sqli/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-11391-ppom-woocommerce-blind-sqli/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-11391. Status: Patched. Affects: PPOM for WooCommerce (woocommerce-product-addon plugin). Tags: wordpress, woocommerce, ppom, product-addon, sql-injection, blind-sqli, time-based, cwe-89, python, php.</description><category>web</category><category>Critical</category><category>wordpress</category><category>woocommerce</category><category>ppom</category><category>product-addon</category><category>sql-injection</category><category>blind-sqli</category><category>time-based</category><category>cwe-89</category><category>python</category><category>php</category></item><item><title>Podlove Podcast Publisher &lt;= 4.2.6 - Unauthenticated Arbitrary File Upload RCE (CVE-2025-10147)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-10147-podlove-podcast-publisher-file-upload-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-10147-podlove-podcast-publisher-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-10147. Status: Weaponized. Affects: Podlove Podcast Publisher (WordPress plugin). Tags: wordpress, podlove, podcast-publisher, unauthenticated-file-upload, rce, cwe-434, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>podlove</category><category>podcast-publisher</category><category>unauthenticated-file-upload</category><category>rce</category><category>cwe-434</category><category>python</category></item><item><title>pgAdmin 4 Restore Feature Regex-Bypass Command Injection RCE (CVE-2025-13780)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13780-pgadmin4-regex-bypass-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13780-pgadmin4-regex-bypass-rce/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2025-13780. Status: Weaponized. Affects: pgAdmin 4. Tags: pgadmin4, postgresql, regex-bypass, command-injection, psql-meta-command, utf8-bom, crlf-injection, rce, python, cwe-77, cwe-88.</description><category>web</category><category>Critical</category><category>pgadmin4</category><category>postgresql</category><category>regex-bypass</category><category>command-injection</category><category>psql-meta-command</category><category>utf8-bom</category><category>crlf-injection</category><category>rce</category><category>python</category><category>cwe-77</category><category>cwe-88</category></item><item><title>pgAdmin 4 Query Tool Authenticated eval() RCE (CVE-2025-2945)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-2945-pgadmin-eval-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-2945-pgadmin-eval-rce/</guid><description>Critical severity (CVSS 9.9) — web · CVE-2025-2945. Status: Weaponized. Affects: pgAdmin 4 (web-based PostgreSQL administration tool). Tags: pgadmin, postgresql, rce, eval-injection, code-injection, cwe-95, python, authenticated, sqleditor.</description><category>web</category><category>Critical</category><category>pgadmin</category><category>postgresql</category><category>rce</category><category>eval-injection</category><category>code-injection</category><category>cwe-95</category><category>python</category><category>authenticated</category><category>sqleditor</category></item><item><title>Opal Estate Pro WordPress Plugin Unauthenticated Administrator Registration (CVE-2025-6934)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-6934-opal-estate-admin-register/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-6934-opal-estate-admin-register/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-6934. Status: Weaponized. Affects: Opal Estate Pro (WordPress real-estate plugin). Tags: wordpress, opal-estate-pro, privilege-escalation, unauthenticated-registration, admin-ajax, nonce-abuse, cwe-269, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>opal-estate-pro</category><category>privilege-escalation</category><category>unauthenticated-registration</category><category>admin-ajax</category><category>nonce-abuse</category><category>cwe-269</category><category>python</category></item><item><title>Mitel MiCollab Path Normalization Bypass to Internal Endpoints (CVE-2025-52913)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-52913-mitel-micollab-path-traversal/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-52913-mitel-micollab-path-traversal/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-52913. Status: PoC. Affects: Mitel MiCollab (unified communications appliance). Tags: mitel, micollab, path-traversal, path-normalization, access-control-bypass, authentication-bypass, cwe-22, axis2, python, unified-communications.</description><category>network</category><category>Critical</category><category>mitel</category><category>micollab</category><category>path-traversal</category><category>path-normalization</category><category>access-control-bypass</category><category>authentication-bypass</category><category>cwe-22</category><category>axis2</category><category>python</category><category>unified-communications</category></item><item><title>Laravel Livewire Remote Code Execution via Known APP_KEY (CVE-2025-54068)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-54068-livewire-appkey-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-54068-livewire-appkey-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-54068. Status: Weaponized. Affects: Laravel Livewire (versions prior to v3.6.4). Tags: laravel, livewire, php, deserialization, app-key, hmac-forgery, gadget-chain, rce, cwe-502, python.</description><category>web</category><category>Critical</category><category>laravel</category><category>livewire</category><category>php</category><category>deserialization</category><category>app-key</category><category>hmac-forgery</category><category>gadget-chain</category><category>rce</category><category>cwe-502</category><category>python</category></item><item><title>Langflow Pre-Auth RCE Mass Scanner (CVE-2026-27966)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2026-27966-langflow-mass-scanner/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2026-27966-langflow-mass-scanner/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-27966 (GHSA-3645-fxcv-hqr4). Status: Patched. Affects: Langflow (langflow-ai). Tags: langflow, rce, pre-auth, route-injection, vertex-injection, csv-agent, prompt-injection, python, mass-scanner, ai-security.</description><category>web</category><category>Critical</category><category>langflow</category><category>rce</category><category>pre-auth</category><category>route-injection</category><category>vertex-injection</category><category>csv-agent</category><category>prompt-injection</category><category>python</category><category>mass-scanner</category><category>ai-security</category></item><item><title>Kubio AI Page Builder &lt;= 2.5.1 Unauthenticated Local File Inclusion (CVE-2025-2294)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-2294-kubio-lfi/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-2294-kubio-lfi/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-2294. Status: PoC. Affects: Kubio AI Page Builder (WordPress plugin). Tags: wordpress, kubio, page-builder, lfi, local-file-inclusion, unauthenticated, php, python, cwe-98.</description><category>web</category><category>Critical</category><category>wordpress</category><category>kubio</category><category>page-builder</category><category>lfi</category><category>local-file-inclusion</category><category>unauthenticated</category><category>php</category><category>python</category><category>cwe-98</category></item><item><title>KiotViet Sync Unauthenticated Arbitrary File Upload (CVE-2025-12674)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-12674-kiotviet-sync-file-upload/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-12674-kiotviet-sync-file-upload/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-12674. Status: Weaponized. Affects: KiotViet Sync (WordPress plugin). Tags: wordpress, kiotviet-sync, arbitrary-file-upload, unauthenticated, rce, rest-api, webshell, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>kiotviet-sync</category><category>arbitrary-file-upload</category><category>unauthenticated</category><category>rce</category><category>rest-api</category><category>webshell</category><category>python</category></item><item><title>JAY Login &amp; Register "Switch Back" Cookie Authentication Bypass (CVE-2025-14440)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-14440-jay-login-register-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-14440-jay-login-register-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-14440. Status: Weaponized. Affects: JAY Login &amp; Register (WordPress plugin). Tags: wordpress, jay-login-register, authentication-bypass, cookie-manipulation, unauthenticated, python, cwe-287, cwe-290.</description><category>web</category><category>Critical</category><category>wordpress</category><category>jay-login-register</category><category>authentication-bypass</category><category>cookie-manipulation</category><category>unauthenticated</category><category>python</category><category>cwe-287</category><category>cwe-290</category></item><item><title>Invision Community Theme Editor Template Injection Unauthenticated RCE (CVE-2025-47916)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-47916-invision-community-template-injection-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-47916-invision-community-template-injection-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-47916. Status: Weaponized. Affects: Invision Community, themeeditor front controller (IPS\core\modules\front\system\themeeditor::customCss()). Tags: invision-community, ssti, template-injection, theme-editor, unauthenticated-rce, php, cwe-94, python.</description><category>web</category><category>Critical</category><category>invision-community</category><category>ssti</category><category>template-injection</category><category>theme-editor</category><category>unauthenticated-rce</category><category>php</category><category>cwe-94</category><category>python</category></item><item><title>IngressNightmare: Kubernetes ingress-nginx Admission Controller Shared-Library Injection RCE (CVE-2025-1974)</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-06_cve-2025-1974-ingressnightmare-nginx-admission-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-06_cve-2025-1974-ingressnightmare-nginx-admission-rce/</guid><description>Critical severity (CVSS 9.8) — cloud · CVE-2025-1974. Status: Weaponized. Affects: Kubernetes ingress-nginx admission controller. Tags: kubernetes, ingress-nginx, ingressnightmare, admission-controller, nginx, ssl-engine, shared-library-injection, cluster-secrets, docker, python, c, cwe-94.</description><category>cloud</category><category>Critical</category><category>kubernetes</category><category>ingress-nginx</category><category>ingressnightmare</category><category>admission-controller</category><category>nginx</category><category>ssl-engine</category><category>shared-library-injection</category><category>cluster-secrets</category><category>docker</category><category>python</category><category>c</category><category>cwe-94</category></item><item><title>HPE OneView `id-pools/executeCommand` OS Command Injection (CVE-2025-37164)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-37164-hpe-oneview-command-injection/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-37164-hpe-oneview-command-injection/</guid><description>Critical severity (CVSS 10) — network · CVE-2025-37164. Status: PoC. Affects: HPE OneView (infrastructure management appliance) REST API. Tags: hpe-oneview, command-injection, os-command-execution, rce, rest-api, python, cwe-78.</description><category>network</category><category>Critical</category><category>hpe-oneview</category><category>command-injection</category><category>os-command-execution</category><category>rce</category><category>rest-api</category><category>python</category><category>cwe-78</category></item><item><title>Hoverfly Middleware Command Injection to RCE (CVE-2025-54123)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-54123-hoverfly-middleware-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-54123-hoverfly-middleware-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-54123. Status: Weaponized. Affects: SpectoLabs Hoverfly (HTTP/API service virtualization tool) — admin API, &lt;= v1.11.3. Tags: hoverfly, command-injection, middleware, api, token-auth, rce, cwe-78, python.</description><category>web</category><category>Critical</category><category>hoverfly</category><category>command-injection</category><category>middleware</category><category>api</category><category>token-auth</category><category>rce</category><category>cwe-78</category><category>python</category></item><item><title>Grafana Enterprise SCIM User ID Collision / Impersonation (CVE-2025-41115)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-41115-grafana-scim-user-impersonation/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-41115-grafana-scim-user-impersonation/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-41115. Status: PoC. Affects: Grafana Enterprise / Grafana Cloud, SCIM provisioning component (/api/scim/v2/Users). Tags: grafana, grafana-enterprise, scim, user-impersonation, privilege-escalation, id-collision, python, docker, cwe-287.</description><category>web</category><category>Critical</category><category>grafana</category><category>grafana-enterprise</category><category>scim</category><category>user-impersonation</category><category>privilege-escalation</category><category>id-collision</category><category>python</category><category>docker</category><category>cwe-287</category></item><item><title>Gladinet CentreStack / Triofox Hardcoded AES Key Access-Ticket Forgery to Arbitrary File Read (CVE-2025-14611)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-14611-centrestack-triofox-file-read/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-14611-centrestack-triofox-file-read/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-14611. Status: Weaponized. Affects: Gladinet CentreStack and Triofox (GladCtrl64.dll / filesvr.dn file-download handler). Tags: gladinet, centrestack, triofox, hardcoded-key, aes-256-cbc, access-ticket-forgery, arbitrary-file-read, authentication-bypass, iis-app-pool, python, cwe-798, cwe-321.</description><category>web</category><category>Critical</category><category>gladinet</category><category>centrestack</category><category>triofox</category><category>hardcoded-key</category><category>aes-256-cbc</category><category>access-ticket-forgery</category><category>arbitrary-file-read</category><category>authentication-bypass</category><category>iis-app-pool</category><category>python</category><category>cwe-798</category><category>cwe-321</category></item><item><title>Frontend Admin by DynamiApps — Unauthenticated Administrator Account Creation (CVE-2025-13342)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13342-frontend-admin-unauth-admin-creation/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13342-frontend-admin-unauth-admin-creation/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-13342. Status: Weaponized. Affects: Frontend Admin by DynamiApps (WordPress plugin built on Advanced Custom Fields / ACF frontend forms). Tags: wordpress, wordpress-plugin, frontend-admin, dynamiapps, acf, advanced-custom-fields, broken-access-control, cwe-284, privilege-escalation, unauthenticated, admin-takeover, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wordpress-plugin</category><category>frontend-admin</category><category>dynamiapps</category><category>acf</category><category>advanced-custom-fields</category><category>broken-access-control</category><category>cwe-284</category><category>privilege-escalation</category><category>unauthenticated</category><category>admin-takeover</category><category>python</category></item><item><title>Fox LMS `createOrder` Unauthenticated Privilege Escalation to Administrator (CVE-2025-14156)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-14156-fox-lms-privilege-escalation/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-14156-fox-lms-privilege-escalation/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-14156. Status: Weaponized. Affects: Fox LMS (WordPress LMS plugin). Tags: wordpress, fox-lms, rest-api, privilege-escalation, role-injection, unauthenticated, python, cwe-269.</description><category>web</category><category>Critical</category><category>wordpress</category><category>fox-lms</category><category>rest-api</category><category>privilege-escalation</category><category>role-injection</category><category>unauthenticated</category><category>python</category><category>cwe-269</category></item><item><title>FortiWeb `cgi-bin/fwbcgi` Path Traversal Authentication Bypass Leading to Rogue Admin Creation (CVE-2025-64446)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-64446-fortiweb-cgiinfo-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-64446-fortiweb-cgiinfo-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-64446. Status: PoC. Affects: Fortinet FortiWeb (Web Application Firewall appliance). Tags: fortiweb, fortinet, waf, authentication-bypass, path-traversal, cgiinfo, cwe-22, cwe-288, admin-account-creation, python.</description><category>network</category><category>Critical</category><category>fortiweb</category><category>fortinet</category><category>waf</category><category>authentication-bypass</category><category>path-traversal</category><category>cgiinfo</category><category>cwe-22</category><category>cwe-288</category><category>admin-account-creation</category><category>python</category></item></channel></rss>