PoC Archive PoC Archive

tag

Rest-Api

WordPress — Pre-Auth XSS to RCE Chain via Login Page Parser Differential (CVE-2026-64638, "XSS2Shell") EPSS 31%
CVE-2026-64638 web Unverified
CVE-2026-64638webHIGH 8.9Unverified2026-08-09CVE-2022-40684 — FortiOS / FortiProxy / FortiSwitchManager Authentication Bypass (vamp-forticheck Scanner) KEV RW EPSS 100%
CVE-2022-40684 network Unverified
CVE-2022-40684networkCRITICAL 9.8Unverified2026-07-31WordPress Mobile Builder Plugin JWT Authentication Bypass to Admin Account Creation (CVE-2025-68860)
CVE-2025-68860 web Unpatched
CVE-2025-68860webCRITICAL 9.8Unpatched2026-07-06RestroPress WordPress Plugin Unauthenticated Information Exposure Leading to JWT Forgery / Account Takeover (CVE-2025-9209)
CVE-2025-9209 web Unpatched
CVE-2025-9209webCRITICAL 9.8Unpatched2026-07-06KiotViet Sync Unauthenticated Arbitrary File Upload (CVE-2025-12674)
CVE-2025-12674 web Unverified
CVE-2025-12674webCRITICAL 9.8Unverified2026-07-06HPE OneView `id-pools/executeCommand` OS Command Injection (CVE-2025-37164) KEV EPSS 90%
CVE-2025-37164 network Unpatched
CVE-2025-37164networkCRITICAL 10Unpatched2026-07-06Fox LMS `createOrder` Unauthenticated Privilege Escalation to Administrator (CVE-2025-14156)
CVE-2025-14156 web Unverified
CVE-2025-14156webCRITICAL 9.8Unverified2026-07-06AI Engine WordPress Plugin Unauthenticated MCP Token Disclosure to Admin Account Creation (CVE-2025-11749) EPSS 75%
CVE-2025-11749 web Unverified
CVE-2025-11749webCRITICAL 9.8Unverified2026-07-06WordPress "List Site Contributors" Plugin Reflected XSS Scanner (CVE-2026-0594)
CVE-2026-0594 web Unverified
CVE-2026-0594webMEDIUMUnverified2026-07-05The Events Calendar WordPress Plugin Unauthenticated Blind SQL Injection (CVE-2026-49772)
CVE-2026-49772 web Patched
CVE-2026-49772webCRITICAL 9.3Patched2026-07-05Tandoor Recipes Authenticated Local File Disclosure via Recipe Import (CVE-2026-25964)
CVE-2026-25964 (GHSA-6485-jr28-52xx) web Patched
CVE-2026-25964webMEDIUM 4.9Patched2026-07-05Snow Monkey Forms — Unauthenticated Arbitrary File Deletion via Path Traversal (CVE-2026-1056) EPSS 12%
CVE-2026-1056 web Unverified
CVE-2026-1056webCRITICALUnverified2026-07-05Simple History Missing Authorization Account Takeover — CVE-2026-7459
CVE-2026-7459 web Unverified
CVE-2026-7459webHIGH 7.5Unverified2026-07-05Masteriyo LMS Authenticated Privilege Escalation to Administrator (CVE-2026-4484)
CVE-2026-4484 web Unverified
CVE-2026-4484webHIGH 8.8Unverified2026-07-05LatePoint Calendar Booking Plugin Agent-to-Administrator Privilege Escalation — CVE-2026-6741
CVE-2026-6741 web Patched
CVE-2026-6741webHIGH 8.8Patched2026-07-05Kirki WordPress Plugin Password-Reset Hijack Leading to Account Takeover (CVE-2026-8206)
CVE-2026-8206 web Unverified
CVE-2026-8206webCRITICAL 9.8Unverified2026-07-05Hippoo Mobile App for WooCommerce — Unauthenticated Admin Account Takeover (CVE-2026-10580)
CVE-2026-10580 web Unverified
CVE-2026-10580webCRITICAL 9.8Unverified2026-07-05ElementsKit Elementor Addons Authenticated Stored XSS via REST API (CVE-2026-2600)
CVE-2026-2600 web Patched
CVE-2026-2600webMEDIUM 6.4Patched2026-07-05