PoC Archive PoC Archive

tag

Session-Poisoning

Craft CMS Pre-Auth Remote Code Execution via Session Poisoning + Yii2 PhpManager Gadget (CVE-2025-32432) KEV EPSS 100%
CVE-2025-32432 web Patched
CVE-2025-32432webCRITICAL 10Patched2026-07-31Wing FTP Server Admin Session Poisoning via Lua loadfile() RCE (CVE-2026-44403)
CVE-2026-44403 web Patched
CVE-2026-44403webHIGHPatched2026-07-05cPanel & WHM Authentication Bypass via Session-File CRLF Injection (CVE-2026-41940) KEV RW EPSS 99%
CVE-2026-41940 web Patched
CVE-2026-41940webCRITICAL 10Patched2026-05-16