<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Unauthenticated — PoC Archive</title><link>https://poc.intelseclab.com/tags/unauthenticated/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 09 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/unauthenticated/index.xml" rel="self" type="application/rss+xml"/><item><title>Ivanti Endpoint Manager Mobile (EPMM) Unauthenticated Remote API Access (CVE-2023-35078)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2023-35078-ivanti-epmm-unauth-api-access/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2023-35078-ivanti-epmm-unauth-api-access/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2023-35078 (Ivanti advisory; CWE-287 per NVD). Status: Patched (Ivanti EPMM 11.8.1.1, 11.9.1.1, 11.10.0.2 and later). Affects: Ivanti Endpoint Manager Mobile (EPMM), previously branded MobileIron Core — the /mifs/aad/api/ administrative API surface. Tags: ivanti, epmm, mobileiron-core, mdm, authentication-bypass, cwe-287, unauthenticated, api, pii-disclosure, cisa-kev, ransomware, scanner.</description><category>network</category><category>Critical</category><category>ivanti</category><category>epmm</category><category>mobileiron-core</category><category>mdm</category><category>authentication-bypass</category><category>cwe-287</category><category>unauthenticated</category><category>api</category><category>pii-disclosure</category><category>cisa-kev</category><category>ransomware</category><category>scanner</category></item><item><title>Ivanti Connect Secure / Policy Secure / ZTA Gateways Remote Unauthenticated Stack-Based Buffer Overflow (CVE-2025-22457)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2025-22457-ivanti-connect-secure-stack-overflow/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2025-22457-ivanti-connect-secure-stack-overflow/</guid><description>Critical severity (CVSS 9) — network · CVE-2025-22457. Status: Patched. Affects: Ivanti Connect Secure, Pulse Connect Secure (end of support), Ivanti Policy Secure, Ivanti ZTA Gateways — the /home/bin/web HTTPS front-end process. Tags: ivanti, connect-secure, pulse-connect-secure, policy-secure, zta-gateway, vpn, stack-overflow, CWE-121, buffer-overflow, rce, unauthenticated, rop, heap-spray, aslr-bruteforce, x-forwarded-for, cisa-kev, ransomware, ruby, edge-device.</description><category>network</category><category>Critical</category><category>ivanti</category><category>connect-secure</category><category>pulse-connect-secure</category><category>policy-secure</category><category>zta-gateway</category><category>vpn</category><category>stack-overflow</category><category>CWE-121</category><category>buffer-overflow</category><category>rce</category><category>unauthenticated</category><category>rop</category><category>heap-spray</category><category>aslr-bruteforce</category><category>x-forwarded-for</category><category>cisa-kev</category><category>ransomware</category><category>ruby</category><category>edge-device</category></item><item><title>GitLab Unauthenticated RCE via Workhorse Pre-Auth Upload into ExifTool DjVu Injection (CVE-2021-22205)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2021-22205-gitlab-exiftool-preauth-rce/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2021-22205-gitlab-exiftool-preauth-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2021-22205 (chains CVE-2021-22204 in ExifTool). Status: Patched (GitLab 13.8.8, 13.9.6, 13.10.3). Affects: GitLab Community Edition and Enterprise Edition (via bundled ExifTool, invoked by GitLab Workhorse). Tags: gitlab, exiftool, djvu, rce, preauth, unauthenticated, workhorse, perl, qx, reverse-shell, metadata-injection, kev, ransomware, python, cve-2021-22205, cve-2021-22204.</description><category>web</category><category>Critical</category><category>gitlab</category><category>exiftool</category><category>djvu</category><category>rce</category><category>preauth</category><category>unauthenticated</category><category>workhorse</category><category>perl</category><category>qx</category><category>reverse-shell</category><category>metadata-injection</category><category>kev</category><category>ransomware</category><category>python</category><category>cve-2021-22205</category><category>cve-2021-22204</category></item><item><title>CyberPanel Pre-Auth Remote Code Execution via getresetstatus Command Injection (CVE-2024-51378)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2024-51378-cyberpanel-preauth-rce/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2024-51378-cyberpanel-preauth-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2024-51378. Status: Patched (commit 1c0c6cb; CyberPanel 2.3.8 and later). Affects: CyberPanel (aka Cyber Panel), by CyberPersons — Django-based hosting control panel. Tags: cyberpanel, rce, command-injection, preauth, unauthenticated, options-method, secmiddleware-bypass, statusfile, kev, ransomware, psaux, python, httpx, cve-2024-51378.</description><category>web</category><category>Critical</category><category>cyberpanel</category><category>rce</category><category>command-injection</category><category>preauth</category><category>unauthenticated</category><category>options-method</category><category>secmiddleware-bypass</category><category>statusfile</category><category>kev</category><category>ransomware</category><category>psaux</category><category>python</category><category>httpx</category><category>cve-2024-51378</category></item><item><title>Barrier 2.4.0 — barrierd.exe Unauthenticated IPC → SYSTEM Privilege Escalation (NotCVE-2026-0010)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-01_notcve-2026-0010-barrier-daemon-lpe/</link><pubDate>Sat, 01 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-01_notcve-2026-0010-barrier-daemon-lpe/</guid><description>High severity — binary · NotCVE-2026-0010 (disputed CVE assignment — author contests the identifier). Status: Unpatched — Barrier is unmaintained with no vendor fix; patched successor Deskflow covers the same issue via CVE-2026-41477 / GHSA-6rx5-g478-775c. Affects: Barrier (debauchee), Windows service daemon barrierd.exe. Tags: barrier, barrierd, windows, ipc, tcp-24801, unauthenticated, lpe, privilege-escalation, system, cwe-306, local.</description><category>binary</category><category>High</category><category>barrier</category><category>barrierd</category><category>windows</category><category>ipc</category><category>tcp-24801</category><category>unauthenticated</category><category>lpe</category><category>privilege-escalation</category><category>system</category><category>cwe-306</category><category>local</category></item><item><title>Microweber CMS Unauthenticated Path Traversal → Arbitrary File Read (CVE-2026-65694)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2026-65694-microweber-path-traversal/</link><pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2026-65694-microweber-path-traversal/</guid><description>High severity (CVSS 7.5) — web · CVE-2026-65694 (VulnCheck advisory). Status: Unpatched. Affects: Microweber CMS — ServeStaticFileContoller::serveFromUserfiles(). Tags: microweber, path-traversal, cwe-22, unauthenticated, arbitrary-file-read, laravel, query-string-override.</description><category>web</category><category>High</category><category>microweber</category><category>path-traversal</category><category>cwe-22</category><category>unauthenticated</category><category>arbitrary-file-read</category><category>laravel</category><category>query-string-override</category></item><item><title>IBM Langflow OSS Unauthenticated RCE via Auto-Login + validate/code Chain (CVE-2026-9198)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2026-9198-langflow-auto-login-validate-code-rce/</link><pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2026-9198-langflow-auto-login-validate-code-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-9198. Status: Weaponized. Affects: IBM Langflow OSS (visual AI/agent-flow builder). Tags: langflow, ibm, auto-login, code-injection, cwe-94, unauthenticated, rce, python-exec, ai-agent-framework.</description><category>web</category><category>Critical</category><category>langflow</category><category>ibm</category><category>auto-login</category><category>code-injection</category><category>cwe-94</category><category>unauthenticated</category><category>rce</category><category>python-exec</category><category>ai-agent-framework</category></item><item><title>Craft CMS Pre-Auth Remote Code Execution via Session Poisoning + Yii2 PhpManager Gadget (CVE-2025-32432)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2025-32432-craftcms-preauth-rce/</link><pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-31_cve-2025-32432-craftcms-preauth-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-32432. Status: Patched (Craft CMS 5.6.17+). Affects: Craft CMS (craftcms/cms). Tags: craftcms, rce, preauth, session-poisoning, php-deserialization, yii2, phpfpm, unauthenticated, go, cve-2025-32432.</description><category>web</category><category>Critical</category><category>craftcms</category><category>rce</category><category>preauth</category><category>session-poisoning</category><category>php-deserialization</category><category>yii2</category><category>phpfpm</category><category>unauthenticated</category><category>go</category><category>cve-2025-32432</category></item><item><title>Rails Active Storage Arbitrary File Read to RCE via libvips Unfuzzed Loaders (CVE-2026-66066)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-66066-rails-activestorage-libvips-rce/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-66066-rails-activestorage-libvips-rce/</guid><description>Critical severity (CVSS 9.5) — web · CVE-2026-66066 (GHSA-xr9x-r78c-5hrm). Status: Weaponized. Affects: Ruby on Rails — Active Storage (image variant processing via :vips/libvips). Tags: ruby-on-rails, active-storage, libvips, arbitrary-file-read, marshal-deserialization, rce, unauthenticated, cwe-22.</description><category>web</category><category>Critical</category><category>ruby-on-rails</category><category>active-storage</category><category>libvips</category><category>arbitrary-file-read</category><category>marshal-deserialization</category><category>rce</category><category>unauthenticated</category><category>cwe-22</category></item><item><title>Microsoft SharePoint Server WS-Federation SecurityContextToken Deserialization → Unauthenticated RCE (CVE-2026-50522)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-50522-sharepoint-preauth-rce/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-50522-sharepoint-preauth-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-50522. Status: Weaponized — public PoC confirmed used in real attacks within hours of release (watchTowr honeypot telemetry). Affects: Microsoft SharePoint Server (on-premises). Tags: sharepoint, deserialization, binaryformatter, ws-federation, unauthenticated, rce, kev, actively-exploited, microsoft.</description><category>web</category><category>Critical</category><category>sharepoint</category><category>deserialization</category><category>binaryformatter</category><category>ws-federation</category><category>unauthenticated</category><category>rce</category><category>kev</category><category>actively-exploited</category><category>microsoft</category></item><item><title>Joomla Helix Ultimate Framework — Unauthenticated Arbitrary File Deletion (CVE-2026-57830)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-57830-joomla-helix-ultimate-file-deletion/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-57830-joomla-helix-ultimate-file-deletion/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2026-57830. Status: Weaponized. Affects: Helix Ultimate Framework (plg_system_helixultimate), the JoomShaper Joomla template framework bundled with virtually every JoomShaper Joomla template. Tags: joomla, helix-ultimate, joomshaper, arbitrary-file-deletion, cwe-862, unauthenticated, csrf-token-only-check.</description><category>web</category><category>Critical</category><category>joomla</category><category>helix-ultimate</category><category>joomshaper</category><category>arbitrary-file-deletion</category><category>cwe-862</category><category>unauthenticated</category><category>csrf-token-only-check</category></item><item><title>Joomla Balbooa Forms Unauthenticated Arbitrary File Upload → RCE (CVE-2026-56291)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-56291-joomla-balbooa-forms-file-upload-rce/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-56291-joomla-balbooa-forms-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-56291. Status: Weaponized. Affects: Balbooa Forms (com_baforms) — third-party Joomla! extension by balbooa.com. Tags: joomla, balbooa-forms, file-upload, webshell, unauthenticated, rce, kev, actively-exploited, cwe-434.</description><category>web</category><category>Critical</category><category>joomla</category><category>balbooa-forms</category><category>file-upload</category><category>webshell</category><category>unauthenticated</category><category>rce</category><category>kev</category><category>actively-exploited</category><category>cwe-434</category></item><item><title>Crawl4AI JsonCssExtractionStrategy AST Sandbox Escape → Unauthenticated RCE (CVE-2026-53753)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-53753-crawl4ai-sandbox-escape-rce/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-53753-crawl4ai-sandbox-escape-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-53753 (GHSA-qxjp-w3pj-48m7). Status: Weaponized — full end-to-end command execution reproduced against the official unclecode/crawl4ai:0.8.6 image. Affects: Crawl4AI — open-source LLM-friendly web crawler/scraper, Docker API server. Tags: crawl4ai, sandbox-escape, rce, python, ast-bypass, unauthenticated, llm-tooling, ai-security.</description><category>web</category><category>Critical</category><category>crawl4ai</category><category>sandbox-escape</category><category>rce</category><category>python</category><category>ast-bypass</category><category>unauthenticated</category><category>llm-tooling</category><category>ai-security</category></item><item><title>Budibase Unauthenticated NoSQL Operator Injection (CVE-2026-54350)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-54350-budibase-nosql-injection/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-54350-budibase-nosql-injection/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-54350 (GHSA-8qv3-p479-cj62). Status: Weaponized — reproduced end-to-end against a real budibase/budibase:3.39.0 instance. Affects: Budibase (open-source low-code application platform) — POST /api/v2/queries/:queryId. Tags: budibase, nosql-injection, mongodb, unauthenticated, low-code, json-injection.</description><category>web</category><category>Critical</category><category>budibase</category><category>nosql-injection</category><category>mongodb</category><category>unauthenticated</category><category>low-code</category><category>json-injection</category></item><item><title>Apache APISIX `jwe-decrypt` Integrity-Check Bypass → Unauthenticated Gateway Auth Bypass (CVE-2026-49230)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-49230-apisix-jwe-decrypt-auth-bypass/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-49230-apisix-jwe-decrypt-auth-bypass/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2026-49230. Status: Weaponized. Affects: Apache APISIX — jwe-decrypt auth plugin (apisix/plugins/jwe-decrypt.lua). Tags: apache-apisix, jwe, jwt, integrity-bypass, cwe-354, unauthenticated, api-gateway, lua.</description><category>web</category><category>Critical</category><category>apache-apisix</category><category>jwe</category><category>jwt</category><category>integrity-bypass</category><category>cwe-354</category><category>unauthenticated</category><category>api-gateway</category><category>lua</category></item><item><title>wp2shell — WordPress Core Pre-Auth SQLi → Row Forgery → Admin Creation → RCE (CVE-2026-63030 + CVE-2026-60137)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-63030-cve-2026-60137-wp2shell-wordpress-core-preauth-rce/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-63030-cve-2026-60137-wp2shell-wordpress-core-preauth-rce/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2026-63030 (REST /batch/v1 route confusion, CVSS 7.5), CVE-2026-60137 (author__not_in SQL injection, CVSS 9.1); GHSA-ff9f-jf42-662q, GHSA-fpp7-x2x2-2mjf. Status: Weaponized — full pre-auth RCE confirmed against stock-default WordPress core, no plugins/misconfiguration required. Affects: WordPress core (REST API /batch/v1, WP_Query::author__not_in). Tags: wordpress, wp-core, sql-injection, route-confusion, cwe-89, cwe-436, unauthenticated, remote, privilege-escalation, rce, oembed, changeset.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wp-core</category><category>sql-injection</category><category>route-confusion</category><category>cwe-89</category><category>cwe-436</category><category>unauthenticated</category><category>remote</category><category>privilege-escalation</category><category>rce</category><category>oembed</category><category>changeset</category></item><item><title>SimpleHelp OIDC Authentication Bypass via Unverified JWT Signature (CVE-2026-48558)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-48558-simplehelp-oidc-auth-bypass/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-48558-simplehelp-oidc-auth-bypass/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-48558. Status: Weaponized — forges valid privileged sessions with no credentials. Affects: SimpleHelp — remote support / RMM (remote monitoring and management) platform, OIDC authentication flow. Tags: simplehelp, rmm, oidc, jwt, alg-none, cwe-347, authentication-bypass, unauthenticated, remote, kev, actively-exploited, ransomware.</description><category>web</category><category>Critical</category><category>simplehelp</category><category>rmm</category><category>oidc</category><category>jwt</category><category>alg-none</category><category>cwe-347</category><category>authentication-bypass</category><category>unauthenticated</category><category>remote</category><category>kev</category><category>actively-exploited</category><category>ransomware</category></item><item><title>Cisco Unified Communications Manager WebDialer SSRF → Arbitrary File Write → Root (CVE-2026-20230)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-19_cve-2026-20230-cisco-ucm-ssrf-arbitrary-file-write/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-19_cve-2026-20230-cisco-ucm-ssrf-arbitrary-file-write/</guid><description>Critical severity (CVSS 8.6) — network · CVE-2026-20230 (cisco-sa-cucm-ssrf-cXPnHcW). Status: PoC — scanner/tester confirms the WebDialer precondition and SSRF reachability. Affects: Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (SME) — WebDialer service. Tags: cisco, unified-communications-manager, ucm, webdialer, ssrf, cwe-918, unauthenticated, remote, privilege-escalation, kev, actively-exploited.</description><category>network</category><category>Critical</category><category>cisco</category><category>unified-communications-manager</category><category>ucm</category><category>webdialer</category><category>ssrf</category><category>cwe-918</category><category>unauthenticated</category><category>remote</category><category>privilege-escalation</category><category>kev</category><category>actively-exploited</category></item><item><title>Adobe ColdFusion RDS Path Traversal → Arbitrary File Read/Write → RCE (CVE-2026-48282)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-48282-coldfusion-rds-path-traversal-rce/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-48282-coldfusion-rds-path-traversal-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-48282 (Adobe APSB26-68). Status: Weaponized — arbitrary file read/write, directory browsing, webshell deployment, and command execution all confirmed. Affects: Adobe ColdFusion — Remote Development Service (RDS), /CFIDE/main/ide.cfm. Tags: coldfusion, adobe, rds, path-traversal, cwe-22, unauthenticated, remote, webshell, kev, actively-exploited.</description><category>web</category><category>Critical</category><category>coldfusion</category><category>adobe</category><category>rds</category><category>path-traversal</category><category>cwe-22</category><category>unauthenticated</category><category>remote</category><category>webshell</category><category>kev</category><category>actively-exploited</category></item><item><title>SonicWall SMA1000 WorkPlace SSRF → Internal Erlang RPC Remote Code Execution (CVE-2026-15409)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-15_cve-2026-15409-sonicwall-sma1000-ssrf-erlang-rce/</link><pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-15_cve-2026-15409-sonicwall-sma1000-ssrf-erlang-rce/</guid><description>Critical severity (CVSS 10) — network · CVE-2026-15409 (SNWLID-2026-0008). Status: Weaponized — unauthenticated, non-root remote code execution confirmed against a real appliance build. Affects: SonicWall SMA1000 Appliance — WorkPlace interface (websocket proxy service). Tags: sonicwall, sma1000, workplace, ssrf, erlang, rpc, cwe-918, unauthenticated, remote, kev, actively-exploited.</description><category>network</category><category>Critical</category><category>sonicwall</category><category>sma1000</category><category>workplace</category><category>ssrf</category><category>erlang</category><category>rpc</category><category>cwe-918</category><category>unauthenticated</category><category>remote</category><category>kev</category><category>actively-exploited</category></item><item><title>Flowise Enterprise Authentication Bypass via Hardcoded Default JWT Secrets (CVE-2026-56271)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-12_cve-2026-56271-flowise-hardcoded-jwt-authbypass/</link><pubDate>Sun, 12 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-12_cve-2026-56271-flowise-hardcoded-jwt-authbypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-56271 (GHSA-cc4f-hjpj-g9p8). Status: Weaponized (functional PoC forges valid admin JWTs and confirms bypass against real endpoints). Affects: Flowise — open-source low-code LLM/agent orchestration platform (enterprise edition, passport authentication middleware). Tags: flowise, ai-gateway, llm-orchestration, jwt, hardcoded-secret, authentication-bypass, cwe-321, unauthenticated, remote, privilege-escalation.</description><category>web</category><category>Critical</category><category>flowise</category><category>ai-gateway</category><category>llm-orchestration</category><category>jwt</category><category>hardcoded-secret</category><category>authentication-bypass</category><category>cwe-321</category><category>unauthenticated</category><category>remote</category><category>privilege-escalation</category></item><item><title>Crawl4AI Docker API Server Arbitrary File Write via `output_path` (CVE-2026-56260)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-12_cve-2026-56260-crawl4ai-output-path-arbitrary-write/</link><pubDate>Sun, 12 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-12_cve-2026-56260-crawl4ai-output-path-arbitrary-write/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2026-56260 (GHSA-365w-hqf6-vxfg). Status: PoC — lab (vulnerable-app/) demonstrates genuine unrestricted arbitrary file write; the bundled poc.py scanner is deliberately conservative (writes only to a randomized safe /tmp marker) so it is safe to run against real/production targets. See Notes.. Affects: Crawl4AI — open-source LLM-friendly web crawler/scraper (unclecode/crawl4ai), Docker API server mode. Tags: crawl4ai, ai-web-crawler, docker-api, path-traversal, arbitrary-file-write, cwe-22, unauthenticated, remote, denial-of-service.</description><category>web</category><category>Critical</category><category>crawl4ai</category><category>ai-web-crawler</category><category>docker-api</category><category>path-traversal</category><category>arbitrary-file-write</category><category>cwe-22</category><category>unauthenticated</category><category>remote</category><category>denial-of-service</category></item><item><title>ZKTeco BioTime v8.5.5 Unauthenticated Path Traversal / Arbitrary File Read via iclock API (CVE-2023-38950)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2023-38950-zkteco-biotime-path-traversal/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2023-38950-zkteco-biotime-path-traversal/</guid><description>High severity (CVSS 7.5) — web · CVE-2023-38950. Status: Weaponized (public PoC, in CISA KEV). Affects: ZKTeco BioTime (web-based time &amp; attendance / access control management platform). Tags: zkteco, biotime, path-traversal, arbitrary-file-read, cwe-22, unauthenticated, remote, iclock-api, kev.</description><category>web</category><category>High</category><category>zkteco</category><category>biotime</category><category>path-traversal</category><category>arbitrary-file-read</category><category>cwe-22</category><category>unauthenticated</category><category>remote</category><category>iclock-api</category><category>kev</category></item><item><title>Unauthenticated Arbitrary File Upload RCE in iCagenda for Joomla (CVE-2026-48939)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2026-48939-icagenda-joomla-file-upload-rce/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2026-48939-icagenda-joomla-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-48939. Status: Weaponized (public PoC available, actively exploited in the wild, in CISA KEV since 2026-07-10). Affects: iCagenda — events/calendar extension (component) for Joomla. Tags: joomla, icagenda, file-upload, rce, cwe-434, unauthenticated, remote, kev, cms, php, access-control-bypass.</description><category>web</category><category>Critical</category><category>joomla</category><category>icagenda</category><category>file-upload</category><category>rce</category><category>cwe-434</category><category>unauthenticated</category><category>remote</category><category>kev</category><category>cms</category><category>php</category><category>access-control-bypass</category></item><item><title>Sitecore XP Report.ashx Insecure Deserialization RCE (CVE-2021-42237)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2021-42237-sitecore-xp-deserialization-rce/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2021-42237-sitecore-xp-deserialization-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2021-42237 (Sitecore advisory SC2021-003-499266). Status: Weaponized (public PoC + Metasploit module, in CISA KEV, known ransomware campaign use). Affects: Sitecore Experience Platform (XP). Tags: sitecore, deserialization, rce, cms, unauthenticated, remote, kev, known-ransomware-use, cwe-502.</description><category>web</category><category>Critical</category><category>sitecore</category><category>deserialization</category><category>rce</category><category>cms</category><category>unauthenticated</category><category>remote</category><category>kev</category><category>known-ransomware-use</category><category>cwe-502</category></item><item><title>LiteLLM Proxy Pre-Authentication SQL Injection via Error-Handling Callback (CVE-2026-42208)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2026-42208-litellm-sqli-proxy-authbypass/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2026-42208-litellm-sqli-proxy-authbypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-42208 (GHSA-r75f-5x8p-qvmc). Status: Weaponized (public working PoC + Docker lab, actively exploited in the wild within 36 hours of disclosure). Affects: LiteLLM Proxy — open-source LLM/AI gateway (22,000+ GitHub stars) fronting OpenAI, Anthropic, and other model provider APIs. Tags: litellm, ai-gateway, llm-proxy, sql-injection, cwe-89, unauthenticated, remote, blind-sqli, kev-adjacent, credential-theft.</description><category>web</category><category>Critical</category><category>litellm</category><category>ai-gateway</category><category>llm-proxy</category><category>sql-injection</category><category>cwe-89</category><category>unauthenticated</category><category>remote</category><category>blind-sqli</category><category>kev-adjacent</category><category>credential-theft</category></item><item><title>Gitea Docker Image Reverse-Proxy Authentication Bypass — "One Header, Any User" (CVE-2026-20896)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2026-20896-gitea-docker-reverse-proxy-auth-bypass/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2026-20896-gitea-docker-reverse-proxy-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-20896 (GHSA-f75j-4cw6-rmx4). Status: Weaponized (public PoC + detector script, actively exploited in the wild per Sysdig). Affects: Gitea — official Docker images (gitea/gitea), both root and rootless variants. Tags: gitea, docker, authentication-bypass, reverse-proxy, header-spoofing, unauthenticated, remote, cwe-290, actively-exploited.</description><category>web</category><category>Critical</category><category>gitea</category><category>docker</category><category>authentication-bypass</category><category>reverse-proxy</category><category>header-spoofing</category><category>unauthenticated</category><category>remote</category><category>cwe-290</category><category>actively-exploited</category></item><item><title>D-Link DIR-820L `get_set.ccp` LAN Configuration OS Command Injection (CVE-2022-26258)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-11_cve-2022-26258-dlink-dir820l-command-injection/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-11_cve-2022-26258-dlink-dir820l-command-injection/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2022-26258. Status: Weaponized (public PoC available; listed in CISA KEV). Affects: D-Link DIR-820L wireless router, all hardware revisions. Tags: d-link, dir-820l, router, command-injection, cwe-78, unauthenticated, remote, iot, eol-device, kev.</description><category>network</category><category>Critical</category><category>d-link</category><category>dir-820l</category><category>router</category><category>command-injection</category><category>cwe-78</category><category>unauthenticated</category><category>remote</category><category>iot</category><category>eol-device</category><category>kev</category></item><item><title>XRING — XQUIC QPACK Ring Buffer Resize Underflow (Remote Unauthenticated DoS)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-08_xring-xquic-qpack-ring-mem-resize-underflow/</link><pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-08_xring-xquic-qpack-ring-mem-resize-underflow/</guid><description>Critical severity — network. Status: Weaponized (public PoC, unpatched at publication). Affects: [alibaba/xquic](https://github.com/alibaba/xquic) — QUIC/HTTP-3 library, used by Tengine and reportedly across Alibaba's cloud/CDN infrastructure (Taobao, AliPay). Tags: quic, http3, qpack, xquic, alibaba, tengine, ring-buffer, integer-underflow, heap-oob-read, memcpy, remote, unauthenticated, dos, no-cve.</description><category>network</category><category>Critical</category><category>quic</category><category>http3</category><category>qpack</category><category>xquic</category><category>alibaba</category><category>tengine</category><category>ring-buffer</category><category>integer-underflow</category><category>heap-oob-read</category><category>memcpy</category><category>remote</category><category>unauthenticated</category><category>dos</category><category>no-cve</category></item><item><title>XWiki SolrSearch Macro Unauthenticated Groovy RCE (CVE-2025-24893)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-24893-xwiki-solrsearch-groovy-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-24893-xwiki-solrsearch-groovy-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-24893. Status: Weaponized. Affects: XWiki (SolrSearch macro, Main.SolrSearch). Tags: xwiki, groovy, rce, unauthenticated, cwe-94, code-injection, reverse-shell, python, wiki.</description><category>web</category><category>Critical</category><category>xwiki</category><category>groovy</category><category>rce</category><category>unauthenticated</category><category>cwe-94</category><category>code-injection</category><category>reverse-shell</category><category>python</category><category>wiki</category></item><item><title>WordPress WPAMS Plugin Arbitrary File Upload to RCE (CVE-2025-39401)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-39401-wpams-arbitrary-file-upload-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-39401-wpams-arbitrary-file-upload-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-39401. Status: Weaponized. Affects: WPAMS (WordPress Apartment/Property Management System) plugin by mojoomla. Tags: wordpress, wpams, mojoomla, arbitrary-file-upload, webshell, rce, unauthenticated, python, multithreaded, cwe-434.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wpams</category><category>mojoomla</category><category>arbitrary-file-upload</category><category>webshell</category><category>rce</category><category>unauthenticated</category><category>python</category><category>multithreaded</category><category>cwe-434</category></item><item><title>WooCommerce Dynamic Pricing &amp; Discounts (WC Designer Pro) Unauthenticated File Upload RCE (CVE-2025-6440)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-6440-woocommerce-dynamic-pricing-file-upload-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-6440-woocommerce-dynamic-pricing-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-6440. Status: Weaponized. Affects: WordPress WooCommerce Dynamic Pricing &amp; Discounts plugin (wc-designer-pro). Tags: wordpress, woocommerce, wc-designer-pro, dynamic-pricing, file-upload, rce, unauthenticated, wp-ajax, cwe-434, nuclei.</description><category>web</category><category>Critical</category><category>wordpress</category><category>woocommerce</category><category>wc-designer-pro</category><category>dynamic-pricing</category><category>file-upload</category><category>rce</category><category>unauthenticated</category><category>wp-ajax</category><category>cwe-434</category><category>nuclei</category></item><item><title>Webkul Medical Prescription Attachment for WooCommerce — Unrestricted File Upload to Web Shell (CVE-2025-29009)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-29009-woocommerce-medical-prescription-file-upload/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-29009-woocommerce-medical-prescription-file-upload/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-29009. Status: Weaponized. Affects: Webkul "Medical Prescription Attachment Plugin for WooCommerce" (WordPress plugin). Tags: wordpress, woocommerce, medical-prescription-attachment, unrestricted-file-upload, webshell, cwe-434, unauthenticated, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>woocommerce</category><category>medical-prescription-attachment</category><category>unrestricted-file-upload</category><category>webshell</category><category>cwe-434</category><category>unauthenticated</category><category>python</category></item><item><title>WavePlayer Unauthenticated Arbitrary File Upload to RCE (CVE-2025-12057)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-12057-waveplayer-webshell-upload/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-12057-waveplayer-webshell-upload/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-12057. Status: Weaponized. Affects: WavePlayer (WordPress plugin). Tags: wordpress, waveplayer, arbitrary-file-upload, unauthenticated, rce, webshell, ajax, nonce, php, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>waveplayer</category><category>arbitrary-file-upload</category><category>unauthenticated</category><category>rce</category><category>webshell</category><category>ajax</category><category>nonce</category><category>php</category><category>python</category></item><item><title>Twonky Server 8.5.2 Unauthenticated `/nmc/rpc/` Auth Bypass &amp; Admin Credential Log Leak (CVE-2025-13315)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-13315-twonky-server-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-13315-twonky-server-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-13315. Status: PoC. Affects: Twonky Server (Lynx Technology), a DLNA/UPnP media server. Tags: twonky-server, dlna, upnp, media-server, auth-bypass, access-control, information-disclosure, credential-leak, cwe-284, unauthenticated, nuclei.</description><category>network</category><category>Critical</category><category>twonky-server</category><category>dlna</category><category>upnp</category><category>media-server</category><category>auth-bypass</category><category>access-control</category><category>information-disclosure</category><category>credential-leak</category><category>cwe-284</category><category>unauthenticated</category><category>nuclei</category></item><item><title>TNC Toolbox: Web Performance Unauthenticated cPanel Credential Exposure (CVE-2025-12539)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-12539-tnc-toolbox-cpanel-creds-exposure/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-12539-tnc-toolbox-cpanel-creds-exposure/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-12539. Status: Weaponized. Affects: TNC Toolbox: Web Performance (WordPress plugin). Tags: wordpress, tnc-toolbox, sensitive-information-exposure, unauthenticated, cpanel, credential-theft, privilege-escalation, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>tnc-toolbox</category><category>sensitive-information-exposure</category><category>unauthenticated</category><category>cpanel</category><category>credential-theft</category><category>privilege-escalation</category><category>python</category></item><item><title>StoryChief WordPress Plugin Unauthenticated Arbitrary File Upload via Webhook (CVE-2025-7441)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-7441-storychief-webhook-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-7441-storychief-webhook-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-7441. Status: PoC. Affects: StoryChief WordPress plugin. Tags: storychief, wordpress, wordpress-plugin, arbitrary-file-upload, ssrf, remote-code-execution, unauthenticated, webhook, hmac, cwe-434, python.</description><category>web</category><category>Critical</category><category>storychief</category><category>wordpress</category><category>wordpress-plugin</category><category>arbitrary-file-upload</category><category>ssrf</category><category>remote-code-execution</category><category>unauthenticated</category><category>webhook</category><category>hmac</category><category>cwe-434</category><category>python</category></item><item><title>StoreKeeper for WooCommerce Unauthenticated Arbitrary File Upload (CVE-2025-48148)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-48148-storekeeper-woocommerce-webshell-upload/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-48148-storekeeper-woocommerce-webshell-upload/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-48148. Status: Weaponized. Affects: StoreKeeper for WooCommerce (WordPress plugin). Tags: wordpress, woocommerce, storekeeper, arbitrary-file-upload, unauthenticated, webshell, rce, cwe-434, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>woocommerce</category><category>storekeeper</category><category>arbitrary-file-upload</category><category>unauthenticated</category><category>webshell</category><category>rce</category><category>cwe-434</category><category>python</category></item><item><title>Sneeit Framework &lt;= 8.3 Unauthenticated RCE via `call_user_func()` — Rogue Admin Creation (CVE-2025-6389)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-6389-wordpress-rogue-admin-user-creation/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-6389-wordpress-rogue-admin-user-creation/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-6389. Status: Weaponized. Affects: Sneeit Framework (WordPress theme framework plugin, sneeit-framework). Tags: wordpress, sneeit-framework, rce, call_user_func, unauthenticated, wp_insert_user, privilege-escalation, admin-takeover, cwe-94, wp-ajax-nopriv.</description><category>web</category><category>Critical</category><category>wordpress</category><category>sneeit-framework</category><category>rce</category><category>call_user_func</category><category>unauthenticated</category><category>wp_insert_user</category><category>privilege-escalation</category><category>admin-takeover</category><category>cwe-94</category><category>wp-ajax-nopriv</category></item><item><title>Simple User Registration WordPress Plugin — Unauthenticated Privilege Escalation (CVE-2025-4334)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-4334-simple-user-registration-privesc/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-4334-simple-user-registration-privesc/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-4334. Status: PoC. Affects: "Simple User Registration" WordPress plugin (registration/form-builder plugin, wpr_submit_form AJAX action). Tags: wordpress, wp-plugin, simple-user-registration, privilege-escalation, unauthenticated, admin-ajax, cwe-269, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wp-plugin</category><category>simple-user-registration</category><category>privilege-escalation</category><category>unauthenticated</category><category>admin-ajax</category><category>cwe-269</category><category>python</category></item><item><title>Simple Business Directory Pro Unauthenticated Password Reset to Admin Takeover (CVE-2025-53580)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-53580-sbd-password-reset-privesc/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-53580-sbd-password-reset-privesc/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-53580. Status: Weaponized. Affects: quantumcloud "Simple Business Directory Pro" WordPress plugin (simple-business-directory-pro). Tags: wordpress, wordpress-plugin, simple-business-directory-pro, password-reset, privilege-escalation, incorrect-privilege-assignment, cwe-266, account-takeover, unauthenticated, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wordpress-plugin</category><category>simple-business-directory-pro</category><category>password-reset</category><category>privilege-escalation</category><category>incorrect-privilege-assignment</category><category>cwe-266</category><category>account-takeover</category><category>unauthenticated</category><category>python</category></item><item><title>Real Spaces WordPress Theme Unauthenticated Privilege Escalation via `imic_agent_register` (CVE-2025-6758)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-6758-realspaces-privesc/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-6758-realspaces-privesc/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-6758. Status: Weaponized. Affects: Real Spaces - Properties Directory Theme for WordPress (imic_agent_register AJAX handler). Tags: wordpress, real-spaces, imic, privilege-escalation, unauthenticated, admin-ajax, role-assignment, cwe-269, cwe-863, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>real-spaces</category><category>imic</category><category>privilege-escalation</category><category>unauthenticated</category><category>admin-ajax</category><category>role-assignment</category><category>cwe-269</category><category>cwe-863</category><category>python</category></item><item><title>React Native Community CLI Metro Dev Server `/open-url` OS Command Injection (CVE-2025-11953)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-11953-react-native-metro-command-injection/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-11953-react-native-metro-command-injection/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-11953. Status: Weaponized. Affects: @react-native-community/cli / @react-native-community/cli-server-api (Metro Development Server, openURLMiddleware). Tags: react-native, metro, dev-server, cli-server-api, open-url, command-injection, cwe-78, unauthenticated, node.js, python, windows, cross-platform.</description><category>network</category><category>Critical</category><category>react-native</category><category>metro</category><category>dev-server</category><category>cli-server-api</category><category>open-url</category><category>command-injection</category><category>cwe-78</category><category>unauthenticated</category><category>node.js</category><category>python</category><category>windows</category><category>cross-platform</category></item><item><title>Pterodactyl Panel Unauthenticated Path Traversal via locale.json Leaking Database Credentials (CVE-2025-49132)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-49132-pterodactyl-locale-path-traversal/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-49132-pterodactyl-locale-path-traversal/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-49132. Status: Weaponized. Affects: Pterodactyl Panel (game server management panel). Tags: pterodactyl, path-traversal, unauthenticated, information-disclosure, credential-leak, database, php, config-exposure, cwe-22.</description><category>web</category><category>Critical</category><category>pterodactyl</category><category>path-traversal</category><category>unauthenticated</category><category>information-disclosure</category><category>credential-leak</category><category>database</category><category>php</category><category>config-exposure</category><category>cwe-22</category></item><item><title>Kubio AI Page Builder &lt;= 2.5.1 Unauthenticated Local File Inclusion (CVE-2025-2294)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-2294-kubio-lfi/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-2294-kubio-lfi/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-2294. Status: PoC. Affects: Kubio AI Page Builder (WordPress plugin). Tags: wordpress, kubio, page-builder, lfi, local-file-inclusion, unauthenticated, php, python, cwe-98.</description><category>web</category><category>Critical</category><category>wordpress</category><category>kubio</category><category>page-builder</category><category>lfi</category><category>local-file-inclusion</category><category>unauthenticated</category><category>php</category><category>python</category><category>cwe-98</category></item><item><title>KiotViet Sync Unauthenticated Arbitrary File Upload (CVE-2025-12674)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-12674-kiotviet-sync-file-upload/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-12674-kiotviet-sync-file-upload/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-12674. Status: Weaponized. Affects: KiotViet Sync (WordPress plugin). Tags: wordpress, kiotviet-sync, arbitrary-file-upload, unauthenticated, rce, rest-api, webshell, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>kiotviet-sync</category><category>arbitrary-file-upload</category><category>unauthenticated</category><category>rce</category><category>rest-api</category><category>webshell</category><category>python</category></item><item><title>JAY Login &amp; Register "Switch Back" Cookie Authentication Bypass (CVE-2025-14440)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-14440-jay-login-register-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-14440-jay-login-register-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-14440. Status: Weaponized. Affects: JAY Login &amp; Register (WordPress plugin). Tags: wordpress, jay-login-register, authentication-bypass, cookie-manipulation, unauthenticated, python, cwe-287, cwe-290.</description><category>web</category><category>Critical</category><category>wordpress</category><category>jay-login-register</category><category>authentication-bypass</category><category>cookie-manipulation</category><category>unauthenticated</category><category>python</category><category>cwe-287</category><category>cwe-290</category></item><item><title>GiveWP Unauthenticated PHP Object Injection via Weak Serialized-Data Regex Check (CVE-2025-22777)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-22777-givewp-php-object-injection/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-22777-givewp-php-object-injection/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-22777. Status: PoC. Affects: GiveWP – Donation Plugin and Fundraising Platform (WordPress plugin, 100,000+ active installs). Tags: givewp, wordpress, wordpress-plugin, php-object-injection, deserialization, unserialize, gadget-chain, cwe-502, php, unauthenticated.</description><category>web</category><category>Critical</category><category>givewp</category><category>wordpress</category><category>wordpress-plugin</category><category>php-object-injection</category><category>deserialization</category><category>unserialize</category><category>gadget-chain</category><category>cwe-502</category><category>php</category><category>unauthenticated</category></item><item><title>Frontend Admin by DynamiApps — Unauthenticated Administrator Account Creation (CVE-2025-13342)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13342-frontend-admin-unauth-admin-creation/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13342-frontend-admin-unauth-admin-creation/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-13342. Status: Weaponized. Affects: Frontend Admin by DynamiApps (WordPress plugin built on Advanced Custom Fields / ACF frontend forms). Tags: wordpress, wordpress-plugin, frontend-admin, dynamiapps, acf, advanced-custom-fields, broken-access-control, cwe-284, privilege-escalation, unauthenticated, admin-takeover, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wordpress-plugin</category><category>frontend-admin</category><category>dynamiapps</category><category>acf</category><category>advanced-custom-fields</category><category>broken-access-control</category><category>cwe-284</category><category>privilege-escalation</category><category>unauthenticated</category><category>admin-takeover</category><category>python</category></item><item><title>FreePBX Unauthenticated SQL Injection to RCE (CVE-2025-57819)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-57819-freepbx-sqli-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-57819-freepbx-sqli-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-57819. Status: Weaponized. Affects: Sangoma FreePBX administrator web UI (admin/ajax.php, endpoint module). Tags: freepbx, sangoma, sqli, unauthenticated, ajax-php, cron-jobs, reverse-shell, voip, asterisk, cwe-89.</description><category>web</category><category>Critical</category><category>freepbx</category><category>sangoma</category><category>sqli</category><category>unauthenticated</category><category>ajax-php</category><category>cron-jobs</category><category>reverse-shell</category><category>voip</category><category>asterisk</category><category>cwe-89</category></item></channel></rss>