<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Webshell — PoC Archive</title><link>https://poc.intelseclab.com/tags/webshell/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 16 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/webshell/index.xml" rel="self" type="application/rss+xml"/><item><title>Citrix NetScaler ADC/Gateway -- Pre-Auth SAML PrefixList Heap Overflow to RCE (CVE-2026-8452)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-16_cve-2026-8452-citrix-netscaler-saml-preauth-rce/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-16_cve-2026-8452-citrix-netscaler-saml-preauth-rce/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2026-8452. Status: Patched. Affects: Citrix NetScaler ADC and NetScaler Gateway. Tags: citrix, netscaler, adc, gateway, saml, heap-overflow, preauth, rce, shellcode, webshell, freebsd, xml-signature, c14n, CVE-2026-8452.</description><category>network</category><category>Critical</category><category>citrix</category><category>netscaler</category><category>adc</category><category>gateway</category><category>saml</category><category>heap-overflow</category><category>preauth</category><category>rce</category><category>shellcode</category><category>webshell</category><category>freebsd</category><category>xml-signature</category><category>c14n</category><category>CVE-2026-8452</category></item><item><title>Joomla Balbooa Forms Unauthenticated Arbitrary File Upload → RCE (CVE-2026-56291)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-56291-joomla-balbooa-forms-file-upload-rce/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-56291-joomla-balbooa-forms-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-56291. Status: Weaponized. Affects: Balbooa Forms (com_baforms) — third-party Joomla! extension by balbooa.com. Tags: joomla, balbooa-forms, file-upload, webshell, unauthenticated, rce, kev, actively-exploited, cwe-434.</description><category>web</category><category>Critical</category><category>joomla</category><category>balbooa-forms</category><category>file-upload</category><category>webshell</category><category>unauthenticated</category><category>rce</category><category>kev</category><category>actively-exploited</category><category>cwe-434</category></item><item><title>Adobe ColdFusion RDS Path Traversal → Arbitrary File Read/Write → RCE (CVE-2026-48282)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-48282-coldfusion-rds-path-traversal-rce/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-48282-coldfusion-rds-path-traversal-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-48282 (Adobe APSB26-68). Status: Weaponized — arbitrary file read/write, directory browsing, webshell deployment, and command execution all confirmed. Affects: Adobe ColdFusion — Remote Development Service (RDS), /CFIDE/main/ide.cfm. Tags: coldfusion, adobe, rds, path-traversal, cwe-22, unauthenticated, remote, webshell, kev, actively-exploited.</description><category>web</category><category>Critical</category><category>coldfusion</category><category>adobe</category><category>rds</category><category>path-traversal</category><category>cwe-22</category><category>unauthenticated</category><category>remote</category><category>webshell</category><category>kev</category><category>actively-exploited</category></item><item><title>WordPress WPAMS Plugin Arbitrary File Upload to RCE (CVE-2025-39401)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-39401-wpams-arbitrary-file-upload-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-39401-wpams-arbitrary-file-upload-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-39401. Status: Weaponized. Affects: WPAMS (WordPress Apartment/Property Management System) plugin by mojoomla. Tags: wordpress, wpams, mojoomla, arbitrary-file-upload, webshell, rce, unauthenticated, python, multithreaded, cwe-434.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wpams</category><category>mojoomla</category><category>arbitrary-file-upload</category><category>webshell</category><category>rce</category><category>unauthenticated</category><category>python</category><category>multithreaded</category><category>cwe-434</category></item><item><title>Webkul Medical Prescription Attachment for WooCommerce — Unrestricted File Upload to Web Shell (CVE-2025-29009)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-29009-woocommerce-medical-prescription-file-upload/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-29009-woocommerce-medical-prescription-file-upload/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-29009. Status: Weaponized. Affects: Webkul "Medical Prescription Attachment Plugin for WooCommerce" (WordPress plugin). Tags: wordpress, woocommerce, medical-prescription-attachment, unrestricted-file-upload, webshell, cwe-434, unauthenticated, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>woocommerce</category><category>medical-prescription-attachment</category><category>unrestricted-file-upload</category><category>webshell</category><category>cwe-434</category><category>unauthenticated</category><category>python</category></item><item><title>WavePlayer Unauthenticated Arbitrary File Upload to RCE (CVE-2025-12057)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-12057-waveplayer-webshell-upload/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-12057-waveplayer-webshell-upload/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-12057. Status: Weaponized. Affects: WavePlayer (WordPress plugin). Tags: wordpress, waveplayer, arbitrary-file-upload, unauthenticated, rce, webshell, ajax, nonce, php, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>waveplayer</category><category>arbitrary-file-upload</category><category>unauthenticated</category><category>rce</category><category>webshell</category><category>ajax</category><category>nonce</category><category>php</category><category>python</category></item><item><title>ThinkPHP 5.0.24 File Inclusion Leading to Remote Code Execution (CVE-2025-63888)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-63888-thinkphp-file-inclusion-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-63888-thinkphp-file-inclusion-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-63888. Status: Weaponized. Affects: ThinkPHP (top10.org / TopThink PHP framework). Tags: thinkphp, php, file-inclusion, lfi, rce, log-poisoning, webshell, cwe-98, cwe-22.</description><category>web</category><category>Critical</category><category>thinkphp</category><category>php</category><category>file-inclusion</category><category>lfi</category><category>rce</category><category>log-poisoning</category><category>webshell</category><category>cwe-98</category><category>cwe-22</category></item><item><title>StoreKeeper for WooCommerce Unauthenticated Arbitrary File Upload (CVE-2025-48148)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-48148-storekeeper-woocommerce-webshell-upload/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-48148-storekeeper-woocommerce-webshell-upload/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-48148. Status: Weaponized. Affects: StoreKeeper for WooCommerce (WordPress plugin). Tags: wordpress, woocommerce, storekeeper, arbitrary-file-upload, unauthenticated, webshell, rce, cwe-434, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>woocommerce</category><category>storekeeper</category><category>arbitrary-file-upload</category><category>unauthenticated</category><category>webshell</category><category>rce</category><category>cwe-434</category><category>python</category></item><item><title>KiotViet Sync Unauthenticated Arbitrary File Upload (CVE-2025-12674)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-12674-kiotviet-sync-file-upload/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-12674-kiotviet-sync-file-upload/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-12674. Status: Weaponized. Affects: KiotViet Sync (WordPress plugin). Tags: wordpress, kiotviet-sync, arbitrary-file-upload, unauthenticated, rce, rest-api, webshell, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>kiotviet-sync</category><category>arbitrary-file-upload</category><category>unauthenticated</category><category>rce</category><category>rest-api</category><category>webshell</category><category>python</category></item><item><title>Flozen WordPress Theme Unauthenticated Arbitrary File Upload (CVE-2025-49071)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-49071-flozen-theme-arbitrary-file-upload/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-49071-flozen-theme-arbitrary-file-upload/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-49071. Status: Weaponized. Affects: Flozen Theme for WordPress. Tags: wordpress, flozen-theme, arbitrary-file-upload, unauthenticated, webshell, zip-upload, rce, cwe-434, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>flozen-theme</category><category>arbitrary-file-upload</category><category>unauthenticated</category><category>webshell</category><category>zip-upload</category><category>rce</category><category>cwe-434</category><category>python</category></item><item><title>Cibeles AI `actualizador_git.php` Unauthenticated Arbitrary File Upload / RCE (CVE-2025-13595)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13595-cibeles-ai-file-upload-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13595-cibeles-ai-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-13595. Status: Weaponized. Affects: Cibeles AI (WordPress plugin). Tags: wordpress, cibeles-ai, unauthenticated-file-upload, github-mirror-abuse, webshell, python, cwe-434, cwe-306.</description><category>web</category><category>Critical</category><category>wordpress</category><category>cibeles-ai</category><category>unauthenticated-file-upload</category><category>github-mirror-abuse</category><category>webshell</category><category>python</category><category>cwe-434</category><category>cwe-306</category></item><item><title>AI Feeds `actualizador_git.php` Unauthenticated Arbitrary File Upload / RCE (CVE-2025-13597)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13597-ai-feeds-file-upload-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13597-ai-feeds-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-13597. Status: Weaponized. Affects: AI Feeds (WordPress plugin). Tags: wordpress, ai-feeds, unauthenticated-file-upload, github-mirror-abuse, webshell, python, cwe-434, cwe-306.</description><category>web</category><category>Critical</category><category>wordpress</category><category>ai-feeds</category><category>unauthenticated-file-upload</category><category>github-mirror-abuse</category><category>webshell</category><category>python</category><category>cwe-434</category><category>cwe-306</category></item><item><title>WordPress Ninja Forms Plugin Unauthenticated File Upload — CVE-2026-0740</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0740-ninja-forms-file-upload/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0740-ninja-forms-file-upload/</guid><description>High severity — web · CVE-2026-0740. Status: PoC. Affects: WordPress "Ninja Forms" plugin — file upload field/module. Tags: wordpress, ninja-forms, file-upload, webshell, admin-ajax, plugin-vulnerability, cwe-434.</description><category>web</category><category>High</category><category>wordpress</category><category>ninja-forms</category><category>file-upload</category><category>webshell</category><category>admin-ajax</category><category>plugin-vulnerability</category><category>cwe-434</category></item><item><title>WordPress "Drag and Drop File Upload for Contact Form 7" Unauthenticated RCE — CVE-2026-5364</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5364-cf7-dnd-upload-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5364-cf7-dnd-upload-rce/</guid><description>High severity (CVSS 8.1) — web · CVE-2026-5364. Status: PoC. Affects: WordPress plugin "Drag and Drop File Upload for Contact Form 7" (drag-and-drop-file-upload-for-contact-form-7). Tags: wordpress, contact-form-7, file-upload, webshell, rce, sanitize-file-name-bypass, admin-ajax, cwe-434.</description><category>web</category><category>High</category><category>wordpress</category><category>contact-form-7</category><category>file-upload</category><category>webshell</category><category>rce</category><category>sanitize-file-name-bypass</category><category>admin-ajax</category><category>cwe-434</category></item><item><title>WebStack WordPress Theme Unauthenticated Arbitrary File Upload RCE — CVE-2026-1555</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1555-webstack-wp-file-upload-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1555-webstack-wp-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-1555. Status: Weaponized. Affects: WebStack theme for WordPress. Tags: wordpress, webstack-theme, arbitrary-file-upload, unauthenticated-rce, webshell, ajax, cwe-434.</description><category>web</category><category>Critical</category><category>wordpress</category><category>webstack-theme</category><category>arbitrary-file-upload</category><category>unauthenticated-rce</category><category>webshell</category><category>ajax</category><category>cwe-434</category></item><item><title>Visitor Management System 1.0 — Unrestricted File Upload to RCE (CVE-2026-37748)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-37748-visitor-management-system-file-upload-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-37748-visitor-management-system-file-upload-rce/</guid><description>High severity (CVSS 7.2) — web · CVE-2026-37748. Status: PoC. Affects: Visitor Management System (sanjay1313) 1.0. Tags: php, unrestricted-file-upload, rce, webshell, admin-authenticated, cwe-434.</description><category>web</category><category>High</category><category>php</category><category>unrestricted-file-upload</category><category>rce</category><category>webshell</category><category>admin-authenticated</category><category>cwe-434</category></item><item><title>User Registration Advanced Fields WordPress Plugin Unauthenticated Arbitrary File Upload (CVE-2026-4882)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-4882-user-registration-advanced-fields-file-upload/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-4882-user-registration-advanced-fields-file-upload/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-4882. Status: PoC. Affects: User Registration Advanced Fields plugin for WordPress. Tags: wordpress, wordpress-plugin, file-upload, webshell, unauthenticated, rce, nonce-leak.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wordpress-plugin</category><category>file-upload</category><category>webshell</category><category>unauthenticated</category><category>rce</category><category>nonce-leak</category></item><item><title>Piotnet Addons for Elementor Pro Unauthenticated Arbitrary File Upload RCE (CVE-2026-4885)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-4885-piotnet-elementor-file-upload/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-4885-piotnet-elementor-file-upload/</guid><description>Critical severity — web · CVE-2026-4885. Status: PoC. Affects: Piotnet Addons for Elementor Pro (WordPress plugin). Tags: wordpress, wordpress-plugin, elementor, piotnet, file-upload, webshell, unauthenticated, rce, mass-exploit.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wordpress-plugin</category><category>elementor</category><category>piotnet</category><category>file-upload</category><category>webshell</category><category>unauthenticated</category><category>rce</category><category>mass-exploit</category></item><item><title>midi-Synth WordPress Plugin Arbitrary File Upload (CVE-2026-1306)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1306-wp-midi-synth-file-upload/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1306-wp-midi-synth-file-upload/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-1306. Status: Weaponized. Affects: midi-Synth WordPress plugin. Tags: wordpress, wp-plugin, file-upload, cwe-434, webshell, ajax, mass-scanning.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wp-plugin</category><category>file-upload</category><category>cwe-434</category><category>webshell</category><category>ajax</category><category>mass-scanning</category></item><item><title>Mercator Configuration SSRF Chained to Internal Redis RCE (CVE-2026-49345)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-49345-mercator-ssrf-redis-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-49345-mercator-ssrf-redis-rce/</guid><description>Critical severity — web · CVE-2026-49345. Status: PoC. Affects: Mercator (sourcentis/mercator vulnerability-management web app), ConfigurationController::testProvider. Tags: ssrf, redis, rce, gopher, webshell, internal-network-pivot, php, mercator.</description><category>web</category><category>Critical</category><category>ssrf</category><category>redis</category><category>rce</category><category>gopher</category><category>webshell</category><category>internal-network-pivot</category><category>php</category><category>mercator</category></item><item><title>KnowledgeDeliver ASP.NET ViewState Deserialization RCE via Hardcoded Machine Keys — CVE-2026-5426</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5426-knowledgedeliver-viewstate-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5426-knowledgedeliver-viewstate-rce/</guid><description>Critical severity — web · CVE-2026-5426. Status: PoC. Affects: KnowledgeDeliver (ASP.NET Web Forms application). Tags: aspnet, viewstate, deserialization, rce, hardcoded-keys, machinekey, knowledgedeliver, webshell, python.</description><category>web</category><category>Critical</category><category>aspnet</category><category>viewstate</category><category>deserialization</category><category>rce</category><category>hardcoded-keys</category><category>machinekey</category><category>knowledgedeliver</category><category>webshell</category><category>python</category></item><item><title>Kanboard — Missing Access Control on Plugin Installation Leads to Administrative RCE via Webshell Plugin (CVE-2026-25924)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25924-kanboard-plugin-webshell/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25924-kanboard-plugin-webshell/</guid><description>High severity (CVSS 8.4) — web · CVE-2026-25924 / GHSA-grch-p7vf-vc4f. Status: Weaponized. Affects: Kanboard (project management application). Tags: kanboard, rce, webshell, plugin-installation, incorrect-authorization, cwe-863, cwe-94, admin-bypass, backdoor.</description><category>web</category><category>High</category><category>kanboard</category><category>rce</category><category>webshell</category><category>plugin-installation</category><category>incorrect-authorization</category><category>cwe-863</category><category>cwe-94</category><category>admin-bypass</category><category>backdoor</category></item><item><title>FUXA SCADA/HMI — Unauthenticated Path Traversal to Remote Code Execution (CVE-2026-25895)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25895-fuxa-path-traversal-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25895-fuxa-path-traversal-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-25895. Status: Weaponized. Affects: FUXA (Node.js-based SCADA/HMI platform), frangoteam. Tags: fuxa, scada, ics, path-traversal, arbitrary-file-write, rce, unauthenticated, cwe-22, cron-persistence, webshell.</description><category>web</category><category>Critical</category><category>fuxa</category><category>scada</category><category>ics</category><category>path-traversal</category><category>arbitrary-file-write</category><category>rce</category><category>unauthenticated</category><category>cwe-22</category><category>cron-persistence</category><category>webshell</category></item><item><title>FreeScout Zero-Click RCE via Email Attachment Filename Sanitization Bypass ("Mail2Shell") — CVE-2026-28289</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-28289-freescout-mail-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-28289-freescout-mail-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-28289. Status: Weaponized. Affects: FreeScout helpdesk/mailbox application. Tags: freescout, rce, zero-click, email-attachment, htaccess-bypass, unicode-bypass, webshell, helpdesk.</description><category>web</category><category>Critical</category><category>freescout</category><category>rce</category><category>zero-click</category><category>email-attachment</category><category>htaccess-bypass</category><category>unicode-bypass</category><category>webshell</category><category>helpdesk</category></item><item><title>EspoCRM Authenticated RCE via Formula ACL Bypass + Attachment Path Traversal — CVE-2026-33656</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33656-espocrm-formula-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33656-espocrm-formula-rce/</guid><description>Critical severity — web · CVE-2026-33656. Status: Weaponized. Affects: EspoCRM &lt;= 9.3.3. Tags: espocrm, rce, path-traversal, webshell, htaccess-poisoning, formula-engine, authenticated, crm.</description><category>web</category><category>Critical</category><category>espocrm</category><category>rce</category><category>path-traversal</category><category>webshell</category><category>htaccess-poisoning</category><category>formula-engine</category><category>authenticated</category><category>crm</category></item><item><title>Discuz! X5.0 Race Condition + CAPTCHA-Solving Pre-Auth to RCE Chain (CVE-2026-49952)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-49952-discuz-race-condition-captcha-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-49952-discuz-race-condition-captcha-rce/</guid><description>Critical severity — web · CVE-2026-49952 (chain also referenced as KIS-2026-09, KIS-2026-10, KIS-2026-11). Status: PoC. Affects: Discuz! X5.0 (PHP-based forum/CMS software). Tags: discuz, php, forum, race-condition, captcha-bypass, ocr, account-takeover, lfi, webshell, rce, pre-auth.</description><category>web</category><category>Critical</category><category>discuz</category><category>php</category><category>forum</category><category>race-condition</category><category>captcha-bypass</category><category>ocr</category><category>account-takeover</category><category>lfi</category><category>webshell</category><category>rce</category><category>pre-auth</category></item><item><title>Control Web Panel Pre-Auth Blind SQL Injection to RCE — CVE-2026-57517</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-57517-cwp-blind-sqli-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-57517-cwp-blind-sqli-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-57517. Status: PoC. Affects: Control Web Panel (CWP) — user panel (port 2083). Tags: control-web-panel, cwp, sqli, into-dumpfile, webshell, unauth-rce, hosting-panel.</description><category>web</category><category>Critical</category><category>control-web-panel</category><category>cwp</category><category>sqli</category><category>into-dumpfile</category><category>webshell</category><category>unauth-rce</category><category>hosting-panel</category></item><item><title>Chamilo LMS Authenticated RCE via Unrestricted File Upload — CVE-2026-29041</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-29041-chamilo-lms-file-upload-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-29041-chamilo-lms-file-upload-rce/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-29041. Status: Weaponized. Affects: Chamilo LMS. Tags: chamilo, lms, file-upload, rce, webshell, cwe-434, mime-bypass, authenticated.</description><category>web</category><category>High</category><category>chamilo</category><category>lms</category><category>file-upload</category><category>rce</category><category>webshell</category><category>cwe-434</category><category>mime-bypass</category><category>authenticated</category></item><item><title>Bludit CMS API Unrestricted File Upload to RCE (CVE-2026-25099)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25099-bludit-webshell-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25099-bludit-webshell-rce/</guid><description>High severity — web · CVE-2026-25099. Status: Weaponized. Affects: Bludit CMS (/api/files/&lt;page-key> endpoint). Tags: bludit, cms, file-upload, webshell, rce, php, api-token, cwe-434, authenticated.</description><category>web</category><category>High</category><category>bludit</category><category>cms</category><category>file-upload</category><category>webshell</category><category>rce</category><category>php</category><category>api-token</category><category>cwe-434</category><category>authenticated</category></item><item><title>Unauthenticated RCE in Joomla Content Editor (JCE) Profile Import (CVE-2026-48907)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-01_cve-2026-48907-joomla-jce-unauth-rce/</link><pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-01_cve-2026-48907-joomla-jce-unauth-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-48907. Status: Weaponized. Affects: Joomla Content Editor (JCE) extension by Widget Factory. Tags: RCE, unauthenticated, Joomla, JCE, CMS, access-control, webshell, php-webshell, file-upload, CISA-KEV, active-exploitation.</description><category>web</category><category>Critical</category><category>RCE</category><category>unauthenticated</category><category>Joomla</category><category>JCE</category><category>CMS</category><category>access-control</category><category>webshell</category><category>php-webshell</category><category>file-upload</category><category>CISA-KEV</category><category>active-exploitation</category></item><item><title>Cisco Unified CM WebDialer SSRF to Arbitrary File Write / RCE (CVE-2026-20230)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-01_cve-2026-20230-cisco-ucm-webdialer-ssrf-rce/</link><pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-01_cve-2026-20230-cisco-ucm-webdialer-ssrf-rce/</guid><description>Critical severity (CVSS 8.6) — network · CVE-2026-20230. Status: Weaponized. Affects: Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (SME). Tags: SSRF, RCE, Cisco, Unified-Communications-Manager, WebDialer, file-write, webshell, jsp-webshell, CISA-KEV, active-exploitation.</description><category>network</category><category>Critical</category><category>SSRF</category><category>RCE</category><category>Cisco</category><category>Unified-Communications-Manager</category><category>WebDialer</category><category>file-write</category><category>webshell</category><category>jsp-webshell</category><category>CISA-KEV</category><category>active-exploitation</category></item></channel></rss>