We don't just detect these vulnerabilities. We prove they're exploitable on your app with safe, non-destructive proof-of-concept payloads.
Detects Apache Tomcat servers whose HTTP/2 connector mixes headers between requests on the same connection. The compression scheme HTTP/2 uses for headers keeps a shared table that both sides have to agree on for the whole connection. On these versions Tomcat checks each header for illegal characters from inside that shared decoder, and when it finds one it stops reading the rest of the request's headers but keeps the connection open. Everything after the rejected header is therefore never recorded, so the two sides no longer agree on the table, and every later request on that connection resolves indexed headers to the wrong values. We show that with two connections. On the first, a marker header is stored and then re-used by index on a second request, which answers. On the second connection that same second request goes unanswered, because one extra header with a trailing space was placed ahead of the marker. Upgrade Tomcat to 11.0.26, 10.1.60 or 9.0.122. Until you upgrade, turn HTTP/2 off on every connector.
Added 7d ago
Detects services that clone attacker-influenced repositories with a git build older than the July 2025 fix, where a plain recursive clone runs attacker code. Git strips a trailing carriage return when it reads a config value but does not quote one when it writes it, so a submodule whose recorded path ends in a carriage return gets written into the submodule config and read back as a shorter, different path. A symlink committed at that shorter path redirects the submodule checkout, and because the redirect comes from config rather than the working tree, git writes through it without the usual symlink protections. Point it at the submodule hooks directory, track an executable post-checkout file in the submodule, and git runs that file to finish the very checkout that created it. We prove it by reading our own marker, a product only the target could compute, and the uid of the clone process out of the clone log. Repository importers, CI and build runners, mirrors and docs pipelines are the exposed surface. In the CISA known-exploited catalogue since August 2025. Upgrade git to 2.50.1, 2.49.1, 2.48.2, 2.47.3, 2.46.4, 2.45.4, 2.44.4 or 2.43.7.
Added 8d ago
Detects vm2 sandboxes that an attacker can break out of through WebAssembly.compileStreaming or WebAssembly.instantiateStreaming, yielding code execution on the host. On Node.js 26 those two calls hand the sandbox a Promise whose prototype belongs to the host, so vm2's own then/catch overrides and its species hardening never run on it. Guest code plants its own Symbol.species on that Promise and calls finally(), which delivers the raw host-realm error straight into the sandbox; the error's Function constructor then compiles code in the host realm and yields the host process object. We prove it by running a shell command on the host and reading back a product only the target could have computed. No unsafe configuration is needed: a default new VM() with no host objects exposed is enough, so anyone who can submit JavaScript owns the machine. This is a bypass of the earlier WebAssembly JSPI fix. vm2 3.10.1 through 3.11.6 affected. Upgrade to vm2 3.11.7, or migrate off the deprecated vm2 to isolated-vm.
Added 10d ago
Detects FreePBX phone systems whose database can be read and rewritten by anyone on the internet, with no login. FreePBX 15, 16 and 17 running the Endpoint Manager module below 15.0.66 / 16.0.89 / 17.0.3 accept a namespaced class name in the module parameter of /admin/ajax.php. The framework autoloader turns that into a file path and runs the module's provisioning handler before the session check happens, and that handler pastes the brand parameter straight into a SQL query. We prove it without writing anything: we ask the target's own database to multiply two random numbers and read the product back out of its error message. The same request accepts extra statements, which is how attackers added themselves as PBX administrators and scheduled commands that run as root. CISA lists this as actively exploited since August 2025. Update Endpoint Manager to 15.0.66, 16.0.89 or 17.0.3 or later, update the framework, and keep /admin off the public internet.
Added 11d ago
Detects WordPress sites where an unauthenticated visitor can make the page-template loader execute a PHP file from outside the theme. WordPress 4.7.0 through 7.1.1 build a template candidate from the requested page slug without validating it, and the only sanitiser applied to that slug deliberately preserves percent-escaped characters, so a double-encoded traversal survives and is decoded straight back into a directory path. If the active theme owns a top-level directory whose name starts with page- (page-templates in Twenty Twelve, Twenty Fourteen, Neve, Hestia and Sydney) the traversal climbs out of the theme and any readable .php file on the server is included. The verifier proves it by making the site return the output of its own wp-links-opml.php from a normal page URL, with a benign slug as the control. Attackers are already chaining the same primitive into PEAR pearcmd.php to write attacker-controlled PHP to disk, which is remote code execution. CVSS 9.2, CISA KEV, exploited in the wild within hours of the patch. Upgrade to WordPress 7.1.2, or the patched release on your branch (backported as far as 4.7.37).
Added 12d ago
Detects CakePHP apps whose queries are SQL-injectable through the framework's FunctionsBuilder cast/extract/datePart/dateAdd helpers. In cakephp/database before 5.2.14 / 5.3.7 / 5.1.9 / 4.6.5 / 4.5.12 the data-type, date-part and unit arguments were spliced into the generated SQL as unescaped structural fragments, so an application that forwards request data into any of them is injectable. We prove execution by sending a value like `text)) UNION SELECT 1337*31337-- ` that breaks out of the CAST(...) call and reading the computed product back from the response — data only the database could produce. From there an attacker reads or rewrites the entire database with the connection's privileges. Update cakephp/database to a patched release, which rejects any non-alphanumeric type argument.
Added 16d ago
Detects Snipe-IT installations at 8.6.3 or earlier, where any authenticated user holding a pending checkout acceptance can read arbitrary server-readable files and drive arbitrary server-side HTTP requests. The acceptance note is rendered through Blade's {{ $note }}, which escapes HTML metacharacters but not markdown ones, so image syntax such as  survives into Laravel's mail::table component, is expanded by CommonMark into a real <img src> tag, and is then resolved by eduardokum/laravel-mail-auto-embed via file_get_contents() for local paths or curl for URLs. The fetched bytes are attached to the outbound notification, which the attacker receives by ticking 'send me a copy'. A default install leaks APP_KEY, the key behind Laravel's signed URLs and encrypted session cookies, so the impact is identity forgery rather than disclosure alone. Auto-embed needs no operator opt-in: no shipped .env sets the enable flag. Exploitation is blind, so proof comes from an out-of-band canary callback. Upgrade to Snipe-IT 8.7.0 or later.
Added 16d ago
Detects Gravity Forms installations vulnerable to unauthenticated arbitrary file upload leading to remote code execution. In all versions up to and including 3.1.0.4, a mismatch between the field-validation pipeline and the file-persistence pipeline lets a File Upload field whose Visibility is set to Hidden bypass extension validation. A file that was rejected during validation keeps its intact upload state and is passed to upload_file() with no re-validation, so an unauthenticated attacker can POST a .php web shell to the async upload endpoint (admin-ajax.php action=gf_upload_files) on any public form containing a Hidden File Upload field. The verifier uploads a PHP payload that prints a per-run canary computed from two constants, then fetches the persisted file and confirms the arithmetic result came back, proving server-side code execution rather than mere file persistence. CVSS 9.8. Upgrade to Gravity Forms 3.1.0.5 or later.
Added 19d ago
Detects vm2 sandboxes vulnerable to a promise-rejection escape that yields host remote code execution. When a host-realm promise exposed to the sandbox rejects, vm2 is supposed to rebuild the error and drop every property that references a host object. The gate that triggers the rebuild only recognises a direct call to the host promise then or catch method, so registering the rejection handler through Function.prototype.call or apply skips it entirely. The raw host error then reaches sandbox code intact, and any host object hanging off it becomes a live handle into the host process, which leads straight to arbitrary command execution. This is an incomplete fix for GHSA-m283-3h24-438v. vm2 3.11.6 is affected. Upgrade to vm2 3.11.7, or migrate off the deprecated vm2 to isolated-vm.
Added 14d ago
Detects vm2 sandboxes vulnerable to a Promise.prototype.finally() escape that yields host remote code execution. vm2 installs its Promise then/catch wrappers by direct property assignment; on Node.js 26 / V8 14.6 that path leaves the PromiseThenLookupChain protector valid, so finally() takes a fast path to the original native then and bypasses vm2's resetPromiseSpecies hardening. An attacker-controlled constructor Symbol.species then drives a native promise reaction that delivers a raw host-realm error whose constructor.constructor is the host Function constructor, reaching the host process and arbitrary code execution. Anyone who can submit JavaScript to the sandbox owns the host. vm2 3.10.2 through 3.11.6 affected. Upgrade to vm2 3.11.7, or migrate off the deprecated vm2 to isolated-vm.
Added 20d ago
Detects Winter CMS installations vulnerable to authenticated backend privilege escalation in winter/wn-backend-module <1.0.477, 1.1.0–1.1.11, and 1.2.0–1.2.11. Winter Storm's FormController save pipeline routes posted attributes through setModelAttributes(), which performs direct property assignment ($model->$attr = $value) and therefore bypasses Eloquent's $guarded array on the Backend User model. Because the self-redirect in the Users controller only guards the GET path of update(), any authenticated backend user can POST onSave to /backend/backend/users/update/{own-id} with User[permissions][...]=1 — the 'update' form context exposes the permissions field and grants the attacker arbitrary backend permissions they did not previously hold. CVSS 9.9. Patched in 1.0.477/1.1.12/1.2.12 by a beforeSave() hook on the User model that throws AuthorizationException for self-edits of role_id/is_superuser/permissions, edits to other users without backend.manage_users, and any non-superuser save touching a superuser record.
Added 5mo ago
Detects n8n instances vulnerable to stored XSS via MCP OAuth client registration. An unauthenticated attacker can register an MCP OAuth client whose crafted client_name bypasses the sanitizeHtml() href filter — the URL-validation regex used the multiline flag (/^https?:\/\//gm), so payloads like 'javascript:alert(1);//\nhttps://x.com' slip through and become a clickable javascript: link in the OAuth consent / revocation toast. A single click in an authenticated victim's session executes arbitrary JavaScript, enabling credential theft, workflow manipulation, and privilege escalation. Versions <1.123.32, 2.17.0-2.17.3, and 2.18.0 affected. Update to 1.123.32, 2.17.4, or 2.18.1.
Added 5mo ago
Detects Parse Server instances vulnerable to JWT audience validation bypass in the Google, Apple, and Facebook authentication adapters. When clientId (Google/Apple) or appIds (Facebook) is not configured, the adapter passes undefined as the audience to jwt.verify, which silently skips audience validation. Facebook Limited Login is vulnerable regardless of configuration because the adapter passed clientId — never present in the facebook options struct — instead of appIds. An unauthenticated attacker who possesses a validly signed Google/Apple/Facebook JWT issued for any app (including their own) can authenticate as any user on the target Parse Server by presenting that token as authData. Affects all versions before 8.6.10 and 9.0.0 through 9.5.0-alpha.10. Update to 8.6.10 or 9.5.0-alpha.11 or later.
Added 5mo ago
Detects Prometheus instances in versions 2.48.0 through 3.5.2 and 3.6.0 through 3.11.2 where the Azure AD remote_write OAuth client_secret field in storage/remote/azuread was declared as a plain Go string instead of the config_util.Secret alias. Prometheus only redacts fields whose declared type is Secret when serializing config to /api/v1/status/config, so the configured Azure AD client_secret is rendered in plaintext alongside the client_id and tenant_id. Any unauthenticated user who can reach Prometheus's HTTP API reads the credential in a single GET request and can mint OAuth tokens against the Azure AD app registration. Patched in 3.5.3 (LTS) and 3.11.3.
Added 5mo ago
Detects the CMP Coming Soon & Maintenance Plugin (NiteoThemes) for WordPress in versions up to and including 4.1.16 where the cmp_theme_update_install AJAX handler accepts a fully attacker-controlled file URL, downloads the ZIP from any host, and extracts it into a web-accessible directory without rejecting PHP entries. The capability check is publish_pages instead of manage_options. An authenticated user with a valid plugin nonce (in practice an Administrator) can drop a PHP webshell into wp-content/plugins/cmp-premium-themes/ and execute arbitrary code. The fix in 4.1.17 raises the capability check, forces the download URL through a hostname allowlist, and rejects ZIPs containing .php, .phtml, or .phar entries.
Added 5mo ago
Detects WordPress instances running the Login as User plugin (one-click-login-as-user) version 1.0.3 or earlier, where the handle_return_to_admin() function in includes/class-login-handler.php trusts a client-controlled oclaup_original_admin cookie and re-authenticates the browser as that user without verifying the cookie was minted during a legitimate admin → user switch. Any authenticated Subscriber can mint the required nonce, set the cookie to user ID 1 (default admin), and call admin-post.php?action=oclaup_return_to_admin to gain full administrator access. The plugin was closed on WordPress.org with no patched release — uninstall is the only mitigation.
Added 5mo ago
Detects Apache APISIX versions 2.12.0 through 3.15.0 where the forward-auth plugin leaves client-supplied values intact for any header in upstream_headers that is missing from the auth response. When a route is fronted by forward-auth with identity headers (X-User-ID, X-User-Email, X-User-Role, X-Forwarded-User), an unauthenticated attacker can spoof the user identity by attaching the header to their request — bypassing authentication on any upstream that trusts the gateway-provided identity. The fix in 3.16.0 unconditionally calls set_header() so a nil value clears any client-injected header.
Added 5mo ago
Detects the WebStack WordPress theme through version 1.2024 where the io_img_upload() function in inc/ajax.php is registered on wp_ajax_nopriv (no authentication) and declares an allowed extension list ('jpg','png','jpeg') but never enforces it. An unauthenticated attacker can POST any file — including PHP — to admin-ajax.php with action=img_upload and the file is saved into the WordPress uploads directory with its original extension, enabling remote code execution. The vendor is unmaintained and no patch exists; remove the theme or block the endpoint.
Added 5mo ago
Detects Apache Tomcat versions 9.0.83–9.0.115, 10.1.0-M7–10.1.52, and 11.0.0-M1–11.0.18 where the FFM (Foreign Function & Memory) OpenSSL integration fails to set an X509 verification error when the OCSP responder returns TRY_LATER. On servers configured with CLIENT_CERT mutual TLS authentication and OCSP revocation checking with soft-fail disabled, an attacker with a revoked or unverifiable client certificate can bypass the revocation check and authenticate as if their certificate were valid. The fix in 9.0.116/10.1.53/11.0.20 adds X509_STORE_CTX_set_error to correctly reject the connection.
Added 5mo ago
Detects the Ninja Forms File Uploads plugin for WordPress versions up to 3.3.26 where the handle_upload function validates the source file extension but not the destination filename. An unauthenticated attacker can upload a file with a safe extension (e.g., image.jpg) and override the destination filename to a PHP file, creating a webshell that enables full remote code execution. The nf_fu_get_new_nonce AJAX action issues upload nonces without authentication, confirming the upload pipeline is active.
Added 5mo ago
Detects the ProSolution WP Client plugin for WordPress versions up to 1.9.9 where the proSol_fileUploadProcess AJAX handler trusts the client-supplied MIME type via proSol_mimeExt(), which allows all file extensions including .php. The handler is registered on wp_ajax_nopriv (unauthenticated). An attacker can upload a PHP webshell and achieve full remote code execution.
Added 5mo ago
Detects NocoBase instances before version 2.0.28 where the Workflow JavaScript plugin's VM sandbox exposes the host console._stdout object. An authenticated user can traverse the prototype chain (console._stdout.constructor.constructor) to escape the sandbox and execute arbitrary OS commands as root. The verifier confirms the vulnerable version and active workflow plugin endpoint without executing the exploit.
Added 5mo ago
Detects OpenIdentityPlatform OpenAM instances before 16.0.6 vulnerable to pre-authentication remote code execution. The jato.clientSession HTTP parameter is deserialized using raw ObjectInputStream without class filtering — a bypass of the CVE-2021-35464 fix that only protected jato.pageSession. Any unauthenticated attacker can execute arbitrary commands.
Added 5mo ago
Detects Joomla CMS versions 4.0.0 through 5.4.3 and 6.0.0 through 6.0.3 where the REST API config endpoint (/api/index.php/v1/config/application) has no authorization check in ApplicationController::displayList(). Any API-authenticated user — even a low-privilege Registered user — can read the full configuration.php including database credentials (host, username, password), SMTP credentials, and the application secret key. The fix in 5.4.4/6.0.4 adds a core.admin permission check, restricting access to Super Admins only.
Added 5mo ago
Detects File Browser instances before version 2.62.2 where the signup handler copies default user permissions — including Execute=true and the Commands allowlist — to self-registered accounts. The patch for CVE-2026-32760 only stripped the Admin flag but left Execute and Commands intact. An unauthenticated attacker can register, authenticate, and run arbitrary shell commands on the server via the /api/command/ WebSocket endpoint. The fix explicitly sets Execute=false and Commands=[] for self-registered users.
Added 6mo ago
Detects LiteLLM proxy instances 1.81.16-1.83.6 where the API-key lookup query interpolates the caller-supplied Authorization header directly into SQL via an f-string. When initial auth fails, the failure-logging callback runs the same f-stringed query against the raw Bearer token, so any unauthenticated request can inject SQL and read upstream provider keys (OpenAI/Anthropic/Bedrock/Vertex), virtual API keys, the proxy master key, and the runtime configuration. CISA added it to KEV within weeks of disclosure; in-the-wild exploitation began within 36 hours of the patch. The fix in 1.83.7 replaces the f-string with a $1 bind parameter and passes the hashed token as a positional arg.
Added 5mo ago
Detects Kestra instances before version 1.3.7 where the flow/execution search API's label filter parameter is concatenated directly into SQL queries without parameterization. A double-quote in the label key breaks the JSON string literal inside the SQL statement, allowing arbitrary SQL injection. On PostgreSQL deployments (the default), this enables remote code execution via COPY TO PROGRAM. The fix in 1.3.7 replaces string concatenation with jOOQ parameterized bind variables. Also tracked as CVE-2026-38428 by NVD — same advisory (GHSA-365w-2m69-mp9x), same patch.
Added 6mo ago
Detects Sonarr instances before version 4.0.16.2942 where the ASP.NET ForwardedHeadersMiddleware trusts X-Forwarded-For from any source. When 'Disabled for Local Addresses' auth is configured, an attacker spoofs the header with a private IP (e.g. 192.168.1.1) to bypass login entirely. The /initialize.json endpoint then exposes the full API key, granting complete control over downloads, media libraries, and settings.
Added 6mo ago
Detects Dgraph instances before v25.3.1 / v24.1.6 where the restoreTenant admin GraphQL mutation is missing from the authorization middleware configuration. An unauthenticated attacker can overwrite the entire database from a malicious backup, read server files via file:// URIs, or reach internal services via SSRF. The fix adds restoreTenant to the Guardian-of-the-Galaxy middleware map.
Added 6mo ago
Detects WordPress instances running W3 Total Cache plugin version 2.9.3 or earlier, where the output buffering pipeline is bypassed when the User-Agent header contains 'W3 Total Cache'. This causes raw mfunc/mclude HTML comments — including the W3TC_DYNAMIC_SECURITY token — to appear in the page source. That token is the only thing protecting a feature that passes PHP code to eval(), enabling unauthenticated remote code execution when chained with mfunc injection.
Added 6mo ago
Detects WordPress instances running the Webmention plugin version 5.6.2 or earlier, where the MF2::parse_authorpage() function uses wp_remote_get() instead of wp_safe_remote_get() when fetching author page URLs during Webmention processing. An unauthenticated attacker can make the server fetch internal URLs (cloud metadata, localhost services, internal APIs) by sending a crafted Webmention. The fix in 5.7.0 switches to wp_safe_remote_get() which blocks internal/private IP requests.
Added 6mo ago
Detects pyLoad instances before version 0.5.0b3.dev97 where the ClickNLoad localhost restriction can be bypassed by forging the HTTP Host header to 127.0.0.1:9666. This allows unauthenticated remote access to download injection, file write, and JavaScript execution endpoints. The fix replaces the string-based Host header check with proper is_loopback_request() validation.
Added 6mo ago
Detects WordPress instances running the Debugger & Troubleshooter plugin version 1.3.2 or earlier, where the User Role Simulator feature accepts a raw user ID from the wp_debug_troubleshoot_simulate_user cookie without any cryptographic validation. An unauthenticated attacker sets this cookie to 1 (the default admin account) to gain full administrator access. The fix in 1.4.0 replaces the raw ID with a cryptographically signed token that requires database-backed validation.
Added 6mo ago
Detects FastGPT instances before version 4.14.9.5 where the HTTP tools testing endpoint (/api/core/app/httpTools/runTool) accepts requests without authentication. This endpoint acts as a full HTTP proxy — an attacker can supply any URL and the server will fetch it, enabling access to cloud metadata endpoints, internal services, and private network resources. The fix in 4.14.9.5 adds authCert token validation to gate the endpoint.
Added 6mo ago
Detects Contest Gallery WordPress plugin versions 28.1.5 or earlier. The email confirmation handler uses the user's email string in a WHERE ID = %s clause instead of the numeric user ID. MySQL silently coerces an email like '[email protected]' to integer 1 (the admin user ID), overwriting the admin's user_activation_key. An unauthenticated AJAX endpoint (post_cg1l_login_user_by_key) then authenticates any user by activation key lookup, granting full admin access. Requires non-default RegMailOptional=1 setting. The fix in 28.1.6 uses absint() for the WHERE clause and switches to get_user_meta() with hash_equals() for key-based login.
Added 6mo ago
Detects Budibase instances running version 3.33.3 or earlier. The webhook trigger endpoint (/api/webhooks/trigger/) requires no authentication, and the bash automation step passes user-controlled payload data through Handlebars template processing directly into Node.js execSync() without sanitisation. An attacker can inject arbitrary OS commands via webhook payload fields, executing as root inside the container. The fix in 3.33.4 replaces execSync with execa (no shell) and splits the freeform code field into separate command + args.
Added 6mo ago
Detects Spring Cloud Config Servers vulnerable to directory traversal via the profile URL segment. The environment and resource endpoints validate the name and label parameters for path traversal but skip the profile parameter. An attacker injects encoded dot-dot sequences to escape the configured search directory and read arbitrary configuration files, database credentials, and API keys from the server filesystem.
Added 6mo ago
Detects WordPress installs running the Gravity SMTP plugin at version 2.1.4 or earlier. The plugin registers a REST API endpoint at /wp-json/gravitysmtp/v1/tests/mock-data with a permission_callback that unconditionally returns true. When the ?page=gravitysmtp-settings parameter is appended, the endpoint returns ~365KB of JSON containing the full system report: PHP version, loaded extensions, web server version, document root, database info, all active plugins with versions, WordPress config, database table names, and configured SMTP API keys/tokens.
Added 6mo ago
Detects WordPress installs running the JetFormBuilder plugin at version 3.5.6.1 or earlier. The server-side rule validation system passes a user-controlled callback function name to call_user_func() with a trivially bypassable blacklist — the check is case-sensitive and omits critical functions like passthru, proc_open, and eval. A contributor-level user can execute arbitrary PHP functions via the REST API validate-field endpoint, achieving full server compromise.
Added 6mo ago
Detects WordPress installs running the JetFormBuilder plugin at version 3.5.6.2 or earlier. The Media Field preset handler (set_from_array) accepts arbitrary file paths in the JSON payload without validation. An unauthenticated attacker can submit a form with a crafted preset pointing to sensitive files like wp-config.php. When the Send Email action fires with attachment enabled, the targeted file is exfiltrated as an email attachment.
Added 6mo ago
Detects WordPress installs running the Everest Forms Pro plugin at version 1.9.12 or earlier. The Calculation Addon's process_filter() function concatenates user-submitted form field values into a PHP code string and passes it to eval(). sanitize_text_field() does not escape single quotes, allowing unauthenticated attackers to break out of the string context and inject arbitrary PHP code — enabling full server compromise.
Added 6mo ago
Detects Nginx UI instances where the /mcp_message endpoint is accessible without authentication. The MCP integration only applies IP whitelisting (empty by default = allow all) but no auth middleware on the message endpoint. An attacker can invoke MCP tools to restart nginx, create or modify config files, and reload the service — achieving complete control over the web server routing and traffic.
Added 6mo ago
Detects WordPress installs running the Post SMTP plugin at version 3.8.0 or earlier. The plugin's email log display renders the event_type field from the Reporting and Tracking extension without output escaping. An unauthenticated attacker can inject JavaScript payloads via email tracking callbacks that execute when an admin views the email logs, enabling session hijacking and admin account takeover.
Added 6mo ago
Detects WordPress installs running the Simply Schedule Appointments plugin at version 1.6.10.0 or earlier. The plugin's TD_DB_Model::db_query() method takes the fields[] parameter from REST API requests and interpolates values directly into the SQL SELECT clause via backtick-wrapped implode() without sanitization or allowlist validation. An unauthenticated attacker can inject SQL to extract usernames, email addresses, and password hashes from the WordPress database.
Added 6mo ago
Detects WordPress installs running the Temporary Login plugin (by Elementor) at version 1.0.0 or earlier. The maybe_login_temporary_user() hook on init reads the temp-login-token GET parameter without verifying it is a string. Sending the parameter as an array (?temp-login-token[]=x) bypasses the empty() guard, coerces sanitize_key() to return an empty string, and causes WordPress get_users() to ignore the empty meta_value and return the first user holding the _temporary_login_token meta. The plugin then issues a wordpress_logged_in_ cookie for that user. An unauthenticated remote attacker can take over the WordPress administrator account in a single GET request.
Added 5mo ago
Detects WordPress installs running the SlimStat Analytics plugin (wp-slimstat) at version 5.3.5 or earlier. The plugin's AJAX tracking endpoint accepts a browser fingerprint (fh parameter) from unauthenticated visitors. The value passes through sanitize_text_field() which does not strip attribute-injection characters, then is rendered unescaped in the admin Access Log dashboard's title attribute. An attacker can inject JavaScript that executes when any admin views the analytics page, enabling session hijacking and full admin takeover.
Added 6mo ago
Detects WordPress installs running the Contact Form by Supsystic plugin at version 1.7.36 or earlier. The plugin renders form HTML through an unsandboxed Twig template engine, and the cfsPreFill feature passes user-supplied GET parameters into template expressions without escaping. An unauthenticated attacker can inject arbitrary Twig expressions via URL parameters to achieve server-side template injection and remote code execution.
Added 6mo ago
Detects Rails applications using Active Storage DiskService where the path_for method does not validate blob keys for directory traversal sequences. An attacker with access to the disk endpoint can craft a key containing ../../ to read arbitrary files from the server, including database credentials, encryption keys, and private configuration. Affects Rails < 7.2.3.1, 8.0.x < 8.0.4.1, and 8.1.x < 8.1.2.1.
Added 6mo ago
Detects WordPress installs running the CMS Commander Client plugin (cms-commander-client) at version 2.288 or earlier. The plugin's restore() function in lib/CMSC/Backup.php uses extract($args) and then interpolates or_blogname, or_blogdescription, and or_admin_email directly into SQL UPDATE queries via PHP string interpolation. Although $wpdb->prepare() is called, the absence of %s placeholders makes it a no-op. An attacker with a valid CMS Commander API key can inject arbitrary SQL via these unsigned parameters, extracting database credentials, user password hashes, and modifying any WordPress configuration.
Added 6mo ago
Detects WordPress installs running the WowStore (product-blocks) plugin at version 4.4.3 or earlier. The plugin's product-search REST endpoint accepts unauthenticated POST requests and interpolates the search parameter directly into SQL LIKE clauses without $wpdb->prepare(). An attacker can inject SQL to extract user credentials, customer orders, and any other data from the WordPress database. Affects WowStore versions up to and including 4.4.3.
Added 6mo ago
Detects Spring AI applications where the SimpleVectorStore filter expression converter interpolates user-controlled metadata filter key names directly into SpEL templates without sanitization. An unauthenticated attacker can inject arbitrary Spring Expression Language via the filter key parameter, breaking out of the #metadata['...'] context to execute arbitrary Java code including T(java.lang.Runtime).getRuntime().exec() for full Remote Code Execution. Affects Spring AI 1.0.0 through 1.0.4 and 1.1.0-M1 through 1.1.3.
Added 6mo ago
Detects WordPress installs running the Modular DS (modular-connector) plugin at version 2.5.1 or earlier. The plugin's isDirectRequest() method accepts origin=mo to bypass all authentication checks on the login REST endpoint, allowing unauthenticated attackers to obtain a full administrator session cookie. Actively exploited in the wild since January 2026, affecting 40,000+ installations.
Added 6mo ago
Detects Moodle installations running the Custom Certificate plugin (mdjnelson/moodle-mod_customcert) at versions prior to 4.4.9 or 5.0.3. The get_element_html and save_element web services fail to verify that the supplied element ID belongs to the authorized template, allowing any teacher to read and overwrite certificate elements from any other course via sequential ID enumeration.
Added 6mo ago
Detects WordPress installs running NextGEN Gallery at version 4.0.3 or earlier. The LegacyTemplateLocator accepts shortcode template parameters without path validation, allowing Author-level users to include and execute arbitrary PHP files on the server via path traversal sequences. This exposes wp-config.php credentials, enables reading sensitive server files, and achieves code execution when combined with file upload capabilities.
Added 6mo ago
Detects WordPress installs running the Jupiter X Core plugin at version 4.14.1 or earlier. The import_popup_templates() function lacks authorization checks, allowing Subscriber-level users to upload files with dangerous types (.phar, .svg, .xhtml). On Apache+mod_php servers, .phar uploads lead to remote code execution. On any server, .svg uploads enable stored XSS.
Added 6mo ago
Detects Laravel apps using plank/laravel-mediable <= 6.4.0 with prefer_client_mime_type enabled. An attacker uploads a PHP webshell with Content-Type: image/jpeg, bypassing all server-side MIME validation. If stored in a web-accessible directory with PHP execution, this achieves remote code execution. No patch available — vendor unresponsive. Mitigation: set prefer_client_mime_type to false.
Added 6mo ago
Detects Grafana instances running versions 11.6.0 through 12.4.1 where the SQL Expressions feature permits SELECT...INTO clauses, enabling authenticated users to write arbitrary files to the server filesystem. By overwriting a Sqlyze driver or AWS data source configuration, an attacker can achieve full remote code execution. Requires Viewer permissions and the sqlExpressions feature toggle to be enabled. Update to Grafana 12.4.2 or later.
Added 6mo ago
Detects MantisBT instances running on MySQL where the SOAP API's mc_login function accepts passwords as integers instead of strings. By sending the password as xsd:integer 0, MySQL's implicit type conversion causes the stored password hash to compare equal to 0, bypassing authentication entirely. An attacker who knows any username gains full API access. All versions before 2.28.1 on MySQL backends are affected.
Added 6mo ago
Detects Parse Server instances where allowExpiredAuthDataToken is enabled and auth provider validation is skipped on login when authData matches stored data. An attacker who obtains stored authData can impersonate any user with linked OAuth accounts, gaining a valid session token without the provider re-validating credentials. Affects versions before 8.6.52 and 9.0.0 through 9.6.0-alpha.40.
Added 6mo ago
Detects GitLab instances where the GraphQL API endpoint lacks CSRF token validation on mutation operations. An unauthenticated attacker can execute arbitrary GraphQL mutations on behalf of any logged-in user who visits a malicious page — creating personal access tokens, modifying repositories, or changing CI/CD settings. Versions 17.10.0–18.8.6, 18.9.0–18.9.2, and 18.10.0 are affected.
Added 6mo ago
Detects KiviCare Clinic & Patient Management System plugin versions through 4.1.2 where the social login endpoint accepts any arbitrary string as an OAuth token without verifying it against Google or Apple. An unauthenticated attacker can take over any patient account by providing just their email address. For admin and doctor accounts, valid WordPress session cookies are leaked in the 403 response headers because wp_set_auth_cookie() is called before the role check.
Added 6mo ago
Detects Spring AI applications where the MariaDBFilterExpressionConverter wraps user-controlled filter values in single quotes without escaping. An attacker with low privileges can inject arbitrary SQL via metadata filter parameters, bypassing access controls to read all documents in the vector store including restricted data, or extract database contents via error-based and time-based blind injection. Affects Spring AI 1.0.0 through 1.0.3 and 1.1.0-M1 through 1.1.2.
Added 6mo ago
Detects Parse Server instances where the authentication endpoint accepts non-string values in the authData user identifier field. An unauthenticated attacker can send a crafted login request that causes the server to perform a pattern-matching query instead of an exact-match lookup, matching any existing user and obtaining their session token. Anonymous authentication is enabled by default. Affects all versions before 8.6.38 and 9.0.0 through 9.6.0-alpha.11.
Added 6mo ago
Detects Spring Boot applications 3.4.0–3.4.14, 3.5.0–3.5.11, 4.0.0–4.0.3 where the Actuator EndpointRequest matcher for health group additional paths generates overly broad patterns. When a health group is exposed at an additional server path (e.g., /healthz), the matcher also matches subpaths (/healthz/admin), allowing unauthenticated access to protected application endpoints that share the path prefix.
Added 6mo ago
Detects the Linksy Search and Replace WordPress plugin at version 1.0.4 or earlier, where the linksy_search_and_replace_item_details AJAX action lacks any capability check. Any authenticated subscriber can update arbitrary database tables and values, including wp_capabilities, to escalate their role to administrator.
Added 6mo ago
Detects Frappe Framework instances before 15.84.0 / 14.99.0 where the DatabaseQuery.sanitize_fields() method only checks the first parenthesis in field names for blacklisted SQL functions. Wrapping a dangerous function like version() inside an allowed function like abs() bypasses the check entirely, enabling unauthenticated data extraction from the database.
Added 6mo ago
Detects Spring Security applications where OnCommittedResponseWrapper fails to track Content-Length set via setHeader/setIntHeader/addIntHeader, causing the HTTP response to commit before security headers (X-Frame-Options, X-Content-Type-Options, Cache-Control) are written. All browser-side protections are silently disabled.
Added 6mo ago
Detects Node.js applications using simple-git 3.15.0–3.32.2 where the blockUnsafeOperationsPlugin regex is case-sensitive but git config keys are case-insensitive. Passing uppercase -c PROTOCOL.ALLOW=always bypasses the security check and enables the ext:: protocol, which executes arbitrary OS commands on the host machine.
Added 6mo ago
Detects Magento / Adobe Commerce instances where the REST API ServiceInputProcessor accepts nested objects in guest checkout endpoints, enabling unauthenticated session takeover and remote code execution via DI traversal + session poisoning. Affects all versions through 2.4.7-p7, 2.4.8-p2, and 2.4.9-alpha2.
Added 6mo ago
Detects Craft CMS instances running versions 3.0.0 through 5.6.16 where the image transform endpoint accepts non-string handle parameters, enabling PHP object injection via Yii's __class bypass. An unauthenticated attacker can execute arbitrary code by sending a crafted JSON payload to /actions/assets/generate-transform.
Added 6mo ago
Detects Laravel Livewire v3 instances (3.0.0–3.6.3) where the component property update hydration mechanism allows unauthenticated attackers to smuggle malicious synthesizers through the updates payload, triggering a GuzzleHttp\Psr7\FnStream gadget chain for arbitrary command execution without needing the APP_KEY.
Added 6mo ago
Detects exposed React Native Metro Development Servers where the /open-url endpoint passes user-supplied URLs to the OS open handler without validation. An unauthenticated network attacker can execute arbitrary commands on the developer's machine. Affects @react-native-community/cli-server-api versions 4.8.0 through 20.0.0-alpha.2.
Added 6mo ago
Detects the Library Management System WordPress plugin at version 3.2.1 or earlier, where the bid parameter in the book shortcode handler has insufficient escaping, allowing unauthenticated attackers to inject SQL and extract sensitive data from the database.
Added 6mo ago
Detects the Front End Users WordPress plugin at version 3.2.32 or earlier, where the registration form file upload field lacks file type validation. An unauthenticated attacker can upload a PHP webshell through the registration form, which is stored in a predictable uploads directory, enabling remote code execution.
Added 6mo ago
Detects Gladinet CentreStack and Triofox instances prior to version 16.12.10420.56791 where the hardcoded AES-256-CBC key from GladCtrl64.dll allows unauthenticated attackers to forge encrypted access tickets and download arbitrary files via the /storage/filesvr.dn endpoint. This can be chained with CVE-2025-30406 for full remote code execution.
Added 6mo ago
Detects Keycloak instances where the IdentityBrokerService.performLogin endpoint allows authentication via a disabled Identity Provider. Versions before 26.2.14, 26.4.10, and 26.5.5 are affected. An attacker who knows the IdP alias can bypass admin-imposed IdP restrictions.
Added 6mo ago
Detects Keycloak instances where the parseInvitationToken function decodes organization invitation JWTs without verifying their cryptographic signature. Versions before 26.2.13, 26.4.9, and 26.5.3 are affected. An attacker can modify the organization ID and email in a legitimate invitation token to register into any organization.
Added 6mo ago
Detects LatePoint WordPress plugin versions 5.2.7 and earlier where Agent-level users can manipulate the wordpress_user_id parameter during customer creation to link customers to administrator accounts. Combined with the built-in password reset, this allows full WordPress admin takeover from a low-privileged Agent account.
Added 6mo ago
Detects the Page Builder by SiteOrigin WordPress plugin at version 2.33.5 or earlier, where the post-loop widget's locate_template() function concatenates user-controlled template names with WP_PLUGIN_DIR without path traversal validation. A Contributor-level user can include and execute arbitrary PHP files on the server, enabling credential theft and remote code execution.
Added 6mo ago
Detects the Ally (pojo-accessibility) WordPress plugin at version 4.0.3 or earlier, where the get_global_remediations() method uses esc_url_raw() to sanitize the current page URL before concatenating it into a SQL JOIN clause. esc_url_raw() does not escape SQL metacharacters, allowing unauthenticated time-based blind SQL injection.
Added 6mo ago
Detects The Events Calendar WordPress plugin at version 6.15.17 or earlier, where the ajax_create_import function accepts arbitrary file paths via the CSV import feature without path validation. An authenticated attacker with Author-level access can read any file on the server — including wp-config.php, /etc/passwd, and database credentials — by pointing the Event Aggregator CSV importer at a traversal path.
Added 6mo ago
Detects Tutor LMS Pro plugin at version 3.9.5 or earlier where the Social Login addon accepts a user-supplied email in the OAuth callback without verifying it matches the email from the validated token claims. An unauthenticated attacker can authenticate with their own OAuth account but substitute the victim’s email, logging in as any user including administrators.
Added 6mo ago
Detects Jenkins instances running versions 2.483 through 2.550 (weekly) or 2.492.1 through 2.541.1 (LTS) where the 'Mark temporarily offline' feature renders the user-provided offline cause description as raw HTML without escaping. Attackers with Agent/Configure or Agent/Disconnect permissions can inject JavaScript that executes when administrators view the agent status page, enabling session hijacking and credential theft.
Added 6mo ago
Detects Zimbra instances running versions 10.0.0–10.0.17 or 10.1.0–10.1.12 where the AntiSamy HTML sanitizer doesn't strip CSS @import directives from emails. Attackers can send crafted emails that execute JavaScript when opened in Classic UI, enabling session hijacking and credential theft.
Added 6mo ago
Detects n8n instances where the Data Table Get node's orderByColumn parameter is vulnerable to SQL injection when processed as an expression. The quoteIdentifier() function fails to escape embedded double quotes, allowing identifier breakout. On PostgreSQL deployments, multi-statement execution enables data modification and deletion. Versions <1.123.26, <2.13.3, and 2.14.0 affected.
Added 6mo ago
Detects n8n instances where the Merge node's Combine by SQL mode runs AlaSQL in the main Node.js process with a bypassable denylist. An authenticated user can escape the sandbox via JavaScript prototype chain traversal using AlaSQL's arrow operator to execute arbitrary OS commands, read the credential encryption key, and decrypt all stored secrets. Versions <1.123.27, <2.13.3, and 2.14.0 affected.
Added 6mo ago
Detects n8n instances where the /rest/binary-data endpoint serves HTML inline without Content-Security-Policy sandbox when binary data has no filename. An authenticated user can craft a workflow that executes JavaScript in other users' browsers on the n8n origin, stealing credentials and hijacking sessions. Versions <1.123.27, <2.13.3, and 2.14.0 affected.
Added 6mo ago
Detects n8n instances running versions 0.211.0 through 1.120.3 or 1.121.0 where the workflow expression evaluation engine allows authenticated users to escape the sandbox and execute arbitrary OS commands via prototype chain access to the Node.js process object.
Added 6mo ago
Detects n8n instances where the Git node does not validate the repositoryPath parameter against the isFilePathBlocked function. An authenticated user can specify a repository path pointing to sensitive directories, writing arbitrary files to the server and achieving remote code execution. Affects versions >= 0.123.0, < 1.121.3.
Added 6mo ago
Detects Traefik instances where lowercase Connection header tokens bypass the case-sensitive protection check, allowing attackers to strip Traefik-managed identity headers (X-Real-Ip, X-Forwarded-Host, etc.) from proxied requests. Versions 2.11.9–2.11.37 and 3.1.3–3.6.8 are affected.
Added 6mo ago
Exploits a cryptographic fail-open in the WPvivid Backup & Migration plugin's backup transfer feature. When RSA decryption fails, the plugin falls back to a null AES key, allowing an attacker to encrypt a payload with that null key and upload arbitrary files via path traversal. We upload a harmless canary file to prove the flaw exists.
Added 6mo ago
Confirms the Grafana Image Renderer's /render endpoint accepts path traversal in the filePath parameter with the default auth token, allowing arbitrary file writes that lead to remote code execution. Affects versions 1.0.0 through 4.0.16.
Added 6mo ago
Detects the Pix for WooCommerce WordPress plugin at version 1.5.0 or earlier, where the lkn_pix_for_woocommerce_c6_save_settings AJAX action accepts arbitrary file uploads without authentication or file type validation. An unauthenticated attacker can obtain a nonce from an exposed endpoint and upload a PHP webshell to a predictable path, achieving remote code execution.
Added 6mo ago
Detects n8n instances where form webhook endpoints accept Content-Type: application/json, bypassing the multipart file upload parser. An unauthenticated attacker can control the files.filepath field to read any file on the server, including /etc/passwd, n8n encryption keys, and the database. Combined with CVE-2025-68613, this enables full RCE.
Added 6mo ago
Detects Cloudflare Pingora reverse proxies at version 0.7.0 or earlier, where the HTTP/1.1 parser prematurely switches to pass-through mode on requests with an Upgrade header — before the backend confirms with 101 Switching Protocols. An attacker can smuggle arbitrary HTTP requests that bypass all proxy-level security controls (WAF, ACL, rate limiting).
Added 6mo ago
Detects Forgejo instances before 13.0.2 (and Gitea <= 1.24.6) vulnerable to arbitrary file read/write via symlink following in template repository expansion. An authenticated attacker creates a template repository with a symbolic link pointing outside the repo, and when a new repository is generated from it, the template engine follows the symlink — reading and writing to arbitrary files on the server. Combined with SSH authorized_keys injection, this leads to full remote code execution.
Added 6mo ago
Detects GitLab EE instances where the aiSelfHostedModels GraphQL query is accessible without authentication, exposing self-hosted AI model configurations including plaintext API tokens for LLM providers. Affects GitLab EE 18.5.0–18.8.6, 18.9.0–18.9.2, and 18.10.0.
Added 6mo ago
Confirms the GitLab AI Gateway's Duo Workflow Service evaluates user-supplied Jinja2 template expressions without blocking callables or dangerous operators. A math canary (41*271=11111) proves arbitrary expression evaluation, enabling remote code execution on the AI Gateway server.
Added 6mo ago
Detects GitLab instances where the Web IDE iframe accepts arbitrary parentOrigin parameters, allowing cross-origin token theft. Versions 18.2.0–18.6.5, 18.7.0–18.7.3, and 18.8.0–18.8.3 are affected.
Added 6mo ago
Detects the All-in-One Microsoft 365 & Entra ID SSO Login plugin at version 2.2.5 or earlier, where JWT tokens from the browser are accepted without cryptographic signature verification. An unauthenticated attacker can forge a token with any user's email and log in as administrator.
Added 6mo ago
Confirms that the User Registration & Membership plugin is installed at version 5.1.2 or earlier with the membership registration AJAX handler active. The plugin accepts a user-supplied WordPress role during membership registration without server-side validation, allowing an unauthenticated attacker to register as administrator and take full control of the WordPress install.
Added 6mo ago
Confirms that FreeSMS interpolates the login password field directly into a SQL query without escaping. A time-based blind SQL injection payload (SLEEP) proves an attacker can execute arbitrary database commands without authentication, enabling full database extraction and account takeover.
Added 6mo ago
Confirms that the Royal Elementor Addons plugin accepts file uploads via the Forms widget AJAX handler without authentication. Versions through 1.3.78 validate the MIME type on the client side only, allowing PHP webshell upload and remote code execution.
Added 6mo ago
Confirms Chamilo version is vulnerable and the wsConvertPpt SOAP endpoint is accessible. Versions through 1.11.18 pass the filename directly to exec() without sanitization, allowing unauthenticated remote code execution.
Added 6mo ago
Confirms that Chamilo's Big File Upload endpoint at /main/inc/lib/javascript/bigupload/inc/bigUpload.php is accessible without authentication and accepts arbitrary file types. Versions through 1.11.24 allow direct PHP webshell upload and execution.
Added 6mo ago
Confirms that Chamilo's file manager AJAX endpoint at /main/inc/lib/javascript/bigupload/inc/bigUpload.php is accessible and processes file uploads without authentication. Versions through 1.11.24 accept arbitrary file writes, enabling remote code execution via PHP webshell upload.
Added 6mo ago
Uploads a crafted ZIP to the unauthenticated flow import endpoint, proving that DB-GPT executes arbitrary Python code from uploaded modules without validation.
Added 6mo ago
Confirms unauthenticated access to the OAuth token endpoint by sending a credential lookup request without a session. Vulnerable instances process the request, proving any user's OAuth tokens for GitHub, Google, Slack, etc. can be stolen.
Added 6mo ago
Uploads a file with mismatched MIME type to the unauthenticated attachment endpoint, proving that Flowise accepts executable scripts disguised as harmless file types.
Added 6mo ago
Injects a closing parenthesis into the wpfob ORDER BY parameter on the recent topics page, triggering a MySQL syntax error that confirms unquoted SQL injection. No authentication required.
Added 6mo ago
Detects Rocket.Chat instances affected by CVE-2026-30831 where the enterprise DDP Streamer accepts username/password login without enforcing 2FA or checking user-active status. Attackers can bypass two-factor authentication entirely via the DDP WebSocket endpoint.
Added 6mo ago
Extracts data from the WordPress database through a time-based blind SQL injection in the Tutor LMS plugin's checkout coupon code parameter. No authentication required.
Added 7mo ago
Detects error-based SQL injection in Chamilo LMS via the OpenID assoc_handle parameter. The openid_verify_assertion() function interpolates user input directly into a SQL query without parameterization.
Added 6mo ago
Detects error-based SQL injection in Chamilo LMS via the SOAP WSCertificatesList startingDate parameter. The registration.soap.php endpoint interpolates date parameters directly into SQL without parameterization.
Added 6mo ago
Detects case-sensitivity bypass in the Chamilo vChamilo plugin's phar:// wrapper filter. Mixed-case Phar:// input passes the str_starts_with() check, allowing PHP deserialization via file-system functions.
Added 6mo ago
Detects error-based SQL injection in Chamilo LMS via the custom_dates filter property in the model.ajax.php jqGrid endpoint. The endpoint appends user-supplied JSON filter data directly into a SQL WHERE clause without sanitization, allowing unauthenticated database access.
Added 6mo ago
Proves unauthenticated command injection via the X-Nuclio-Arguments HTTP header, which is passed directly to sh -c without sanitization. A math canary confirms arbitrary command execution.
Added 6mo ago
Extracts data from the WordPress database through a UNION-based SQL injection in the JS Help Desk plugin's ticket tracking cookie. No authentication required.
Added 7mo ago
Detects time-based blind SQL injection in the JS Help Desk WordPress plugin's ticket status endpoint. The plugin's base64 token is decoded and injected directly into SQL without sanitization.
Added 7mo ago
Detects time-based blind SQL injection in SimpleJobScript's job applications endpoint. The job_id POST parameter is concatenated directly into SQL without sanitization, allowing unauthenticated database access.
Added 6mo ago
Reads arbitrary server files including /proc/1/environ through path traversal in the PWA ZIP processing endpoint, exfiltrating all secrets and credentials in a single request.
Added 7mo ago
Detects vulnerable Gogs versions where the repository editor API follows symlinks without checking directory components. Any authenticated user can overwrite arbitrary files via symlink traversal and inject commands into .git/config for remote code execution.
Added 7mo ago
Detects vulnerable Gogs versions where LFS object uploads lack SHA256 content hash verification, allowing cross-repository object overwrite and supply-chain poisoning.
Added 7mo ago
Bypasses filename extension blocklist using zero-width space (U+200B) to upload .htaccess and PHP webshell, achieving remote code execution. Patch bypass for CVE-2026-27636.
Added 7mo ago
Downloads the full system backup including SSL keys and credentials without authentication. The AES encryption key is exposed in the response header.
Added 7mo ago
Identifies vulnerable SmarterMail builds and confirms the admin ConnectToHub endpoint accepts unauthenticated requests, proving remote code execution is possible.
Added 7mo ago
Detects vulnerable Roundcube versions where SVG animate tags bypass the HTML sanitizer, allowing stored XSS in email rendering and account takeover.
Added 7mo ago
Reads internal configuration files like WEB-INF/web.xml without authentication through Zimbra's RestFilter servlet path parameter.
Added 7mo ago
Confirms the WebEx zimlet SSRF endpoint is exposed and processing requests, allowing attackers to make the server fetch arbitrary internal URLs.
Added 7mo ago
Executes a harmless math operation through React Server Components prototype chain traversal, proving unauthenticated remote code execution. Includes WAF bypass variants.
Added 7mo ago
Sends a crafted header that causes Next.js to skip all middleware, completely bypassing authentication and authorization on protected routes.
Added 7mo ago
Reads /etc/passwd through URL-encoded path traversal sequences in Apache's CGI handler, proving arbitrary file read on the server.
Added 7mo ago
Reads /etc/passwd through a double-encoded dot sequence. Apache 2.4.50 stopped the single-encoded form and still accepted this one.
Added 15d ago
Reads /etc/passwd through Grafana's plugin static file serving, which fails to sanitize path traversal sequences in the plugin ID path.
Added 7mo ago
Confirms that Grafana's data source proxy accepts wildcard UID (*) in the URL path, allowing any authenticated viewer to query all configured data sources regardless of permissions. Affects Grafana 8.x through 10.3.3.
Added 6mo ago
Detects exposed Laravel Ignition debug endpoints that accept arbitrary solution payloads without authentication, proving remote code execution capability.
Added 7mo ago
Reads internal configuration files like WEB-INF/web.xml through Jira's semicolon path parameter bypass in static resource serving.
Added 7mo ago
Reads internal configuration files through Confluence's semicolon path parameter bypass, the same technique as the Jira variant.
Added 7mo ago
Reads /etc/passwd through double URL-encoded path traversal in Flink's JobManager REST API log file endpoint.
Added 7mo ago
Sends the actual Form API exploit payload with a harmless echo canary. If the canary appears in the response, the server executed attacker-controlled code.
Added 7mo ago
Detects Drupal instances where the REST API with HAL module accepts unauthenticated requests. Versions 8.5.x before 8.5.11 and 8.6.x before 8.6.10 deserialize attacker-controlled PHP objects from HAL+JSON input, enabling remote code execution without authentication.
Added 7mo ago
Reads ColdFusion's password.properties file through locale parameter traversal on the administrator console.
Added 7mo ago
Lists all WordPress usernames through the unauthenticated REST API endpoint, exposing accounts for password brute-force attacks.
Added 7mo ago
Confirms that Grafana's XY Chart plugin renders tooltip content using innerHTML without sanitization. An attacker with editor access can craft a dashboard link that executes JavaScript in any viewer's browser, stealing session tokens.
Added 6mo ago
Detects the Contact Form Entries WordPress plugin at version 1.4.7 or earlier, where the download_csv function deserializes form field data using maybe_unserialize() without object type restrictions. Combined with a POP chain from another plugin, an unauthenticated attacker can achieve file deletion, data theft, or remote code execution.
Added 6mo ago
Detects MCPJam Inspector at version 1.4.2 or earlier, where the HTTP server binds to all interfaces and exposes the /api/mcp/connect endpoint without authentication. An attacker with network access can send a crafted POST request to execute arbitrary commands on the server.
Added 6mo ago
Detects Langflow instances prior to 1.9.0 where the build_public_tmp endpoint accepts attacker-controlled flow definitions containing arbitrary Python code. The code is passed to exec() without sandboxing, enabling unauthenticated remote code execution. Actively exploited within 20 hours of disclosure.
Added 6mo ago
Detects Langflow instances from 1.2.0 through 1.8.1 where the POST /api/v2/files/ endpoint accepts directory traversal sequences in multipart upload filenames. An authenticated attacker can write arbitrary files on the server, leading to remote code execution. Bypass of incomplete CVE-2025-68478 fix.
Added 6mo ago
Detects Parse Server instances using PostgreSQL where the sort/order query parameter accepts dot-notation field names with unescaped single quotes in sub-field values. An attacker with the Application ID and REST API key (typically exposed in client-side code) can inject arbitrary SQL via the order parameter, enabling full database access.
Added 6mo ago
Detects the Datalogics Ecommerce Delivery WordPress plugin before version 2.6.60, where an unauthenticated REST API endpoint allows arbitrary WordPress option updates. Attackers can enable user registration and set the default role to Administrator, gaining full control of the install.
Added 6mo ago
Detects WooCommerce Custom Product Addons Pro plugin before version 5.4.2, where the custom pricing formula feature uses PHP eval() on user-submitted values without proper sanitization. Unauthenticated attackers can inject arbitrary PHP code through add-to-cart requests, achieving remote code execution.
Added 6mo ago
Detects the Kali Forms WordPress plugin before version 2.4.10, where the form processor maps user-supplied POST keys into internal placeholder storage. Placeholders like {entryCounter} and {thisPermalink} are later passed to call_user_func(), allowing unauthenticated attackers to execute arbitrary PHP functions.
Added 6mo ago
Detects Argo Workflows instances before 3.7.11 or 4.0.2 where the workflow template endpoints bypass authorization checks. Any request with a bearer token can retrieve WorkflowTemplates and ClusterWorkflowTemplates, including embedded Secret manifests with database passwords, API keys, and cloud credentials.
Added 6mo ago
Detects Rocket.Chat instances affected by CVE-2026-28514 where the enterprise DDP Streamer's account service calls an async password validation function without await. The returned Promise is always truthy, allowing any password to authenticate as any user.
Added 6mo ago
Detects FreeScout instances running version 1.8.208 or earlier where incoming email bodies are rendered in agent notification emails without sanitization. Attackers can send crafted emails to any FreeScout-monitored inbox to inject JavaScript that executes when agents view the notification, enabling session hijacking and account takeover.
Added 6mo ago
Detects Spring Boot applications with CloudFoundry actuator support where the SecurityFilterChain only matches known actuator endpoint paths. Unknown sub-paths under /cloudfoundryapplication/ bypass Spring Security entirely, allowing unauthenticated access to application controllers. Affects Spring Boot 4.0.0–4.0.3, 3.5.0–3.5.11, 3.4.0–3.4.14, 3.3.0–3.3.17, 2.7.0–2.7.31. Update to 3.5.12 or 4.0.4.
Added 6mo ago
Detects MinIO instances vulnerable to JWT algorithm confusion in OIDC authentication. MinIO stores the OIDC client_secret in its public key lookup map keyed by client_id. An attacker who knows the client secret can forge HS256 identity tokens to assume any IAM role including consoleAdmin, gaining full access to all stored objects. Affects all MinIO releases from RELEASE.2022-11-08 through the last open-source release. Update to MinIO AIStor RELEASE.2026-03-17 or later.
Added 6mo ago
Detects Harbor container registry instances running version 2.15.0 or earlier where the default admin password (Harbor12345) has not been changed. Attackers can authenticate with these well-known credentials to gain full admin access — pulling private images, pushing malicious ones, and compromising container supply chains.
Added 6mo ago
Detects Jenkins instances running version 2.554 or earlier (weekly) or LTS 2.541.2 or earlier where symbolic links in .tar/.tar.gz archives are followed during extraction, allowing files to be written to arbitrary filesystem locations. Attackers with Item/Configure permission can achieve remote code execution by planting Groovy init scripts. Update to Jenkins 2.555 or LTS 2.541.3.
Added 6mo ago
Detects SuiteCRM instances before version 7.15.1 (or 8.9.3 for 8.x) where the getUserNameFilter() function in LDAPAuthenticateUser.php embeds usernames directly into LDAP search filters without ldap_escape(). On LDAP-configured instances, attackers can inject filter operators to bypass authentication or enumerate users.
Added 6mo ago
Detects the Performance Monitor WordPress plugin before version 1.0.7, where the curl_data REST endpoint (permission_callback: __return_true) passes user-supplied URLs directly to curl_init()/curl_exec() without validation. Unauthenticated attackers can make the server fetch arbitrary URLs including internal services and cloud metadata.
Added 6mo ago
Detects H3 instances (including Nuxt/Nitro applications) running versions 2.0.0 through 2.0.1-rc.14 where the FastURL class in srvx constructs URLs from the untrusted Host header. An attacker can inject a path into the Host header to make middleware see a spoofed pathname, bypassing authentication and authorization checks on any middleware-protected route. Update H3 to 2.0.1-rc.15 or later.
Added 6mo ago
Detects Masteriyo LMS plugin versions 2.1.6 and below where the Instructors REST API endpoint accepts a roles parameter without authorization checks. Any authenticated student can escalate to WordPress administrator with a single API request. Update to Masteriyo LMS 2.1.7 or later.
Added 6mo ago
Detects AVideo instances where the CloneSite plugin exposes clone configuration data (including secret keys) without authentication. These keys enable a full attack chain: database dump, credential extraction, and OS command injection via rsync. Update AVideo past commit c85d076 or to the next release.
Added 6mo ago
Detects Joomla installs running the Astroid Template Framework at version 3.3.10 or earlier. The framework's system plugin exposes admin AJAX endpoints without authentication — it checks CSRF tokens but never verifies the caller is an admin. An attacker grabs a token from the public login page, then uses the media upload handler to upload a PHP web shell. In the wild, attackers are installing persistent backdoor plugins (plg_system_blpayload). Update to Astroid Framework 3.3.11 or later.
Added 6mo ago
Detects MW WP Form plugin versions 5.1.0 and below where the generate_user_filepath() function fails to validate absolute paths. An unauthenticated attacker can move arbitrary server files (like wp-config.php) to the uploads directory via a form with a file upload field, potentially causing full takeover. Update to MW WP Form 5.1.1 or later.
Added 6mo ago
Detects WordPress installs running the JetEngine plugin at version 3.8.6.1 or earlier. The listing_load_more AJAX handler excludes filtered_query from HMAC validation, and the SQL Query Builder's prepare_where_clause() concatenates user-controlled compare operators into SQL without sanitization. An unauthenticated attacker can extract database contents including usernames and password hashes. Update to JetEngine 3.8.6.2 or later.
Added 6mo ago
Detects WordPress installs running the WP DSGVO Tools (GDPR) plugin at version 3.1.38 or earlier. The super-unsubscribe AJAX action accepts a process_now parameter from unauthenticated users, bypassing email confirmation and immediately anonymizing any non-admin account — randomizing the password, overwriting username and email, stripping roles, and anonymizing all comments. The required nonce is publicly available on any page with the unsubscribe form shortcode. Update WP DSGVO Tools to 3.1.39 or later.
Added 6mo ago
Detects WordPress installs running the WP Extended plugin at version 3.2.4 or earlier. The Menu Editor module's grantVirtualCaps() method grants manage_options to any authenticated user when the URL contains '/wp-admin/profile.php' in the query string. A subscriber can escalate to administrator with a single crafted request, then create new admin accounts or install backdoors. Update WP Extended to 3.2.5 or later.
Added 6mo ago
Detects WordPress installs running the WP Maps plugin (wp-google-map-plugin) at version 4.9.1 or earlier. The prepare_items() method in class.tabular.php reads the orderby GET parameter through sanitize_text_field() and interpolates it directly into an SQL ORDER BY clause without whitelist validation. The unauthenticated AJAX handler (wpgmp_ajax_call) exposes internal methods to any visitor. An attacker can extract database contents including admin credentials and customer data. Update to WP Maps 4.9.2 or later.
Added 6mo ago
Detects AVideo installations at version 26.0 or earlier. The fixCleanTitle() static method in objects/category.php constructs a SQL SELECT query by directly interpolating $clean_title and $id without parameterized queries. An authenticated user with category-creation privileges can inject arbitrary SQL to extract database contents including admin credentials and user PII via UNION injection. Update AVideo to a version after commit 994cc2b.
Added 6mo ago
Detects Outline instances running versions 0.86.0 through 1.5.x where the email OTP login flow has no attempt limit and the rate limiter is disabled by default. The rate limiter key can also be forged via unsigned JWT cookies, enabling unrestricted brute-force of the 6-digit OTP code within its 10-minute lifetime. Successful exploitation grants full account access including documents and admin controls.
Added 6mo ago
Detects the Order Notification for WooCommerce plugin (woc-order-alert) before version 3.6.2 which overrides WooCommerce's REST API permission checks with a blanket '__return_true' filter. Any unauthenticated attacker can read customer data, modify products, create fraudulent coupons, and manipulate orders via the WooCommerce REST API.
Added 6mo ago
Detects pyLoad instances through version 0.5.0b3.dev96 where the download engine's SSRF filter only validates the initial URL hostname. An authenticated attacker can submit a download URL pointing to an attacker-controlled server that responds with a 302 redirect to internal endpoints (cloud metadata at 169.254.169.254, localhost services, private network). pycurl follows the redirect without any destination validation, exposing IAM credentials and internal services. The fix adds a pycurl PREREQFUNCTION callback that checks every connection including redirects.
Added 6mo ago
Detects Apache ActiveMQ Classic instances before 5.19.4 / 6.2.3 where the Jolokia JMX-HTTP bridge is accessible with default credentials (admin:admin). The addNetworkConnector MBean operation accepts crafted vm:// URIs with brokerConfig parameters that load remote Spring XML application contexts, enabling arbitrary code execution. This bug has existed for 13+ years.
Added 6mo ago
Detects Parse Server instances where the Cloud Function trigger store can be traversed via the JavaScript prototype chain. An attacker appends '.prototype.constructor' to a Cloud Function name in the API URL, causing the handler to resolve through the prototype chain while the validator store finds no validator — skipping requireUser, requireMaster, and custom validators entirely. Any Cloud Function defined with the 'function' keyword (not arrow functions) is exploitable. Update to Parse Server 8.6.67 or 9.7.0 or later.
Added 6mo ago
Detects Django instances running under ASGI where ASGIRequest normalizes header names by converting hyphens to underscores, allowing an attacker to spoof security-sensitive headers by supplying the underscore variant (e.g., X_Forwarded_Host instead of X-Forwarded-Host). This bypasses reverse proxy header stripping and lets an attacker forge the client IP, host, and protocol. The fix ignores headers with underscores entirely. Update to Django 6.0.4, 5.2.13, or 4.2.30.
Added 6mo ago
Detects PraisonAI MCP server instances where the OAuth validate_token() method returns True for any unknown Bearer token. An unauthenticated attacker can send a fabricated token to the /mcp endpoint and gain full access to all registered MCP tools — agent execution, file read/write, workflow operations, and skill loading. Update to PraisonAI 4.5.97 or later.
Added 6mo ago
Detects Tautulli instances before version 2.17.0 where the notification template eval sandbox can be bypassed via nested code objects (lambda expressions). The str_eval() function only checks allowlisted names at the top-level code object — attributes accessed inside lambdas are stored in co_consts and never validated. When NOTIFY_TEXT_EVAL is enabled in Advanced Settings, an admin can execute arbitrary Python commands on the server. Update to Tautulli v2.17.0 or later.
Added 6mo ago
Detects Bludit CMS instances before version 3.18.4 with the API plugin enabled. The file upload endpoint (POST /api/files/) has no effective file extension validation — any API token holder can upload PHP webshells and execute arbitrary commands as the web server user. The API plugin is disabled by default but when activated, the token is visible to all admin-panel users and may leak through logs or other vulnerabilities.
Added 6mo ago
Detects marimo notebook instances before version 0.23.0 where the /terminal/ws WebSocket endpoint does not call validate_auth(). An unauthenticated attacker connects and receives a full PTY shell as the server process user, enabling arbitrary command execution. The fix adds authentication validation before accepting WebSocket connections.
Added 5mo ago
Detects WordPress instances with the DSGVO Google Web Fonts GDPR plugin installed (all versions through 1.1). The plugin registers an unauthenticated AJAX action (DSGVOGWPdownloadGoogleFonts) that fetches attacker-controlled URLs via wp_remote_get() and saves files to a public directory without any file type validation. An attacker can upload PHP webshells and achieve remote code execution. No patch exists — the plugin was closed on WordPress.org. Remove it immediately.
Added 5mo ago
Detects Joomla instances running versions 4.0.0–5.4.3 or 6.0.0–6.0.3 where the REST API articles endpoint (/api/index.php/v1/content/articles) passes user-supplied list[ordering] parameters directly into SQL ORDER BY clauses. The API controller bypasses the model's normal ordering validation, allowing any authenticated API user to inject SQL expressions and extract database contents — admin credentials, session tokens, and configuration secrets. Update to Joomla 5.4.4 or 6.0.4.
Added 5mo ago
Detects WordPress instances with Everest Forms ≤ 3.4.3 installed, where the plugin calls PHP's native unserialize() on stored form entry metadata in html-admin-page-entries-view.php without passing the allowed_classes parameter. An unauthenticated attacker can submit a serialized PHP object payload via any public form field — it survives sanitize_text_field() sanitization and is stored in wp_evf_entrymeta. When an administrator views entries, the unsafe unserialize() call processes the stored data without class restrictions, enabling POP chain exploitation for file write, SSRF, or remote code execution. Update Everest Forms to 3.4.4 or later.
Added 5mo ago
Detects GitLab CE/EE instances from 16.9.6 through 18.8.8, 18.9.0 through 18.9.4, and 18.10.0 through 18.10.2 where authenticated users can invoke restricted server-side methods through the /-/cable WebSocket endpoint's GraphqlChannel due to improper access control. A low-privileged user can enumerate private projects, user details, and internal configuration. Update to GitLab 18.8.9, 18.9.5, or 18.10.3.
Added 5mo ago
Detects OAuth2 Proxy instances before 7.15.2 where setting the User-Agent header to the health check value (GoogleHC/1.0) bypasses authentication on any URL path. An unauthenticated attacker gains full access to all upstream services behind the proxy.
Added 5mo ago
Detects Chamilo LMS instances before 1.11.38 where the password reset mechanism generates tokens using sha1(email) with no random component, no expiration, and no rate limiting. An attacker who knows a user's email can compute the reset token and change the victim's password without authentication, leading to full account takeover. Update to Chamilo 1.11.38 or 2.0.0-RC.3.
Added 5mo ago
Detects Laravel Passport instances from 13.0.0 through 13.7.0 where the TokenGuard in authenticateViaBearerToken() fails to distinguish client_credentials grant tokens from user-associated tokens. The JWT subject claim is set to the client ID by the OAuth2 server, but the guard passes it directly to retrieveById() without checking whether it represents a user or client. When client IDs collide with user IDs (integer IDs or MySQL implicit casting of UUIDs), a machine-to-machine token impersonates a real user — reading their data and acting on their behalf. Update to laravel/passport 13.7.1 or later.
Added 5mo ago
Detects WordPress installs running the AcyMailing newsletter plugin between 9.11.0 and 10.8.1 inclusive. The AcymController::call() method skips the acym_isAllowed() capability check whenever the requested task name contains the substring 'Ajax'. Any subscriber-level user can therefore invoke the configuration controller's saveAjax method through wp_ajax_acymailing_router to enable the autologin feature, create a newsletter subscriber whose cms_id points to an administrator, then visit a crafted ?autoSubId=N&subKey=KEY URL to authenticate as that administrator. Update AcyMailing to 10.8.2 or later.
Added 5mo ago
Detects the miniOrange 2FA WordPress plugin (5.3.24–6.3.0 free track, 18.0–19.2 premium track) vulnerable to unauthenticated arbitrary WordPress option deletion. The plugin registers its out-of-band email-verification link handler on the init hook (fired for every request), and when ?Txid and ?accessToken are present it uses the ?userID and ?Txid request parameters directly as site-option names passed to delete_site_option() — with no login, nonce, or capability check. Any anonymous visitor can delete options such as siteurl, template, or active_plugins, locking every administrator out of wp-admin or disabling security plugins (CWE-862, CVSS 10.0). Update miniOrange 2FA to 6.3.1 (free) or 19.3 (premium) or later.
Added 16d ago
Detects Traefik 2.11.0 through 2.11.56 and 3.0.0 through 3.7.12, where the HTTP/3 entrypoint builds its QUIC connection context without calling service.AddTransportOnContext. The per-connection RoundTripper holder is therefore missing from every HTTP/3 request context, so kerberosRoundTripper cannot pin a transport dedicated to the frontend connection and keeps using the shared backend transport. Against a backend that answers 401 WWW-Authenticate: NTLM or Negotiate — schemes that bind authentication to the TCP connection rather than to the request — backend keep-alive then lets an unrelated HTTP/3 client be served on the connection a victim authenticated, reading victim-only data and acting as that victim without ever holding their credentials. The verifier reads the version from the Traefik API and confirms the HTTP/3 precondition from /api/entrypoints or an Alt-Svc h3 advertisement. Patched in 2.11.57 and 3.7.13.
Added 16d ago