Brendan
|
10d12570c0
|
Merge pull request #20791 from Chocapikk/webcheck
Add Web-Check screenshot API command injection RCE exploit (CVE-2025-32778)
|
2026-01-12 17:14:04 -06:00 |
|
jheysel-r7
|
b9be6ac259
|
Merge pull request #20785 from Chocapikk/react2shell-clean
Update react2shell module: Add Waku framework support
|
2026-01-08 17:58:48 -08:00 |
|
msutovsky-r7
|
b39e781500
|
Land #20700, adds module for Taiga.io RCE (CVE-2025-62368)
Adds exploit module for authenticated deserialization vulnerability in Taiga.io (CVE-2025-62368)
|
2026-01-07 11:53:32 +01:00 |
|
jheysel-r7
|
0d21fd4cc9
|
Merge pull request #20692 from msutovsky-r7/persistence/multi/python-site-specific-config-hook
Adds module for python site-specific hook persistence
|
2026-01-06 16:19:31 -08:00 |
|
Brendan
|
6c4a61fa42
|
Merge pull request #20761 from Chocapikk/acf-extended-rce
Add WordPress ACF Extended unauthenticated RCE exploit (CVE-2025-13486)
|
2025-12-18 16:03:06 -06:00 |
|
Valentin Lobstein
|
080f74f862
|
Update Web-Check documentation with docker-compose.yml setup instructions
|
2025-12-18 19:19:17 +01:00 |
|
Valentin Lobstein
|
5178cdee42
|
Update Web-Check documentation with git clone command
|
2025-12-18 18:56:18 +01:00 |
|
Valentin Lobstein
|
13f102eb5b
|
Add Web-Check screenshot API command injection RCE exploit (CVE-2025-32778)
|
2025-12-18 18:51:12 +01:00 |
|
Valentin Lobstein
|
3b407575fa
|
Update react2shell module: Add Waku framework support
|
2025-12-17 23:07:01 +01:00 |
|
jheysel-r7
|
388a967101
|
Merge pull request #20749 from nakkouchtarek/grav-ssti-rce
Add Grav CMS Twig SSTI Sandbox Bypass RCE Exploit Module & Documentation
|
2025-12-11 16:13:09 -08:00 |
|
jheysel-r7
|
0c921ea2e7
|
Merge pull request #20725 from Chocapikk/magento
Add Magento SessionReaper (CVE-2025-54236) exploit module
|
2025-12-10 08:56:47 -08:00 |
|
jheysel-r7
|
d86c5f0908
|
Merge pull request #20746 from Chocapikk/king-addons
Add WordPress King Addons privilege escalation exploit (CVE-2025-8489)
|
2025-12-10 08:37:11 -08:00 |
|
Martin Sutovsky
|
6a626a855b
|
Addresses some comments
|
2025-12-10 17:01:27 +01:00 |
|
Valentin Lobstein
|
b4d65afcf5
|
Add exploit module for WordPress ACF Extended CVE-2025-13486 unauthenticated RCE
|
2025-12-09 22:02:41 +01:00 |
|
Valentin Lobstein
|
e9467cd1e3
|
Clarify file-based session storage requirements and exploit limitations
Co-authored-by: jheysel-r7 <jheysel-r7@users.noreply.github.com>
|
2025-12-09 19:26:30 +01:00 |
|
Valentin Lobstein
|
6bc2bffd8c
|
Refactor create_admin_user to handle errors internally and remove custom.ini from documentation
|
2025-12-09 19:20:56 +01:00 |
|
Valentin Lobstein
|
17cc68df0f
|
Update documentation/modules/exploit/multi/http/wp_king_addons_privilege_escalation.md
Co-authored-by: Julien Voisin <jvoisin@users.noreply.github.com>
|
2025-12-09 19:14:22 +01:00 |
|
sfewer-r7
|
1a8e88c054
|
fix a typo with the use of CVE-2025-55102, it should be CVE-2025-55182
|
2025-12-09 09:05:59 +00:00 |
|
jheysel-r7
|
66279422d1
|
Merge pull request #20747 from vognik/2025-55182
Add CVE-2025-55182 / CVE-2025-66478
|
2025-12-08 13:41:49 -08:00 |
|
vognik
|
bdd7cb5365
|
upgraded payload
|
2025-12-08 01:32:43 -08:00 |
|
vognik
|
1dde12b483
|
fix naming errors
|
2025-12-06 02:53:38 -08:00 |
|
vognik
|
38682b5ed6
|
refactoring
|
2025-12-05 14:58:59 -08:00 |
|
vognik
|
88309b5a4a
|
add suggestions from @Chocapikk
|
2025-12-05 08:02:56 -08:00 |
|
vognik
|
baa0a11492
|
small fixes
|
2025-12-05 00:11:44 -08:00 |
|
vognik
|
770e63b0d1
|
add windows documentation
|
2025-12-05 00:06:58 -08:00 |
|
vognik
|
e51ea0ae23
|
improve documentation
|
2025-12-04 23:03:13 -08:00 |
|
vognik
|
f71a71ab18
|
add exploit mvp
|
2025-12-04 22:16:27 -08:00 |
|
Tarek Nakkouch
|
3c4fdfcad0
|
Add Grav CMS Twig SSTI Sandbox Bypass RCE Exploit Module (CVE-2025-66294)
|
2025-12-05 00:01:56 +01:00 |
|
Diego Ledda
|
4d52e22480
|
Merge pull request #20720 from Chocapikk/wp-ai-engine
Add WordPress AI Engine MCP RCE exploit (CVE-2025-11749)
|
2025-12-04 12:56:04 +01:00 |
|
Valentin Lobstein
|
296e931b7d
|
Fix WordPress lab permissions in documentation
|
2025-12-04 01:39:25 +01:00 |
|
Valentin Lobstein
|
b3fc1b05e5
|
Add WordPress King Addons privilege escalation exploit (CVE-2025-8489)
|
2025-12-04 01:37:40 +01:00 |
|
msutovsky-r7
|
b6330acb12
|
Land #20718, adds module for Monsta FTP RCE (CVE-2025-34299)
Add Monsta FTP downloadFile RCE (CVE-2025-34299)
|
2025-11-27 15:16:58 +01:00 |
|
Valentin Lobstein
|
4ff9fd4542
|
Apply reviewer suggestions and remove unnecessary Options section from documentation
|
2025-11-25 23:48:39 +01:00 |
|
Valentin Lobstein
|
be7ad39127
|
Fix reference URL in documentation to correct Searchlight Cyber research article
|
2025-11-24 23:26:29 +01:00 |
|
Valentin Lobstein
|
9ef10eeea8
|
Update documentation with complete Docker lab setup files
|
2025-11-24 21:12:14 +01:00 |
|
Valentin Lobstein
|
1623660bec
|
Add Magento SessionReaper (CVE-2025-54236) exploit module
|
2025-11-24 21:04:20 +01:00 |
|
Valentin Lobstein
|
080230edd0
|
Add WordPress AI Engine MCP RCE exploit (CVE-2025-11749)
|
2025-11-23 03:56:11 +01:00 |
|
Valentin Lobstein
|
8cffe50470
|
Add Monsta FTP downloadFile RCE (CVE-2025-34299)
|
2025-11-21 20:43:37 +01:00 |
|
Valentin Lobstein
|
6ab2452153
|
Fix documentation inconsistency: update ports for Flowise 3.0.1 (3005) and add Basic Auth service example
|
2025-11-19 22:58:27 +01:00 |
|
Valentin Lobstein
|
8fbbc3e043
|
Update flowise_custommcp_rce documentation: add Basic Auth testing scenario
|
2025-11-19 22:24:28 +01:00 |
|
Valentin Lobstein
|
44cf2e309f
|
Add Flowise RCE exploits (CVE-2025-59528, CVE-2025-8943) with shared mixin, documentation, and Docker Compose setup
|
2025-11-19 22:12:49 +01:00 |
|
Valentin Lobstein
|
df1c157471
|
Improve Flowise CustomMCP RCE exploit stability with Basic Auth support and HTTP response validation
|
2025-11-19 20:12:31 +01:00 |
|
whotwagner
|
4c3ee4f499
|
Refactoring taiga-exploit and docs
|
2025-11-19 19:09:46 +00:00 |
|
Martin Sutovsky
|
197dbf921d
|
Fixes Windows persistence
|
2025-11-19 07:52:54 +01:00 |
|
Martin Sutovsky
|
ec8906bbd4
|
Adds docs
|
2025-11-19 07:17:07 +01:00 |
|
Valentin Lobstein
|
b26c4f5c7b
|
Add Flowise Custom MCP RCE exploit (CVE-2025-8943)
|
2025-11-18 22:25:39 +01:00 |
|
Valentin Lobstein
|
88aadcc856
|
Add Flowise Custom MCP RCE exploit (CVE-2025-8943)
|
2025-11-18 22:03:59 +01:00 |
|
whotwagner
|
5c6b0543a4
|
Fixed a typo in taiga-module-docs
|
2025-11-18 09:59:26 +00:00 |
|
whotwagner
|
351bba0c45
|
Renamed extension for taiga-exploit-docs to .md
|
2025-11-18 09:52:06 +00:00 |
|
whotwagner
|
ba24ea0362
|
Added exploit module for unserialization vulnerability in taiga.io(CVE-2025-62368)
|
2025-11-15 22:41:01 +00:00 |
|