PoC for CVE-2026-3891 — Unauthenticated Arbitrary File Upload leading to Remote Code Execution in Pix for WooCommerce <= 1.5.0
☆21Jul 20, 2026Updated 2 months ago
Alternatives and similar repositories for CVE-2026-3891-Pix-for-WooCommerce-Plugin-Exploit
Users that are interested in CVE-2026-3891-Pix-for-WooCommerce-Plugin-Exploit are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Burp Suite extension for cross-identity & cross-tenant access-control testing — BAC, IDOR, BOLA, and privilege escalation.☆61Jul 12, 2026Updated 2 months ago
- Fast Go-based XSS assessment toolkit☆20Mar 18, 2026Updated 6 months ago
- FortiSandbox RCE Scanner — CVE-2026-39808☆26Apr 21, 2026Updated 5 months ago
- Blind XSS SVG☆10Mar 27, 2023Updated 3 years ago
- ☆13Mar 6, 2025Updated last year
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Passive JavaScript reconnaissance for penetration testers — bridging Burp Suite traffic into structured, AST-based analysis in VSCode.☆36Feb 5, 2026Updated 7 months ago
- ☆24Jul 7, 2026Updated 2 months ago
- A bash script that extracts `shodan-query, google-query, censys-query, fofa-query, hunter-query, zoomeye-query` in nucleihub-templates.☆15Feb 17, 2026Updated 7 months ago
- FrontHunter is a tool for testing large lists of domains to identify candidates for domain fronting.☆22May 5, 2025Updated last year
- Non-destructive detector + Docker lab for wp2shell (CVE-2026-63030 REST /batch/v1 route confusion + CVE-2026-60137 author__not_in SQLi) i…☆62Jul 22, 2026Updated 2 months ago
- SSRFHunter☆18Jan 17, 2026Updated 8 months ago
- burpsuite extension to analyze javascript files using semgrep☆13Feb 3, 2025Updated last year
- A comprehensive WordPress vulnerability scanner and exploitation framework for authorized penetration testing. This tool automatically de…☆76May 21, 2026Updated 4 months ago
- Burp Suite extension + port-based highlighter: dedupes HTTP history into a live unique-request feed and color-codes attacker/victim traff…☆13Aug 14, 2026Updated last month
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- This lab is for **EDUCATIONAL PURPOSES ONLY**. Use it responsibly and only on systems you own or have explicit permission to test. Do not…☆24Feb 20, 2026Updated 7 months ago
- Nginx Rewrite CVE Scan(CVE-2026-42945 nginx-rift CVE-2026-9256)☆34May 27, 2026Updated 3 months ago
- ☆22May 7, 2026Updated 4 months ago
- Vite Arbitrary File Read Exploit☆15Jun 25, 2025Updated last year
- SelfHosted - Bug Bounty Programs | Discover new and fresh bug bounty programs across platforms. Updated frequently to always display the …☆16Nov 24, 2025Updated 9 months ago
- CVE-2026-21643☆18Mar 28, 2026Updated 5 months ago
- This repository contains all the GF-Patterns Repositories. All we have to do is just to run the given Shell File and it's Done !!☆22Jun 28, 2025Updated last year
- parse ffuf & map endpoints to wordlists☆20Feb 25, 2021Updated 5 years ago
- ☆50Feb 27, 2026Updated 6 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Detection template for CVE-2025-8110☆22Dec 11, 2025Updated 9 months ago
- Demonstrate how a signed driver can bypass defenses to deploy ransomware on Windows 11 with advanced AV and UAC evasion techniques.☆34Updated this week
- ☆41Mar 12, 2025Updated last year
- Burp Suite extension — passively detects secrets, API keys, credentials, JWTs & PII in HTTP traffic. 160+ detection rules, bulk scan, ent…☆55Aug 24, 2026Updated 3 weeks ago
- Stock vulnerable wordpress RCE poc for wp2shell.☆108Jul 18, 2026Updated 2 months ago
- Kernel Information Disclosure☆35Jan 13, 2026Updated 8 months ago
- A powerful Bash script for extracting URLs and API endpoints from HTML, JavaScript, and JSON content of web pages. Designed for security …☆18Jun 23, 2026Updated 2 months ago
- My-custom-sensitive-info-disclsure-nuclei-template☆34Jan 3, 2026Updated 8 months ago
- Passively check for XSS character encodings☆20Mar 9, 2026Updated 6 months ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Automated Recon Tool Installer☆16Jun 29, 2022Updated 4 years ago
- It serves as a practical guide for security researchers to identify and test WordPress targets effectively during bug bounty hunting.☆27Jul 19, 2026Updated 2 months ago
- CVE-2026-63030, CVE-2026-60137, wp2shell scanner☆65Jul 18, 2026Updated 2 months ago
- Burpsuite Extension for Jsmon☆26Jul 1, 2026Updated 2 months ago
- Tool for fetching all the available waybackmachine snapshot urls☆27Oct 8, 2024Updated last year
- Full and complete RCE exploit for Magento Polyshell☆30Apr 9, 2026Updated 5 months ago
- NextSSRF — CVE-2026-44578 Scanner & Exploit ║ ║ Next.js WebSocket Upgrade Handler SSRF☆77May 15, 2026Updated 4 months ago