CMS Detection and Exploitation suite - Scan WordPress, Joomla, Drupal and over 180 other CMSs
-
Updated
Jul 17, 2026 - Python
CMS Detection and Exploitation suite - Scan WordPress, Joomla, Drupal and over 180 other CMSs
CVE-2026-48909 PoC
The Joomla MCP Server facilitates interaction between AI assistants (like Claude) and Joomla websites through the Joomla Web Services API. It provides tools to manage articles, including retrieving, creating, updating, and deleting content, as well as managing article states.
A Python script to create an administrator account on Joomla! 1.6/1.7/2.5 using a privilege escalation vulnerability
A PoC exploit for CVE-2023-23752 - Joomla Improper Access Check in Versions 4.0.0 through 4.2.7
Unauthenticated RCE PoC for CVE-2026-48908 — SP Page Builder for Joomla (≤ 6.6.1): arbitrary file upload via asset.uploadCustomIcon. Self-cleaning, token-guarded. Authorized testing only.
CVE-2026-57827 — RSFiles! Joomla Component Unauthenticated File Upload RCE. Split-controller upload bypass. CVSS 9.8 | CWE-434 | com_rsfiles < 1.17.12
starscream is a brute force tool used to try to log into various web services, such as cPanels, Webmail, SSH, Wordpress, WHM, SMTP, Plesk, FTP, Joomla, and Opencart by using a combination of email and password.
A proof of concept for Joomla's CVE-2015-8562 vulnerability (Object Injection RCE)
Bulk scanner + get config from CVE-2023-23752
CVE-2026-56290 - Mass Exploit for Joomla Com_pagebuilderck component (Unrestricted File Upload → RCE). Multi-threaded, automatic CSRF bypass, PHP shell uploader.
Read-only vulnerability scanner for CVE-2026-49049 — Helix3 Joomla plugin unauthenticated AJAX handler
CVE-2026-48907 – Joomla JCE Unauthenticated Remote Code Execution (RCE)
Unauthenticated Arbitrary File/Folder Deletion in Joomla Helix Ultimate (JoomShaper) <= 2.2.6 — CVE-2026-57830
To associate your repository with the joomla topic, visit your repo's landing page and select "manage topics."