"Trust, but verify. Unless it's a browser exploit — then just pop shells." PoC reconstructions of CVEs I've successfully reproduced.
"All PoCs are for authorized security testing & research only. Unauthorized access is a crime."
| CVE | Description | Severity | Status |
|---|---|---|---|
| CVE-2026-44900 | Stored XSS via sanitizeHtml() | 9.3 | ✅ PoC |