[codeb0ss] - Omnipotent Forums.
1.5K subscribers
80 photos
62 files
47 links
Educational, research, and awareness content only. Committed to ethical security practices, responsible disclosure, and lawful use. No abuse, misuse, or illegal activity.
Download Telegram
[codeb0ss] - Omnipotent Forums.
Photo
Gitea_CVE-2026-27771.zip
441 KB
https://thehackernews.com/2026/05/gitea-vulnerability-exposes-private.html

https://horizon3.ai/attack-research/vulnerabilities/cve-2026-27771/

https://orca.security/resources/blog/gitea-container-registry-vulnerability/


Fofa : app="Gitea" - (245,703 Records)

Shodan : http.html:"Gitea"

Proofs are posted in the comments,
For any problems, or to purchase VIP access and features, please contact: @uncodeboss


This content is shared strictly for authorized testing, educational,
and research purposes only. It is not intended for malicious use. All techniques, tools,
or information provided are meant to demonstrate security concepts and to raise awareness in a controlled and legal environment.
Please do not remove or flag this content, as it is shared responsibly for learning and academic purposes.
👏32
[codeb0ss] - Omnipotent Forums.
Photo
CVE-2026-42647_Wordpress-JoomSport.zip
435.1 KB
https://nvd.nist.gov/vuln/detail/CVE-2026-42647

https://patchstack.com/database/wordpress/plugin/joomsport-sports-league-results-management/vulnerability/wordpress-joomsport-plugin-5-7-7-sql-injection-vulnerability

https://pentest-tools.com/vulnerabilities-exploits/joomsport-577-sql-injection_29349


Fofa : body="wp-content/plugins/joomsport-sports-league-results-management" && (body="joomsport-sports-league-results-management" && body="joomsport")


Shodan : http.html:"wp-content/plugins/joomsport-sports-league-results-management" && http.html:"joomsport-sports-league-results-management" && http.html:"joomsport"

Enjoy;
6
{VIP} CVE-2026-48907] - Joomla JCE editor extension (<=v2.9.99.5) - Unauthenticated Remote-Code-Execution.

https://cvefeed.io/vuln/detail/CVE-2026-48907

Proof: In the Comment.

Our VIP/Premium Guests can get access to using this PoC/EXP.
🥰21
One of our older software has been released for archival purposes only.
4
advanced_ssh_executor.zip
446.6 KB
A new and advanced software that automatically and mass/bulk scans the sshs,
scans the type, version, company, etc.

Enjoy;
3👏2
[codeb0ss] - Omnipotent Forums.
Photo
Wordpress-CVE-2026-8502_LearnPress.zip
435.7 KB
https://www.cve.org/CVERecord?id=CVE-2026-8502

- post_password (plaintext)
- post_content (full courses)
- post_title (hidden courses)
- post_status (draft/private)
- post_author (user IDs)



Fofa : body="/wp-content/plugins/learnpress/" && body="learnpress" - (50,000 - 50K) Records.

Shodan : http.html:"/wp-content/plugins/learnpress/assets/css/learnpress.css"

Censys : services.http.response.body: "/wp-content/plugins/learnpress/assets/css/learnpress.css"


Enjoy;
👍62
PrivateVuln_CpanelGetEMAIL.zip
387.8 KB
This is a special Cpanel Vuln discovered by our team, it still works and is the best.

It takes the site email and is very specially used for bigbounty work,etc

Auto Scan/Mass > Expl0it

Just enter your cpanel list and it will do its job.

Enjoy;
👏31
[codeb0ss] - Omnipotent Forums.
Photo
Wordpress_CVE-2026-3018.zip
434 KB
https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/newsletters-lite/newsletters-413-unauthenticated-sql-injection-via-wpmlsubscriber-id-parameter


Shodan :
http.html:/wp-content/plugins/newsletters-lite/
http.html:wp-mailinglist

Fofa :
body="/wp-content/plugins/newsletters-lite/"
body="wp-mailinglist"
body="Newsletters" && header="WordPress"
body="newsletters-lite" && body="subscriber_id"

Enjoy;
3👏3
[codeb0ss] - Omnipotent Forums.
Photo
Advanced_WebshellExecutorv2.0.0.0.zip
1.3 MB
WebshellExecutor - v2.0.0.0

Advanced Software To Scan Webshells With The Best Features. For SEO Webshells/SEO Companies.

Important: We have made some great updates and now includes the best type of backdoors to get webshell as soon as possible and we have added many other ideas that are useful for users and now faster and we have done a lot of work in it.

Please contact us for any suggestions or questions, thank you
@uncodeboss .

This content is shared strictly for authorized testing, educational,
and research purposes only. It is not intended for malicious use. All techniques, tools,
or information provided are meant to demonstrate security concepts and to raise awareness in a controlled and legal environment.
Please do not remove or flag this content, as it is shared responsibly for learning and academic purposes.
👏31