master
Updates docs to reflect new default prompt
Updates msf5 as well
activemq jolokia exploit
replace bold options with h3
Fix AVideo lab documentation: update file editing instructions
sample output to scenarios conversion in docs
Add doc and make minor changes
Apply suggestions from code review
Made all changes as requested
Update documentation/modules/exploit/multi/http/churchcrm_db_restore_rce.md
Removing default version in the Dockerfile
module doc standardizations
Modified documentation
Removed frozen string comment from the top to fix build.. Note that exploit does not work if you remove the 'find' option
Updates docs, adds payload cleanup, removes time delay
drupageddon docs
Update doc and remove auth check
Fix documentation inconsistency: update ports for Flowise 3.0.1 (3005) and add Basic Auth service example
Add Flowise RCE exploits (CVE-2025-59528, CVE-2025-8943) with shared mixin, documentation, and Docker Compose setup
remove and check for instruction text
Refactor: Use inherited SSL option from HttpClient instead of HTTPSSL
Fix docs
use local theme payload only for api_key action
fix install lines
Updated module with CVE info and patched version
plugin version parsing and check logic improvement, msftidy & rubocop compliant
Add Grav CMS Twig SSTI Sandbox Bypass RCE Exploit Module (CVE-2025-66294)
spelling fixes on docs
Add documentation
Fixed typos and errors in documentation
Apply review feedback and sync docs with FILENAME change
Update exploit to improve stability
Update documentation/modules/exploit/multi/http/lighthouse_studio_unauth_rce_CVE_2025_34300.md
Clarify file-based session storage requirements and exploit limitations
undo some spelling fixes when upstream has those issues
Fix: Bootstrap cycle tables and update lab documentation
Add MSF module for EDB 6768
Add Monsta FTP downloadFile RCE (CVE-2025-34299)
module options to options
more libs for moodle and teacher priv esc to rce module
typo
Fix: Guard opcache_reset with function_exists and update documentation
Update documentation/modules/exploit/multi/http/oracle_ebs_cve_2025_61882_exploit_rce.md
vulnerable application h1 to h2
Add: exploits/multi/http/os_cmd_exec
Update oscommerce_installer_unauth_code_exec.md
Clean up some of the module's documentation
Don't be lazy and spell out "introduction" in docs
Update react2shell module: Add Waku framework support
Add configurable JAVA_GADGET_CHAIN option to Shiro module
Finishing touches
remove SMB_SRVPORT as an option. It must allways be 445 so the user cannot change it. We print a message to inform the user this port is intended to be in use so that the SMB server is not compleatly opaque.
update doc
Fix: Fallback check to Detected when plugin version unavailable
add docker lab deploy guide into docs
Refactoring taiga-exploit and docs
fixed msftidy errors and added documentation
Move totaljs cms module and doc
doc cleanup
code review changes from @msutovsky-r7
Update Web-Check documentation with docker-compose.yml setup instructions
Add exploit module for WordPress ACF Extended CVE-2025-13486 unauthenticated RCE
Fix WordPress lab permissions in documentation
spelling
use CamelCase advanced options and honor AutoCheck overrides, randomize forged metadata and use framework HTTP defaults, link credentials and vulnerabilities to the WordPress service, tighten nonce parsing and refresh module documentation
more wp catch themes doc and error handling
add session_created, fix typo
Refactor create_admin_user to handle errors internally and remove custom.ini from documentation
fix docker port
Updated doc after checking msftidy_docs
Fixes documentation header
wp_popular_posts_rce
Tweak whitespacing in the docs for the renderer
Small tweaks
Apply suggestion from @msutovsky-r7