CMS
Exploit Wordpress, Drupal, Joomla and others CMS
Default credentials
Default Credentialscat /opt/tools/metasploit-framework/data/wordlists/cms400net_default_userpass.txt
admin admin
builtin builtin
jedit jedit
jmember jmember
Admin2 Admin2
tbrown tbrown
jsmith jsmith
vs vs
EkExplorerUser EkExplorerUser
Explorer Explorer
member@example.com member@example.com
north north
supermember supermember
west westScanner
Awesome RCE Techniques

Nibbleblog
GetSimple
Wordpress
Discovery
Version
Log file
Fuzzing
WAF path-based bypass
Open Registration
Directory Listing enabled
Plugins and Themes
Username Enumeration



XMLRPC

WPscan
WPProbe
WPFinger
WPIntel
Nuclei Template
Login Bruteforce
With Hydra
With Kraken
Kraken - All-in-One ToolBypass 403
Bypass 403 / 401XSS to RCE
Code Execution
Themes

Metasploit
Others (not CPTS)
Leveraging Known Vulnerabilities
Theme - twentytwentyone v1.1

Plugin Vulnerabilities
WooCommerce - LFI

Buddyforms 2.7.7 - Iconv RCE
PHPTime Clock <= 1.2.2 & Time Clock Pro <= 1.1.4 - Unauthenticated (Limited) Remote Code Execution
Really Simple Security 9.0.0 – 9.1.1.1 – CVE-2024-10924 Authentication Bypass


Authenticated Contributor Remote Code Execution in Widget Options Plugin <= 4.0.7 - CVE-2024-8672
Unauthenticated Remote Code Execution - Bit File Manager version 6.0 - 6.5.5
Unauthenticated Remote Code Execution – Bricks Builder plugin <= 1.9.6
ValvePress Automatic - CVE-2024-27956 - SQLi
WordPress User Registration & Membership plugin (Free < 4.1.2, Pro < 5.1.2)
Formidable Pro plugin
SQLMAPJoomla
Discovery
Scanners
Version
Enumeration
Wordlist
Droopscan
JoomlaScan
Login Brute Force
Kraken - All-in-One ToolJoomla! Config Dist File
Database File List
Joomla! 1.6/1.7/2.5 - Privesc by creating admin account
Joomla! < 4.2.8 - Unauthenticated information disclosure - CVE-2023-23752
Code Execution



Reverse Shell


Plug In - Web Shell
Joomla < 3.9.5
Drupal
Discovery/Footprinting

Enumeration
/core/install.php accessible

Scanners
Droopescan
Drupwn

Login Brute Force
Kraken - All-in-One ToolLeveraging the PHP Filter Module
Drupal before version 8



From version 8 onwards

Uploading a Backdoored Module
Drupalgeddon
Drupalgeddon2
Drupalgeddon3

Pluck CMS
Pluck CMS 4.7.13 - File Upload Remote Code Execution (Authenticated)
Version 4.7.16
Version 4.7.18



WonderCMS
CVE-2023-41425 - XSS to RCE Unauth
Typo3
Scanners
CMS Made Simple
Umbraco
Enumeration
Umbraco - CVE-2019-18988 - RCE
Ghost CMS
Reco
Enumeration
CVE-2024-23724 - Stored XSS
CVE-2023-40028 - Arbitrary File Read
CVE-2023-32235 - Path Traversal
SPIP
Craft CMS
Enumeration
CVE-2025-32432: Craft CMS Preauth RCE
CVE-2024-56145
Kentico CMS
FoxCMS
Sitecore Experience Platform
Cache Poisoning
Backdrop CMS
Interesting Books
Interesting BooksSupport this Gitbook
Last updated



