The Custom 404 Pro WordPress plugin before version 3.7.3 fails to properly escape certain URLs before outputting them in HTML attributes. This allows an attacker to inject malicious scripts via crafted URLs, resulting in a reflected cross-site scripting (XSS) vulnerability.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a comprehensive collection of 100 proof-of-concept (POC) exploits and vulnerability analysis files, primarily in text format, targeting a wide range of enterprise software, web applications, and security appliances. The exploits cover various vulnerability types, including remote code execution (RCE), arbitrary file upload, file read, SQL injection, authentication bypass, information disclosure, and privilege escalation. The structure consists of individual files, each dedicated to a specific vulnerability, often including HTTP request samples, payloads, affected versions, and sometimes Python, Go, or Bash scripts for automated exploitation or detection. Notable vulnerabilities include: - Adobe ColdFusion deserialization RCE (CVE-2023-29300) - SPIP CMS RCE via deserialization (CVE-2023-27372) - MinIO cluster information disclosure (CVE-2023-28432) - Multiple arbitrary file upload and RCE vulnerabilities in Hikvision, Dahua, Yonyou, and other enterprise platforms - SQL injection and authentication bypasses in various OA (Office Automation) and ERP systems - Metabase and Panabit RCE (CVE-2023-38646) - KubePi JWT bypass (CVE-2023-22463) - Generic default credentials and information disclosure issues The repository provides actionable intelligence for penetration testers and defenders, including fingerprintable endpoints (URLs, API paths, file locations), exploit payloads, and affected product/version details. The exploits are operational, with many providing direct code execution or system compromise if the target is vulnerable. No evidence of framework integration (e.g., Metasploit) is present; the repository is a curated set of standalone POCs and scripts.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.