Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!
Cybersecurity Classified by Officially
Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!
Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!
This release has something for everyone: scanner modules, payloads, and exploits. This release’s scanners cover Drupal, PanOS, WordPress, and SCADA; this release’s exploits cover Tenable, Flowise, CheckPoint, Langflow, Ruby, and SPIP.
Forgejo Arbitrary File Read via Org-mode Include
Pull request: #21778 contributed by jvoisin
Path: gather/forgejo_orgmode_fileread_cve_2026_59774
Description: Adds module targeting CVE-2026-59774, an arbitrary file read in Forgejo 7.0 through 15.0.5 and 16.0.0–16.0.1.
Wordpress Planyo Online Reservation System Arbitrary File Read (CVE-2026-3576)
Authors: Balachandar Gowrisankar and sinn3r [email protected]
Pull request: #21769 contributed by anirbala98
Path: gather/wp_planyo_lfi_cve_2026_3576
Description: This adds a module for, CVE-2026-3576, a local file inclusion vulnerability via server side request forgery in WordPress's Planyo Online Reservation System plugin (versions < 3.1). The plugin's AJAX proxy ulap.php does not validate the scheme of URLs supplied to it. This allows unauthenticated attackers to supply file:// URLs to ulap.php and retrieve any arbitrary local file contents from the target.
Concrete CMS Unauthenticated File Usage Disclosure
Pull request: #21695 contributed by zoomdbz
Path: scanner/http/concrete_cms_file_usage_disclosure
Description: Adds an auxiliary scanner module for CVE-2026-6826: Concrete CMS 9.x before 9.5.1 exposes the file usage dialog controller at /ccm/system/dialogs/file/usage/<fID> without a view permission check.
Drupal Core PostgreSQL EntityQuery SQL Injection
Pull request: #21765 contributed by JohannesLks
Path: scanner/http/drupal_pgsql_entityquery_sqli
This is an extract. The publication continues at the source.
Read the original at the source: https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-payloads-exploits-scanners
Officially imported this from Rapid7’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Rapid7 — imported from official source
- Official source
- https://blog.rapid7.com/rss/ RSS
- Imported
- September 18, 2026 11:35
- Versions
- 1 recorded
- Identity
blt526bc61553e28979