Changelog

These are the latest updates we've made to our platform. If you have any questions about any of the updates you see below, please feel free to contact us!

Date

November 2025

  1. Exploitation for CVE-2020-36847 (Remote Code Execution in Wordpress Simple File List plugin)

    Copy link to “Exploitation for CVE-2020-36847 (Remote Code Execution in Wordpress Simple File List plugin)”

    We’ve added an exclusive exploit for CVE-2020-36847 (WordPress Simple File List - Unauthenticated RCE) into Sniper, so you can move from suspicion to proof of rce in a controlled, ethical way.

    Why it matters
    CVE-2020-36847 is a critical, unauthenticated Remote Code Execution vulnerability in the Simple File List plugin for WordPress. Versions up to and including 4.2.2 let an attacker upload a php payload disguised as an image, then use the plugin’s rename function to change the extension to .php and run it on the server. The result is full arbitrary code execution with no login required, a fast path to site takeover, database access, credential theft, and lateral movement if the host can reach internal services. Updating to 4.2.3 or later fixes the issue.

    How to use

    Validate in Sniper → capture RCE evidence safely → patch the plugin (4.2.3+) → re-run Sniper to confirm remediation and rule out other exposed sites using the same plugin.

  2. SQLi detectors uses more payloads in all custom cookies and has reduced false positives

    Copy link to “SQLi detectors uses more payloads in all custom cookies and has reduced false positives”

    We’ve just rolled out an update to Website Scanner’s active SQLi detection: it now injects payloads into all custom, non-standard cookies and cuts down false positives by skipping cookies that were already checked. This means broader coverage on real-world apps that stash input in quirky cookie names, without noisy duplicates in your results.

    Why it matters
    SQL injection still shows up in places scanners can miss, especially in custom cookies used for state, feature flags, or tracking. By extending payload injection to every custom cookie, Website Scanner can uncover SQLi paths that previously hid outside “standard” cookie patterns. At the same time, the improved logic avoids re-testing cookies it has already validated, which reduces repeat hits and lowers the chance of false positives. Net effect: more real findings, less triage fatigue.

    How to use

    Run Website Scanner as usual → review any confirmed SQLi findings → validate further with SQLi Exploiter if needed → fix and re-scan to confirm remediation and ensure no custom-cookie vectors remain exposed.

  3. Detection for CVE-2025-55315 (HTTP Request Smuggling in ASP.NET Core)

    Copy link to “Detection for CVE-2025-55315 (HTTP Request Smuggling in ASP.NET Core)”

    We’ve just added detection for CVE-2025-55315 (HTTP Request Smuggling in ASP.NET Core) into Network Scanner, so you can quickly flag affected kestrel-backed apps during your perimeter and internal scans.

    Why it matters

    CVE-2025-55315 is a critical request smuggling vulnerability in ASP.NET Core’s kestrel server. It stems from inconsistent parsing of HTTP requests, which can let an attacker “hide” one request inside another and slip past intermediate components or app logic. In real terms, that can mean bypassing authentication or authorization checks, hijacking sessions, leaking data, or causing unexpected request routing inside your app stack. Microsoft rated it critical with a CVSS of 9.9 and shipped fixes in the october 2025 security updates across supported .net / asp.net core versions.

    How to use

    Scan with Network Scanner → patch / upgrade the affected asp.net core runtime or app packages → re-scan to verify fixes and confirm no exposed instances remain.

  4. Detection & exploitation for the React Native Community CLI development server RCE (CVE-2025-11953)

    Copy link to “Detection & exploitation for the React Native Community CLI development server RCE (CVE-2025-11953)”

    We’ve just added an exclusive exploit for CVE-2025-11953 (React Native Community CLI development server) into Sniper and paired it with Network Scanner detection, so you can spot and confirm this RCE in one workflow.

    Why it matters
    CVE-2025-11953 is a critical, unauthenticated Remote Code Execution issue in the Metro development server started by the react native community cli. The server exposes an endpoint vulnerable to os command injection, letting an external attacker run arbitrary commands on the host if the dev server is reachable over the network. With a CVSS of 9.8, the impact is full compromise of the dev server environment and whatever credentials, source code, or internal network access it can reach.

    How to use

    Detect with the Network Scanner → validate in Sniper → re-scan to confirm remediation and catch leftover exposure across other hosts running the Metro dev server.

  5. Detection & exploitation for the Oracle RCE (CVE-2025-61882)

    Copy link to “Detection & exploitation for the Oracle RCE (CVE-2025-61882)”

    We’ve just added an exclusive exploit for CVE-2025-61882 (Oracle E-Business Suite BI Publisher RCE) into Sniper and paired it with Network Scanner detection - available exclusively to Pentest-Tools.com customers.

    Why it matters
    This vulnerability is a critical, unauthenticated, pre-auth Remote Code Execution in Oracle EBS (versions 12.2.3 → 12.2.14). It has a CVSS of ~9.8 and is actively exploited in the wild. It allows remote attackers to run arbitrary code and potentially take over the Concurrent Processing subsystem, often containing high-value ERP, payroll, and financial data. This module gives you fast detection and zero-guesswork validation in one place.

    How to use

    detect with the Network Scanner → validate in Sniper → re-scan to confirm remediation and rule out residual exposure across multiple assets.

  6. Added CL.0 request smuggling detection in our HTTP desync attacks active detector

    Copy link to “Added CL.0 request smuggling detection in our HTTP desync attacks active detector”

    Inspired by James Kettle's article and to keep on top on latest research, we introduced the new CL.0 Request Smuggler in our HTTP Request Smuggling detector from Website Vulnerability Scanner. It is automatically enabled inside the detector and it helps uncover more request smuggling attacks.

October 2025

  1. You asked, we listened. You can now download more reports at once directly from the Reports page. Instead of saving each report individually, you can select multiple generated reports and download them together as a single .zip archive.

    Why it matters
    Handling multiple assessments or projects often means managing many reports. This update helps you work faster and stay organized by reducing repetitive actions and keeping related files together.

    How to use

    1. Go to the Reports page in your account.

    2. Select all the reports you want to download.

    3. Click Download. You’ll receive a .zip file containing all the selected reports.

    Key benefits

    1. Save time by downloading multiple reports simultaneously

    2. Keep related files neatly grouped

    3. Simplify sharing and storage of report archives

    Download multiple reports
  2. Exclusive exploit for Magento SessionReaper (CVE-2025-54236)

    Copy link to “Exclusive exploit for Magento SessionReaper (CVE-2025-54236)”

    We’ve just added an exclusive exploit for CVE-2025-54236 (Magento & Adobe Commerce SessionReaper) into Sniper and paired it with Network Scanner detection - available exclusively to Pentest-Tools.com customers.

    Why it matters
    SessionReaper is a low-complexity, remote, unauthenticated vector — prime for mass exploitation. This release gives you fast detection and zero-guesswork validation in one place.

    How to use

    detect with the Network Scanner → validate in Sniper → re-scan to confirm remediation and rule out residual exposure across multiple assets.

    Exclusive exploit for Magento & Adobe Commerce SessionReaper - detect & validate CVE-2025-54236

    Want to learn the story behind the exploit? Dip into the detailed write-up on the blog!

  3. Detection for CVE-2025-26399 in SolarWinds Web Help Desk

    Copy link to “Detection for CVE-2025-26399 in SolarWinds Web Help Desk”

    Why it matters
    CVE-2025-26399 is a critical remote code execution vulnerability that could allow attackers to run arbitrary commands on vulnerable SolarWinds Web Help Desk instances. Early detection is essential to prevent potential exploitation and maintain the security of your infrastructure.

    How to use
    Run a scan with Network Scanner against your targets as usual. The tool will automatically check for signs of CVE-2025-26399 exposure and flag any vulnerable hosts.

    Key benefits

    • Detect vulnerable SolarWinds Web Help Desk instances affected by CVE-2025-26399

    • Gain visibility into potential exposure before attackers can exploit it

    • Strengthen your security posture with timely vulnerability insights

  4. NEW: Vanta integration just got an upgrade!

    Copy link to “NEW: Vanta integration just got an upgrade!”

    Keeping compliance evidence current shouldn’t be a manual job.

    That’s why now you can sync validated vulnerabilities and scheduled scan results directly into Vanta - automatically.

    Here’s what’s new:

    🎯 32 Vanta tests + 2 controls mapped - your findings now tie directly to relevant Vanta compliance checks.

    🎯 Daily sync at 05:00 UTC - stay continuously audit-ready without uploading reports manually.

    🎯 Smart filtering - manual findings are included, while informational or closed findings are excluded to keep data clean.

    🎯 Scheduled scans automatically synced to Compliance → Documents → Vulnerability Scan (up to 5 per recurrence).

    🎯 Available on all paid plans.

    👉 If you’ve used the integration before, please re-link your Vanta account to grant permissions for vulnerability syncing.

    See how it works in this short demo:

    From scans to automated compliance evidence - Vanta Integration
  5. Detection for CVE-2025-10035 in Fortra GoAnywhere MFT

    Copy link to “Detection for CVE-2025-10035 in Fortra GoAnywhere MFT”

    Why it matters
    CVE-2025-10035 is a remote code execution vulnerability that allows attackers to execute arbitrary commands on vulnerable Fortra GoAnywhere MFT instances. Detecting affected systems early is crucial to mitigate risks and protect sensitive data.

    How to use
    Scan your targets using Network Scanner. The tool automatically checks whether CVE-2025-10035 affects any detected Fortra GoAnywhere MFT installations and highlights vulnerable hosts in the results.

    Key benefits

    • Identify Fortra GoAnywhere MFT instances vulnerable to CVE-2025-10035

    • Reduce exposure to active exploitation attempts

    • Support faster remediation through precise detection

  6. Launch internal scans directly in Azure

    Copy link to “Launch internal scans directly in Azure”

    Now you can securely access your private Azure infrastructure with our fresh internal network scanning (VPN agent) capability — so you can run internal vulnerability scans and pentests in minutes.

    Key benefits:

    🎯 Complete visibility – Extend your vulnerability assessments beyond the perimeter to cover internal servers, endpoints, and services in Azure.

    🎯 Secure by design – All scans are tunneled through the VPN Agent with no inbound firewall changes required.

    🎯 Unified view – Run the same Pentest-Tools.com tools for both external and internal testing, managed from a single interface.

    🎯 Fast deployment – Launch in minutes and start scanning immediately, without manual setup.

    💡 Ideal for: security teams covering hybrid environments and consultants managing client cloud networks.

September 2025

  1. Detect SonicWall - Improper access control now

    Copy link to “Detect SonicWall - Improper access control now”

    We keep enhancing the Network Scanner coverage so you can find critical issues before attackers do.

    The latest? This critical vulnerability in SonicWall SonicOS - CVE-2024-40766 (Unauthorized access) allows an unauthenticated remote attacker to gain access as admin on the management console.

    PRO TIP: run targeted CVE scans to validate patching, identify remaining attack surface, and generate evidence for stakeholders.

  2. 🎯 Prove exploitability faster = new Sniper modules

    Copy link to “🎯 Prove exploitability faster = new Sniper modules”

    We added 4 fresh, high-value exploit modules to Sniper: Auto-Exploiter, our proprietary offensive tool, so you can confirm risk quickly and produce stronger evidence for remediation:

    Fortinet FortiSIEM - CVE-2025-25256 (RCE)
    Sniper will give you proof of exploit for this critical RCE vulnerability in FortiSIEM deployments.

    Microsoft SharePoint - CVE-2025-53771 (Auth Bypass) & CVE-2025-49704 (RCE)
    Sniper now includes modules to test both authentication bypass and RCE paths in SharePoint so you can demonstrate end-to-end impact.

    FreePBX — CVE-2025-57819 (Auth Bypass → SQLi → RCE)
    A chained failure: Sniper can validate the authentication bypass that leads to SQL injection and potential RCE in affected FreePBX installs.

    OpenSSH — CVE-2018-15473 (Username enumeration)
    We added a module to automate proof of username enumeration on OpenSSH services (useful in pentests and red-team enumeration phases).

    Why this helps: consultants get fast, reproducible PoCs for client reports; internal teams get quick validation that prioritizes remediation of exploitable paths.

    Remember: if Sniper can exploit it, our Network Scanner can detect it!

  3. NEW: Burp Suite extension for pentesters

    Copy link to “NEW: Burp Suite extension for pentesters”

    Manual reporting slowing you down? 

    Our new Burp Suite extension lets you send selected Audit Issues directly to your Pentest-Tools.com workspace- no copy-paste needed.

    It’s built for pentesters who want clean, consistent findings that are ready to report - faster.

    See how it works:

    From Burp to report - Integration with Burp Suite Professional

August 2025

  1. Take control of web app auth check and findings

    Copy link to “Take control of web app auth check and findings”

    Fresh improvements to our proprietary Website Scanner let you handle authentication and findings with less hassle and more clarity:

    Record auth flows with Chrome – We’ve moved to Chrome Developer Tools to record and configure logins faster and with more reliability. Start here.

    Re-enabled Check Authentication  – Test your credentials upfront and see a screenshot of a successful login, so you know it works.

    Spot outdated server software clearly – The scanner creates a separate finding for each vulnerable technology instead of lumping them together, so you can act on what matters.

    Product interface jquery findings image

  2. Prioritize more accurately with EPSS scoring

    Copy link to “Prioritize more accurately with EPSS scoring”

    We’ve expanded support for the Exploit Prediction Scoring System (EPSS) to help you quickly assess which vulnerabilities are most likely to be exploited:

    For the Website Scanner – Findings now show the CVE name and EPSS score right at the top, so you immediately know which ones attackers are most likely to exploit.

    For the WordPress & Drupal Scanners – Findings now include EPSS data and are better organized with CVE name, score, and percentile highlighted.

    WP-seopress plugin findings image

  3. Your scan results are now easier to work with:

    Collapse findings – Hide or expand findings with a single click for cleaner navigation.

    View all statuses – Findings with any status (not just Open) now appear in their own tab.

    Classification in headers – CVSS, EPSS, CISA KEV, and Confidence (Certain/Uncertain) are now at the top of each finding.

    Grouped findings via API – Use the new group_findings param on /findings to pull data grouped exactly like in the dashboard.

  4. We’ve added even more improvements that make asset and findings management more efficient:

    Multiple AWS regions – Import assets across multiple regions (default region config) without adding separate integrations.

    Asset descriptions everywhere – Asset descriptions now show in Scans and Findings (including manual findings) for easier identification.

July 2025

  1. Detect ToolShell (CVE-2025-53770) now!

    Copy link to “Detect ToolShell (CVE-2025-53770) now!”

    Patching is only half the job — validating your mitigations is what ensures your SharePoint infrastructure is actually secure.

    The Network Vulnerability Scanner now provides fast, targeted detection for this unauthenticated critical RCE vulnerability (CVE-2025-53770, CVSSv3 9.8):

    ✅ Instantly scan SharePoint servers using a single-CVE scan

    ✅ Confirm whether patches were effective

    ✅ Get detailed, evidence-backed findings to report confidently and prioritize remediation where it matters most.