[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":3,"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":10,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":16,"all-banners":23,"vulnerability-29460":95},["Island",4],{"key":5,"params":6,"result":8},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":7},"{}",{"head":9},{},["Island",11],{"key":12,"params":13,"result":14},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":7},{"head":15},{},["Island",17],{"key":18,"params":19,"result":21},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":20},"{\"text-color\":\"gray\"}",{"head":22},{},[24,35,43,48,56,62,68,74,80,86],{"title":25,"slug":26,"text":27,"link":28,"external":29,"targets":30,"cta":32,"variant":33,"campaign_id":34},"wp2shell (Vuln DB homepage)","wp2shell-vuln-db","Emergency CVE response: detection & exploitation now available for *wp2shell*, the critical WP RCE chain","https://pentest-tools.com/vulnerabilities-exploits/wordpress-core-69-701-pre-auth-blind-sql-injection-batch-route-confusion_29451",false,[31],"/vulnerabilities-exploits/","See CVE details","secondary","wp2shell",{"title":36,"slug":37,"text":38,"link":39,"external":29,"targets":40,"cta":42,"variant":33,"campaign_id":34},"wp2shell (CVE page - exploitation)","wp2shell-cve-page-exploit","Validate wp2shell exposure & mitigation! Detect with any plan. Exploit with Pentest Suite.","https://pentest-tools.com/pricing",[41],"/vulnerabilities-exploits/wp2shell-wordpress-core-690-694-and-700-701-pre-auth-batch-route-confusion-leading-to-sql-injection_29452","Explore plans",{"title":44,"slug":45,"text":38,"link":39,"external":29,"targets":46,"cta":42,"variant":33,"campaign_id":34},"wp2shell (CVE page - detection)","wp2shell-cve-page",[47],"/vulnerabilities-exploits/wordpress-core-69-701-pre-auth-blind-sql-injection-batch-route-confusion_29451",{"title":49,"slug":50,"text":51,"link":52,"external":29,"targets":53,"cta":55,"variant":33,"campaign_id":50},"Compliance - Page Launch - Homepage","compliance-pages-launch","Turn confirmed vulnerabilities into evidence your auditor accepts. Testing requirements for DORA, NIS2, SOC 2, ISO 27001, and CRA.","https://pentest-tools.com/usage/compliance",[54],"/","Get compliance evidence",{"title":57,"slug":58,"text":59,"link":52,"external":29,"targets":60,"cta":55,"variant":33,"campaign_id":50},"Compliance - Page Launch - Sniper","compliance-pages-launch-sniper","Five compliance framework pages now reference Sniper as the source of validated exploitability evidence. See them all.",[61],"/exploit-helpers/sniper",{"title":63,"slug":64,"text":65,"link":52,"external":29,"targets":66,"cta":55,"variant":33,"campaign_id":50},"Compliance - Page Launch - Network Scanner","compliance-pages-launch-network-scanner","Scheduled scans are the spine of every compliance framework. Are you audit-ready?",[67],"/network-vulnerability-scanning/network-security-scanner-online",{"title":69,"slug":70,"text":71,"link":52,"external":29,"targets":72,"cta":55,"variant":33,"campaign_id":50},"Compliance - Page Launch - Website Scanner","compliance-pages-launch-website-scanner","Authenticated web-app scans show up in SOC 2, NIS2, and CRA Annex I. See why this is crucial for the business.",[73],"/website-vulnerability-scanning/website-scanner",{"title":75,"slug":76,"text":77,"link":52,"external":29,"targets":78,"cta":55,"variant":33,"campaign_id":50},"Compliance - Page Launch - Integrations","compliance-pages-launch-integrations","Vanta, Jira, webhooks - they all route back to DORA, NIS2, SOC 2, ISO 27001, CRA. See why this is crucial for the business.",[79],"/features/integrations",{"title":81,"slug":82,"text":83,"link":52,"external":29,"targets":84,"cta":55,"variant":33,"campaign_id":50},"Compliance - Page Launch - Advanced Pentest Reporting","compliance-pages-launch-reporting","Editable DOCX. Immutable PDF. JSON for the GRC tool. See why these formats are on every auditor's checklist.",[85],"/features/pentest-reporting",{"title":87,"slug":88,"text":89,"link":90,"external":91,"targets":92,"cta":94,"variant":33,"campaign_id":88},"Office Hours #10 - DEF CON and Black Hat","office-hours-10","[Live Office Hours, Wed Aug 26] What DEF CON and Black Hat told us about AI pentesting","https://zoom.us/webinar/register/5117815316917/WN_m3AgyHW2TxSFuHr1J5mQZA",true,[54,93],"/insights/ai-pentesting-survey","Save your spot",{"id":96,"detectable_with":97,"vuln_details":104,"vuln_id":119,"name":120,"published":121,"updated":105},29460,{"tool":98,"engine":101},{"id":99,"name":100},1,"Network Scanner",{"id":102,"name":103},2,"Nuclei",{"id":96,"codename":105,"description":105,"severity":106,"risk_description":107,"public_description":108,"public_recommendation":109,"recommendation":105,"references":110,"cvssv3":113,"epss_score":114,"epss_percentile":115,"cve":116,"in_cisa_catalog":29,"date":118,"software_type":105,"vendor":105,"product":105,"ptt_exploit_capabilities":105},null,"high","Attackers can read sensitive secret_key files across directories, potentially compromising system security.","Langflow \u003C 1.7.1 contains a path traversal caused by insufficient filtering of folder_name and file_name parameters in download_profile_picture endpoint, letting attackers read secret_key across directories, exploit requires crafted request.","Update to version 1.7.1 or later.",[111,112],"https://github.com/langflow-ai/langflow/security/advisories/GHSA-ph9w-r52h-28p7","https://nvd.nist.gov/vuln/detail/CVE-2026-33497",7.5,0.19584,0.97172,[117],"CVE-2026-33497","2026-03-24T00:00:00Z","NETSCAN-NUCLEI-CVE-CVE-2026-33497","Langflow \u003C 1.7.0 - Path Traversal","2026-07-22T00:00:00Z"]