<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
  <url><loc>https://r0.xyz/</loc></url>
  <url><loc>https://r0.xyz/cat/cve</loc></url>
  <url><loc>https://r0.xyz/cat/exploit</loc></url>
  <url><loc>https://r0.xyz/cat/post</loc></url>
  <url><loc>https://r0.xyz/posts/veramo-data-store-orm-sql-injection</loc><lastmod>2026-05-17T12:22:47.449Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/cve-2023-41283-qts-5-1-x-quts-hero-h5-1-x-qutscloud-5-x-os-command-injection</loc><lastmod>2026-05-14T17:14:04.457Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/cve-2023-41282-qts-5-1-x-quts-hero-h5-1-x-qutscloud-5-x-os-command-injection</loc><lastmod>2026-05-14T17:14:10.427Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/cve-2023-39297-qts-5-1-x-4-5-x-quts-hero-h5-1-x-h4-5-x-qutscloud-5-x-os-command-injection</loc><lastmod>2026-05-14T17:14:01.194Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/cve-2023-41281-qts-5-1-x-quts-hero-h5-1-x-qutscloud-5-x-os-command-injection</loc><lastmod>2026-05-14T17:14:08.000Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/cve-2023-39303-qts-5-1-x-quts-hero-h5-1-x-qutscloud-5-x-improper-authentication</loc><lastmod>2026-05-14T17:14:13.078Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/cve-2023-39302-qts-5-1-x-quts-hero-h5-1-x-qutscloud-5-x-os-command-injection</loc><lastmod>2026-05-14T17:14:06.193Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/cve-2023-39294-qts-5-1-x-quts-hero-h5-1-x-os-command-injection</loc><lastmod>2026-05-14T19:05:09.342Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/remedy-invitational-challenge-writeup</loc><lastmod>2026-05-14T16:09:53.337Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/cve-2023-41285-qnap-qumagie-2-1-4-sql-injection</loc><lastmod>2026-05-14T15:59:17.231Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/cve-2023-41284-qnap-qumagie-2-1-4-sql-injection</loc><lastmod>2026-05-14T15:59:35.576Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/cve-2023-39295-qnap-qumagie-2-1-3-os-command-injection</loc><lastmod>2026-05-14T15:59:49.121Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/cve-2023-2338-pimcore-sql-injection-in-assetcontroller</loc><lastmod>2026-05-14T15:57:22.749Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/cve-2023-2336-pimcore-path-traversal-in-asset-import-from-server-option</loc><lastmod>2026-05-14T15:57:41.599Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/cve-2023-29506-xwiki-rxss-with-authenticate-endpoints</loc><lastmod>2026-05-14T15:58:02.639Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/cve-2022-46391-awstats-hostinfo-reflected-xss</loc><lastmod>2026-05-14T15:58:16.259Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/cve-2022-45152-moodle-blind-ssrf-in-lti-provider-library</loc><lastmod>2026-05-14T15:58:44.145Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/cve-2022-3967-vestacp-func-main-sh-argument-injection</loc><lastmod>2026-05-14T15:56:33.633Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/cve-2022-35651-moodle-stored-xss-and-blind-ssrf-possible-via-scorm-track</loc><lastmod>2026-05-14T15:56:12.338Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/vestacp-multiple-vulnerabilities-2</loc><lastmod>2026-05-14T16:10:09.547Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/vestacp-multiple-vulnerabilities</loc><lastmod>2026-05-14T16:10:12.807Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/cve-2022-24977-impresscms-path-traversal-to-pre-auth-rce-2</loc><lastmod>2026-05-14T15:52:43.541Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/cve-2022-24977-impresscms-path-traversal-to-pre-auth-rce</loc><lastmod>2026-05-14T15:53:00.818Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/impresscms-unauthenticated-code-execution</loc><lastmod>2026-05-14T17:59:45.097Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/cve-2020-36474-vanilla-ssrf</loc><lastmod>2026-05-14T15:54:59.693Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/hitcon-ctf-2021-metamon-verse-writeup</loc><lastmod>2026-05-14T18:09:51.168Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/moodle-blind-sql-injection-via-mnet-authentication</loc><lastmod>2026-05-14T16:13:48.083Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/moodle-stored-xss-and-blind-ssrf-possible-via-feedback-answer-text</loc><lastmod>2026-05-14T16:16:33.088Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/vanilla-ssrf-via-media-scrape-api-through-dns-rebinding</loc><lastmod>2026-05-14T17:28:33.997Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/roxy-wi-through-5-2-2-0-pre-auth-rce</loc><lastmod>2026-05-14T16:16:02.247Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/cve-2021-38169-roxy-wi-through-5-2-2-0-allows-authenticated-cmd-injection</loc><lastmod>2026-05-14T15:50:39.362Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/cve-2021-38168-roxy-wi-through-5-2-2-0-allows-authenticated-sql-injection</loc><lastmod>2026-05-14T15:50:57.125Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/cve-2021-38167-roxy-wi-through-5-2-2-0-allows-unauthenticated-sql-injection</loc><lastmod>2026-05-14T15:51:16.363Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/cve-2021-36396-moodle-blind-ssrf-possible-against-curl-blocked-hosts</loc><lastmod>2026-05-14T15:51:32.371Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/cve-2021-32474-moodle-blind-sql-injection-via-mnet-authentication</loc><lastmod>2026-05-14T15:51:50.378Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/3kctf-2021-babyrtos-exploit</loc><lastmod>2021-05-17T12:48:33.000Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/3kctf-2021-telnet-exploit</loc><lastmod>2021-05-17T12:48:09.000Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/3kctf-2021-ppaste-writeup</loc><lastmod>2026-05-14T18:08:50.906Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/cve-2021-20280-moodle-stored-xss-and-blind-ssrf-via-feedback-answer-text</loc><lastmod>2026-05-14T15:52:13.800Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/h1ctf-hackyholidays-walkthrough</loc><lastmod>2026-05-14T18:08:59.415Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/icectf-2020-krouter-writeup</loc><lastmod>2026-05-14T18:09:06.928Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/cve-2020-36474-safecurl-3-3-vanilla-forum-0-9-2-dns-rebind-to-ssrf</loc><lastmod>2026-05-14T16:44:05.960Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/cve-2020-26134-live-helper-chat-before-3-44v-stored-xss</loc><lastmod>2026-05-14T15:50:04.940Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/3kctf-2020-babym1ps-exploit</loc><lastmod>2020-07-25T23:35:55.000Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/3kctf-2020-glitch-exploit</loc><lastmod>2020-07-25T23:35:06.000Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/3kctf-2020-glitch-writeup</loc><lastmod>2026-05-14T18:09:13.994Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/3kctf-2020-babym1ps-writeup</loc><lastmod>2026-05-14T18:09:10.611Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/3kctf-2020-reporter-writeup</loc><lastmod>2026-05-14T18:09:17.451Z</lastmod></url>
  <url><loc>https://r0.xyz/posts/cve-2020-12720-vbulletin-rce</loc><lastmod>2026-05-14T15:47:12.042Z</lastmod></url>
</urlset>
