CVE-2018-11686

CRITICAL EXPLOITED NUCLEI

FlexPaper < 2.3.6 - Remote Code Execution via Publish Service

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2018-11686 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including redtimmysec, mpgn. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit targets a remote command execution vulnerability in FlexPaper PHP Publish Service <= 2.3.6. It deletes the target configuration file, uploads a webshell, and provides an interactive shell to execute commands on the compromised system.

Description

The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_config.php.

Exploits (2)

exploitdb WORKING POC
by redtimmysec · pythonwebappsphp
https://www.exploit-db.com/exploits/46528

This exploit targets a remote command execution vulnerability in FlexPaper PHP Publish Service <= 2.3.6. It deletes the target configuration file, uploads a webshell, and provides an interactive shell to execute commands on the compromised system.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: FlexPaper PHP Publish Service <= 2.3.6
No auth needed
Prerequisites: Target URL with vulnerable FlexPaper installation
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 6 stars
by mpgn · remote
https://github.com/mpgn/CVE-2018-11686

This PoC exploits CVE-2018-11686, an authentication bypass and command injection vulnerability in FlexPaper PHP Publish Service <= 2.3.6. It leverages unauthenticated access to delete config files and inject commands via the setup process.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: FlexPaper PHP Publish Service <= 2.3.6
No auth needed
Prerequisites: Target must have FlexPaper PHP Publish Service <= 2.3.6 installed and accessible
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

FlexPaper/FlowPaper 2.3.6 - Remote Code Execution
CRITICALVERIFIEDby iamnoooob,pdresearch,pszyszkowski
Shodan: title:"FlexPaper"
FOFA: title="FlexPaper"

References (2)

Core 2
Core References
Release Notes, Third Party Advisory x_refsource_misc
https://flowpaper.com/blog/
Exploit, Patch, Third Party Advisory x_refsource_misc
https://redtimmysec.wordpress.com/2019/03/07/flexpaper-remote-code-execution

Scores

CVSS v3 9.8
EPSS 0.4979
EPSS Percentile 98.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2023-11-14
CWE
CWE-20
Status published
Products (1)
flowpaper/flexpaper < 2.3.6
Published Jul 03, 2019
Tracked Since Feb 18, 2026