EIP-2026-104047

PRE-CVE

PacketVideo Twonky Server 4.4.17/5.0.65 - Cross-Site Scripting / HTML Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-104047. PoCs published by Davide Canali.

AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) vulnerability in Twonky Server versions prior to 4.4.18, 5.0.66, and 5.1. It explains the vulnerability's root cause (lack of input sanitization) and provides an example exploit URL.

Description

PacketVideo Twonky Server 4.4.17/5.0.65 - Cross-Site Scripting / HTML Injection

Exploits (1)

exploitdb WRITEUP VERIFIED
by Davide Canali · textremotemultiple
https://www.exploit-db.com/exploits/34372

The provided text describes a cross-site scripting (XSS) vulnerability in Twonky Server versions prior to 4.4.18, 5.0.66, and 5.1. It explains the vulnerability's root cause (lack of input sanitization) and provides an example exploit URL.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Twonky Server < 4.4.18, 5.0.66, 5.1
No auth needed
Prerequisites: Access to a vulnerable Twonky Server instance
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026