EIP-2026-104688

PRE-CVE

XenForo 2 - CSS Loader Denial of Service

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-104688. PoCs published by LockedByte.

AI-analyzed exploit summary This exploit is a Denial of Service (DoS) tool targeting XenForo 2's CSS loader by sending repeated HTTP requests with a large number of CSS file parameters. It uses multiple threads to overwhelm the target server.

Description

XenForo 2 - CSS Loader Denial of Service

Exploits (1)

exploitdb WORKING POC
by LockedByte · pythondosphp
https://www.exploit-db.com/exploits/44336

This exploit is a Denial of Service (DoS) tool targeting XenForo 2's CSS loader by sending repeated HTTP requests with a large number of CSS file parameters. It uses multiple threads to overwhelm the target server.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: XenForo 2
No auth needed
Prerequisites: Target URL with accessible CSS loader endpoint
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026