EIP-2026-105769

PRE-CVE

Cells Blog 3.3 - Reflected Cross-Site Scripting / Blind SQLite Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-105769. PoCs published by vinicius777.

AI-analyzed exploit summary The exploit demonstrates a reflected XSS vulnerability via the 'msg' parameter in 'errmsg.php' and a blind SQLite injection via the 'pcid' parameter in 'user.php' in Cells Blog v3.3. The PoC includes functional payloads and vulnerable code snippets.

Description

Cells Blog 3.3 - Reflected Cross-Site Scripting / Blind SQLite Injection

Exploits (1)

exploitdb WORKING POC
by vinicius777 · textwebappsphp
https://www.exploit-db.com/exploits/31146

The exploit demonstrates a reflected XSS vulnerability via the 'msg' parameter in 'errmsg.php' and a blind SQLite injection via the 'pcid' parameter in 'user.php' in Cells Blog v3.3. The PoC includes functional payloads and vulnerable code snippets.

Classification
Working Poc 95%
Attack Type
Xss | Sqli
Complexity
Trivial
Reliability
Reliable
Target: Cells Blog v3.3
No auth needed
Prerequisites: Access to the target web application
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026