EIP-2026-105961

PRE-CVE

CMS buzz - Cross-Site Scripting / Password Change / HTML Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-105961. PoCs published by ThE g0bL!N.

AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in CMS Buzz, including XSS, HTML injection, and unauthorized password changes via direct URL manipulation. It provides functional PoC steps and code snippets for cookie theft and session hijacking.

Description

CMS buzz - Cross-Site Scripting / Password Change / HTML Injection

Exploits (1)

exploitdb WORKING POC VERIFIED
by ThE g0bL!N · textwebappsphp
https://www.exploit-db.com/exploits/8984

The exploit demonstrates multiple vulnerabilities in CMS Buzz, including XSS, HTML injection, and unauthorized password changes via direct URL manipulation. It provides functional PoC steps and code snippets for cookie theft and session hijacking.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: CMS Buzz
Auth required
Prerequisites: User registration on the target site · Admin interaction for cookie theft
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026