EIP-2026-106051

PRE-CVE

CodoForum 3.4 - Persistent Cross-Site Scripting

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-106051. PoCs published by Ahmed Sherif.

AI-analyzed exploit summary This is a technical writeup detailing a stored XSS vulnerability in Codoforum v3.4, where improper input sanitization in the reply and search functionalities allows execution of arbitrary JavaScript. The author provides clear reproduction steps and context but does not include functional exploit code.

Description

CodoForum 3.4 - Persistent Cross-Site Scripting

Exploits (1)

exploitdb WRITEUP VERIFIED
by Ahmed Sherif · textwebappsphp
https://www.exploit-db.com/exploits/40015

This is a technical writeup detailing a stored XSS vulnerability in Codoforum v3.4, where improper input sanitization in the reply and search functionalities allows execution of arbitrary JavaScript. The author provides clear reproduction steps and context but does not include functional exploit code.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Codoforum v3.4
Auth required
Prerequisites: Valid user account on the target Codoforum instance
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026