EIP-2026-106079

PRE-CVE

Commentics 2.0 - Multiple Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-106079. PoCs published by Jean Pascal Pereira.

AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in Commentics 2.0, including file deletion via path traversal, XSS via unsanitized input, and CSRF attacks to change admin credentials or add new admins. The PoC includes functional HTTP requests and forms to trigger these issues.

Description

Commentics 2.0 - Multiple Vulnerabilities

Exploits (1)

exploitdb WORKING POC
by Jean Pascal Pereira · textwebappsphp
https://www.exploit-db.com/exploits/19325

The exploit demonstrates multiple vulnerabilities in Commentics 2.0, including file deletion via path traversal, XSS via unsanitized input, and CSRF attacks to change admin credentials or add new admins. The PoC includes functional HTTP requests and forms to trigger these issues.

Classification
Working Poc 95%
Attack Type
Xss | Auth Bypass | Other
Complexity
Trivial
Reliability
Reliable
Target: Commentics 2.0
No auth needed
Prerequisites: Access to the admin interface or ability to trick an admin into visiting a malicious link
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026