EIP-2026-107148
PRE-CVEFlexCMS 3.2.1 - Persistent Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-107148. PoCs published by storm.
AI-analyzed exploit summary The writeup describes a persistent XSS vulnerability in FLEXCMS 3.2.1, where an attacker can inject malicious code into the 'Display name' field in the user profile, affecting all users viewing the 'Users Online' menu.
Description
FlexCMS 3.2.1 - Persistent Cross-Site Scripting
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by storm · textwebappsphp
https://www.exploit-db.com/exploits/18608
The writeup describes a persistent XSS vulnerability in FLEXCMS 3.2.1, where an attacker can inject malicious code into the 'Display name' field in the user profile, affecting all users viewing the 'Users Online' menu.
Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target:
FLEXCMS 3.2.1
Auth required
Prerequisites:
User account with edit profile permissions
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026