EIP-2026-107148

PRE-CVE

FlexCMS 3.2.1 - Persistent Cross-Site Scripting

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-107148. PoCs published by storm.

AI-analyzed exploit summary The writeup describes a persistent XSS vulnerability in FLEXCMS 3.2.1, where an attacker can inject malicious code into the 'Display name' field in the user profile, affecting all users viewing the 'Users Online' menu.

Description

FlexCMS 3.2.1 - Persistent Cross-Site Scripting

Exploits (1)

exploitdb WRITEUP VERIFIED
by storm · textwebappsphp
https://www.exploit-db.com/exploits/18608

The writeup describes a persistent XSS vulnerability in FLEXCMS 3.2.1, where an attacker can inject malicious code into the 'Display name' field in the user profile, affecting all users viewing the 'Users Online' menu.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: FLEXCMS 3.2.1
Auth required
Prerequisites: User account with edit profile permissions
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026