EIP-2026-107222
PRE-CVEFree Simple CMS 1.0 - Multiple Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-107222. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in Free Simple CMS 1.0, including XSS via unsanitized URL input and GET parameters, and LFI via directory traversal. The PoC URLs are functional and directly exploit the vulnerabilities.
Description
Free Simple CMS 1.0 - Multiple Vulnerabilities
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/17403
The exploit demonstrates multiple vulnerabilities in Free Simple CMS 1.0, including XSS via unsanitized URL input and GET parameters, and LFI via directory traversal. The PoC URLs are functional and directly exploit the vulnerabilities.
Classification
Working Poc 95%
Attack Type
Xss | Info Leak
Complexity
Trivial
Reliability
Reliable
Target:
Free Simple CMS 1.0
No auth needed
Prerequisites:
register_globals enabled · target running Free Simple CMS 1.0
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026