EIP-2026-107465
PRE-CVEgpEasy CMS Minishop 1.5 Plugin - Persistent Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-107465. PoCs published by Carlos Mario Penagos Hollmann.
AI-analyzed exploit summary This exploit demonstrates a persistent XSS vulnerability in the gpEasy CMS Minishop 1.5 plugin. The vulnerability arises due to unsanitized user input in the 'Add Category' functionality, allowing arbitrary JavaScript execution when a user with edit rights injects malicious scripts into the 'name' field.
Description
gpEasy CMS Minishop 1.5 Plugin - Persistent Cross-Site Scripting
Exploits (1)
This exploit demonstrates a persistent XSS vulnerability in the gpEasy CMS Minishop 1.5 plugin. The vulnerability arises due to unsanitized user input in the 'Add Category' functionality, allowing arbitrary JavaScript execution when a user with edit rights injects malicious scripts into the 'name' field.