EIP-2026-107670

PRE-CVE

HTMLy Version v2.9.6 - Stored XSS

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-107670. PoCs published by tmrswrr.

AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in HTMLy CMS version 2.9.6 by injecting malicious JavaScript into the 'Blog title' field in the admin configuration panel. The payload triggers an alert dialog upon rendering the compromised page.

Description

HTMLy Version v2.9.6 - Stored XSS

Exploits (1)

exploitdb WORKING POC
by tmrswrr · textwebappsphp
https://www.exploit-db.com/exploits/51979

This exploit demonstrates a stored XSS vulnerability in HTMLy CMS version 2.9.6 by injecting malicious JavaScript into the 'Blog title' field in the admin configuration panel. The payload triggers an alert dialog upon rendering the compromised page.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: HTMLy CMS v2.9.6
Auth required
Prerequisites: Admin access to the HTMLy CMS panel
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026