EIP-2026-107915

PRE-CVE

Invision Power Board (IP.Board) 3.0 - Multiple HTML Injection / Information Disclosure Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-107915. PoCs published by brain[pillow].

AI-analyzed exploit summary This exploit demonstrates an HTML injection vulnerability in Invision Power Board, allowing arbitrary script execution in the context of the affected site. The provided URI and payload showcase how an attacker can bypass sanitization to execute JavaScript code.

Description

Invision Power Board (IP.Board) 3.0 - Multiple HTML Injection / Information Disclosure Vulnerabilities

Exploits (1)

exploitdb WORKING POC VERIFIED
by brain[pillow] · textwebappsphp
https://www.exploit-db.com/exploits/32960

This exploit demonstrates an HTML injection vulnerability in Invision Power Board, allowing arbitrary script execution in the context of the affected site. The provided URI and payload showcase how an attacker can bypass sanitization to execute JavaScript code.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Invision Power Board 3.0.0b5
No auth needed
Prerequisites: Access to a vulnerable Invision Power Board instance
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026