EIP-2026-107938
PRE-CVEInvision Power Top Site List < 2.0 Alpha 3 - SQL Injection (PoC)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-107938. PoCs published by GulfTech Security.
AI-analyzed exploit summary This is a technical writeup detailing an SQL injection vulnerability in Invision Power Top Site List <= 2.0 Alpha 3 via the 'offset' parameter. The analysis includes the vulnerable query, error output, and vendor response.
Description
Invision Power Top Site List < 2.0 Alpha 3 - SQL Injection (PoC)
Exploits (1)
exploitdb
WRITEUP
by GulfTech Security · textwebappsphp
https://www.exploit-db.com/exploits/43789
This is a technical writeup detailing an SQL injection vulnerability in Invision Power Top Site List <= 2.0 Alpha 3 via the 'offset' parameter. The analysis includes the vulnerable query, error output, and vendor response.
Classification
Writeup 90%
Attack Type
Sqli
Complexity
Moderate
Reliability
Theoretical
Target:
Invision Power Top Site List <= 2.0 Alpha 3
No auth needed
Prerequisites:
Access to the vulnerable endpoint
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026