EIP-2026-108916

PRE-CVE

Joomla! Plugin NoNumber Framework - Multiple Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-108916. PoCs published by jdc.

AI-analyzed exploit summary The document describes multiple vulnerabilities in the NoNumber Framework Joomla! Plugin, including Local File Inclusion (LFI) and Open Proxy/Open cURL/Shell Upload flaws. It provides technical details on how to exploit these vulnerabilities, such as manipulating the 'nn_qp' parameter and using cURL options to inject malicious code.

Description

Joomla! Plugin NoNumber Framework - Multiple Vulnerabilities

Exploits (1)

exploitdb WRITEUP
by jdc · textwebappsphp
https://www.exploit-db.com/exploits/17995

The document describes multiple vulnerabilities in the NoNumber Framework Joomla! Plugin, including Local File Inclusion (LFI) and Open Proxy/Open cURL/Shell Upload flaws. It provides technical details on how to exploit these vulnerabilities, such as manipulating the 'nn_qp' parameter and using cURL options to inject malicious code.

Classification
Writeup 90%
Attack Type
Lfi | Rce
Complexity
Moderate
Reliability
Reliable
Target: NoNumber Framework Joomla! Plugin (versions before 17 October 2011 patch)
No auth needed
Prerequisites: Access to the target Joomla! site with the vulnerable plugin installed
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026