EIP-2026-109020

PRE-CVE

Kleophatra CMS 0.1.1 - 'module' Cross-Site Scripting

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-109020. PoCs published by anT!-Tr0J4n.

AI-analyzed exploit summary The exploit demonstrates a reflected XSS vulnerability in Kleophatra CMS 0.1.1 by injecting malicious JavaScript via the 'module' parameter. The PoC includes example URLs that trigger arbitrary script execution in the context of the affected site.

Description

Kleophatra CMS 0.1.1 - 'module' Cross-Site Scripting

Exploits (1)

exploitdb WORKING POC VERIFIED
by anT!-Tr0J4n · textwebappsphp
https://www.exploit-db.com/exploits/33853

The exploit demonstrates a reflected XSS vulnerability in Kleophatra CMS 0.1.1 by injecting malicious JavaScript via the 'module' parameter. The PoC includes example URLs that trigger arbitrary script execution in the context of the affected site.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Kleophatra CMS 0.1.1
No auth needed
Prerequisites: Access to a vulnerable Kleophatra CMS instance · User interaction to click a crafted URL
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026