Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-109055. PoCs published by Emilio Pinna.
AI-analyzed exploit summary The document details XSS and CSRF vulnerabilities in KusabaX <= 0.9.1, including technical analysis of vulnerable code in 'animation.php' and 'manage_page.php', along with proof-of-concept exploit examples.
Description
kusaba x 0.9.1 - Multiple Vulnerabilities
Exploits (1)
exploitdb
WRITEUP
by Emilio Pinna · textwebappsphp
https://www.exploit-db.com/exploits/17221
The document details XSS and CSRF vulnerabilities in KusabaX <= 0.9.1, including technical analysis of vulnerable code in 'animation.php' and 'manage_page.php', along with proof-of-concept exploit examples.
Classification
Writeup 95%
Attack Type
Xss | Sqli
Complexity
Trivial
Reliability
Reliable
Target:
KusabaX <= 0.9.1
No auth needed
Prerequisites:
Access to vulnerable KusabaX instance · User interaction for XSS · Admin session for CSRF
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026