EIP-2026-109499

PRE-CVE

mixedcms 1.0b - Local File Inclusion / Arbitrary File Upload / Authentication Bypass / File Disclosure

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-109499. PoCs published by YEnH4ckEr.

AI-analyzed exploit summary This is a vulnerability writeup for Mixed CMS 1.0, detailing multiple issues including Local File Inclusion (LFI), shell upload, authentication bypass, and file disclosure. It provides URLs and parameters to exploit these vulnerabilities but does not include executable exploit code.

Description

mixedcms 1.0b - Local File Inclusion / Arbitrary File Upload / Authentication Bypass / File Disclosure

Exploits (1)

exploitdb WRITEUP VERIFIED
by YEnH4ckEr · textwebappsphp
https://www.exploit-db.com/exploits/8510

This is a vulnerability writeup for Mixed CMS 1.0, detailing multiple issues including Local File Inclusion (LFI), shell upload, authentication bypass, and file disclosure. It provides URLs and parameters to exploit these vulnerabilities but does not include executable exploit code.

Classification
Writeup 90%
Attack Type
Lfi | Auth Bypass | Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Mixed CMS 1.0
No auth needed
Prerequisites: Access to the target web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026