EIP-2026-109544

PRE-CVE

ModX 2.2.0 - Multiple Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-109544. PoCs published by n0tch.

AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) and Full Path Disclosure (FPD) vulnerability in Modx CMS version 2.2.0. The LFI allows reading arbitrary files, while the FPD reveals the full path of the application on the server.

Description

ModX 2.2.0 - Multiple Vulnerabilities

Exploits (1)

exploitdb WORKING POC
by n0tch · textwebappsphp
https://www.exploit-db.com/exploits/18593

This exploit demonstrates a Local File Inclusion (LFI) and Full Path Disclosure (FPD) vulnerability in Modx CMS version 2.2.0. The LFI allows reading arbitrary files, while the FPD reveals the full path of the application on the server.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Modx CMS 2.2.0
No auth needed
Prerequisites: access to the target URL
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026