Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-109544. PoCs published by n0tch.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) and Full Path Disclosure (FPD) vulnerability in Modx CMS version 2.2.0. The LFI allows reading arbitrary files, while the FPD reveals the full path of the application on the server.
Description
ModX 2.2.0 - Multiple Vulnerabilities
Exploits (1)
exploitdb
WORKING POC
by n0tch · textwebappsphp
https://www.exploit-db.com/exploits/18593
This exploit demonstrates a Local File Inclusion (LFI) and Full Path Disclosure (FPD) vulnerability in Modx CMS version 2.2.0. The LFI allows reading arbitrary files, while the FPD reveals the full path of the application on the server.
Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target:
Modx CMS 2.2.0
No auth needed
Prerequisites:
access to the target URL
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026