EIP-2026-109598

PRE-CVE

moziloCMS 2.0 - Persistent Cross-Site Scripting (Authenticated)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-109598. PoCs published by Abdulkadir Kaya.

AI-analyzed exploit summary This exploit demonstrates a persistent XSS vulnerability in moziloCMS 2.0, where an authenticated attacker can inject malicious JavaScript into the 'Content Page' section, which executes when other users access the page. The provided payloads confirm the vulnerability by triggering alerts.

Description

moziloCMS 2.0 - Persistent Cross-Site Scripting (Authenticated)

Exploits (1)

exploitdb WORKING POC
by Abdulkadir Kaya · textwebappsphp
https://www.exploit-db.com/exploits/48781

This exploit demonstrates a persistent XSS vulnerability in moziloCMS 2.0, where an authenticated attacker can inject malicious JavaScript into the 'Content Page' section, which executes when other users access the page. The provided payloads confirm the vulnerability by triggering alerts.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: moziloCMS 2.0
Auth required
Prerequisites: Authenticated access to the admin panel
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026