EIP-2026-109734

PRE-CVE

MyBB smilie Module < 1.8.11 - 'pathfolder' Directory Traversal

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-109734. PoCs published by Zhiyang Zeng.

AI-analyzed exploit summary The proof of concept describes a directory traversal vulnerability in MyBB versions prior to 1.8.11, where the 'pathfolder' parameter in the admin panel's smilies configuration module is not properly sanitized, allowing attackers to traverse directories. The vulnerability was fixed in version 1.8.11.

Description

MyBB smilie Module < 1.8.11 - 'pathfolder' Directory Traversal

Exploits (1)

exploitdb WRITEUP VERIFIED
by Zhiyang Zeng · textwebappsphp
https://www.exploit-db.com/exploits/41862

The proof of concept describes a directory traversal vulnerability in MyBB versions prior to 1.8.11, where the 'pathfolder' parameter in the admin panel's smilies configuration module is not properly sanitized, allowing attackers to traverse directories. The vulnerability was fixed in version 1.8.11.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: MyBB < 1.8.11
Auth required
Prerequisites: Admin access to the MyBB panel
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026