EIP-2026-110953

PRE-CVE

phpBB 2.0.18 - Cross-Site Scripting / Cookie Disclosure

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-110953. PoCs published by jet.

AI-analyzed exploit summary This is a functional XSS exploit for phpBB <= 2.0.18 that steals user cookies via a crafted HTML injection. The PoC includes both the malicious payload and a server-side PHP script to log stolen cookies.

Description

phpBB 2.0.18 - Cross-Site Scripting / Cookie Disclosure

Exploits (1)

exploitdb WORKING POC VERIFIED
by jet · textwebappsphp
https://www.exploit-db.com/exploits/1383

This is a functional XSS exploit for phpBB <= 2.0.18 that steals user cookies via a crafted HTML injection. The PoC includes both the malicious payload and a server-side PHP script to log stolen cookies.

Classification
Working Poc 95%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: phpBB <= 2.0.18
No auth needed
Prerequisites: Victim must visit a page with the injected payload · Attacker must host a PHP script to capture cookies
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026