EIP-2026-111090

PRE-CVE

PHPJabbers Pet Listing Script 1.0 - Multiple Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-111090. PoCs published by HackXBack.

AI-analyzed exploit summary This exploit demonstrates CSRF and XSS vulnerabilities in Pet Listing Script V1.0. It includes PoC HTML forms for adding an admin user and injecting XSS payloads via type, breed, and extra fields.

Description

PHPJabbers Pet Listing Script 1.0 - Multiple Vulnerabilities

Exploits (1)

exploitdb WORKING POC
by HackXBack · htmlwebappsphp
https://www.exploit-db.com/exploits/30950

This exploit demonstrates CSRF and XSS vulnerabilities in Pet Listing Script V1.0. It includes PoC HTML forms for adding an admin user and injecting XSS payloads via type, breed, and extra fields.

Classification
Working Poc 90%
Attack Type
Xss | Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Pet Listing Script V1.0
No auth needed
Prerequisites: Victim must visit a malicious page or be tricked into submitting a form
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026