EIP-2026-111309
PRE-CVEPiXie CMS 1.04 - Multiple Cross-Site Request Forgery Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-111309. PoCs published by Ali Raheem.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in PiXie CMS v1.04, allowing an attacker to add a super user or a blog post via crafted HTML forms. It also includes a method to steal admin cookies by creating a hidden blog post with malicious JavaScript.
Description
PiXie CMS 1.04 - Multiple Cross-Site Request Forgery Vulnerabilities
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Ali Raheem · htmlwebappsphp
https://www.exploit-db.com/exploits/15850
This exploit demonstrates a CSRF vulnerability in PiXie CMS v1.04, allowing an attacker to add a super user or a blog post via crafted HTML forms. It also includes a method to steal admin cookies by creating a hidden blog post with malicious JavaScript.
Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target:
PiXie CMS v1.04
No auth needed
Prerequisites:
Victim must be logged in as an admin · Attacker must trick victim into visiting a malicious page
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026