EIP-2026-112115

PRE-CVE

Simple Machines Forum (SMF) 1.1.8 - 'avatar' Remote PHP File Execute

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-112115. PoCs published by JosS.

AI-analyzed exploit summary This exploit leverages a remote PHP file execution vulnerability in Simple Machines Forum (SMF) <= 1.1.8 by allowing an attacker to set a malicious PHP file as their avatar. When other users view the topic, the PHP file is executed, leading to information theft or other malicious actions.

Description

Simple Machines Forum (SMF) 1.1.8 - 'avatar' Remote PHP File Execute

Exploits (1)

exploitdb WORKING POC VERIFIED
by JosS · textwebappsphp
https://www.exploit-db.com/exploits/11905

This exploit leverages a remote PHP file execution vulnerability in Simple Machines Forum (SMF) <= 1.1.8 by allowing an attacker to set a malicious PHP file as their avatar. When other users view the topic, the PHP file is executed, leading to information theft or other malicious actions.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Simple Machines Forum <= 1.1.8
Auth required
Prerequisites: Authenticated user account on the forum · Ability to upload a remote avatar · Victim must visit the topic
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026