EIP-2026-112621

PRE-CVE

TextPattern CMS 4.8.7 - Stored Cross-Site Scripting (XSS)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-112621. PoCs published by Mert Daş.

AI-analyzed exploit summary This is a functional proof-of-concept for a stored XSS vulnerability in TextPattern CMS 4.8.7. The exploit demonstrates how an attacker can inject malicious JavaScript payloads into the 'Title' and 'Body' fields of an article, which are then stored and executed when viewed by other users.

Description

TextPattern CMS 4.8.7 - Stored Cross-Site Scripting (XSS)

Exploits (1)

exploitdb WORKING POC
by Mert Daş · textwebappsphp
https://www.exploit-db.com/exploits/49975

This is a functional proof-of-concept for a stored XSS vulnerability in TextPattern CMS 4.8.7. The exploit demonstrates how an attacker can inject malicious JavaScript payloads into the 'Title' and 'Body' fields of an article, which are then stored and executed when viewed by other users.

Classification
Working Poc 95%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: TextPattern CMS 4.8.7
Auth required
Prerequisites: Valid admin credentials for TextPattern CMS · Access to the article editing interface
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026