EIP-2026-112621
PRE-CVETextPattern CMS 4.8.7 - Stored Cross-Site Scripting (XSS)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-112621. PoCs published by Mert Daş.
AI-analyzed exploit summary This is a functional proof-of-concept for a stored XSS vulnerability in TextPattern CMS 4.8.7. The exploit demonstrates how an attacker can inject malicious JavaScript payloads into the 'Title' and 'Body' fields of an article, which are then stored and executed when viewed by other users.
Description
TextPattern CMS 4.8.7 - Stored Cross-Site Scripting (XSS)
Exploits (1)
This is a functional proof-of-concept for a stored XSS vulnerability in TextPattern CMS 4.8.7. The exploit demonstrates how an attacker can inject malicious JavaScript payloads into the 'Title' and 'Body' fields of an article, which are then stored and executed when viewed by other users.