EIP-2026-112719

PRE-CVE

TinyWebGallery 1.8.3 - Cross-Site Scripting / Local File Inclusion

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-112719. PoCs published by Yam Mesicka.

AI-analyzed exploit summary The document describes multiple vulnerabilities in TinyWebGallery 1.8.3, including XSS and directory traversal. It provides examples of malicious input for parameters like 'sview', 'tview', 'dir', and 'item' to exploit these issues.

Description

TinyWebGallery 1.8.3 - Cross-Site Scripting / Local File Inclusion

Exploits (1)

exploitdb WRITEUP VERIFIED
by Yam Mesicka · textwebappsphp
https://www.exploit-db.com/exploits/35298

The document describes multiple vulnerabilities in TinyWebGallery 1.8.3, including XSS and directory traversal. It provides examples of malicious input for parameters like 'sview', 'tview', 'dir', and 'item' to exploit these issues.

Classification
Writeup 90%
Attack Type
Xss | Info Leak
Complexity
Trivial
Reliability
Reliable
Target: TinyWebGallery 1.8.3
No auth needed
Prerequisites: Access to the target web application
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026