EIP-2026-113185
PRE-CVEWaylu CMS - '/products_xx.php' SQL Injection / HTML Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-113185. PoCs published by TheCyberNuxbie.
AI-analyzed exploit summary The provided text describes SQL injection and HTML injection vulnerabilities in Waylu CMS, detailing the attack vectors via crafted URLs. It lacks actual exploit code but provides technical details on how the vulnerabilities can be exploited.
Description
Waylu CMS - '/products_xx.php' SQL Injection / HTML Injection
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by TheCyberNuxbie · textwebappsphp
https://www.exploit-db.com/exploits/37100
The provided text describes SQL injection and HTML injection vulnerabilities in Waylu CMS, detailing the attack vectors via crafted URLs. It lacks actual exploit code but provides technical details on how the vulnerabilities can be exploited.
Classification
Writeup 90%
Attack Type
Sqli | Xss
Complexity
Trivial
Reliability
Theoretical
Target:
Waylu CMS
No auth needed
Prerequisites:
Access to the vulnerable URL endpoints
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026