EIP-2026-114410

PRE-CVE

Xataface WebAuction and Xataface Librarian DB - Multiple Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-114410. PoCs published by SecPod Research.

AI-analyzed exploit summary This exploit demonstrates multiple vulnerabilities in Xataface WebAuction and Xataface Librarian DB, including SQL injection, XSS, and local file inclusion. The PoC provides specific URLs to trigger these vulnerabilities.

Description

Xataface WebAuction and Xataface Librarian DB - Multiple Vulnerabilities

Exploits (1)

exploitdb WORKING POC
by SecPod Research · textwebappsphp
https://www.exploit-db.com/exploits/17813

This exploit demonstrates multiple vulnerabilities in Xataface WebAuction and Xataface Librarian DB, including SQL injection, XSS, and local file inclusion. The PoC provides specific URLs to trigger these vulnerabilities.

Classification
Working Poc 90%
Attack Type
Sqli | Xss | Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Xataface WebAuction v0.3.6 and prior, Xataface Librarian DB v0.2 and prior
No auth needed
Prerequisites: Network access to the target application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026