EIP-2026-114533

PRE-CVE

yMonda Thread-IT 1.6 - Multiple HTML Injections

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-114533. PoCs published by Bahaa Naamneh.

AI-analyzed exploit summary The provided text describes an HTML injection vulnerability in yMonda Thread-IT, specifically in the 'Topic Title', 'Name', and 'Message' fields due to insufficient input sanitization. It includes example payloads demonstrating how an attacker could inject malicious scripts to execute arbitrary HTML/JS code in a user's browser.

Description

yMonda Thread-IT 1.6 - Multiple HTML Injections

Exploits (1)

exploitdb WRITEUP VERIFIED
by Bahaa Naamneh · textwebappsphp
https://www.exploit-db.com/exploits/23175

The provided text describes an HTML injection vulnerability in yMonda Thread-IT, specifically in the 'Topic Title', 'Name', and 'Message' fields due to insufficient input sanitization. It includes example payloads demonstrating how an attacker could inject malicious scripts to execute arbitrary HTML/JS code in a user's browser.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: yMonda Thread-IT version 1.6 and prior
No auth needed
Prerequisites: Access to input fields in Thread-IT (e.g., topic title, name, message)
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026