EIP-2026-114628

PRE-CVE

Zimplit CMS 3.0 - Local File Inclusion / Arbitrary File Upload

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-114628. PoCs published by KedAns-Dz.

AI-analyzed exploit summary This exploit demonstrates multiple vulnerabilities in Zimplit CMS v3.0, including arbitrary file upload, local file inclusion (LFI), and HTML file manipulation. The code provides functional PoC for uploading a malicious PHP shell and executing commands on the target system.

Description

Zimplit CMS 3.0 - Local File Inclusion / Arbitrary File Upload

Exploits (1)

exploitdb WORKING POC VERIFIED
by KedAns-Dz · phpwebappsphp
https://www.exploit-db.com/exploits/37398

This exploit demonstrates multiple vulnerabilities in Zimplit CMS v3.0, including arbitrary file upload, local file inclusion (LFI), and HTML file manipulation. The code provides functional PoC for uploading a malicious PHP shell and executing commands on the target system.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Zimplit CMS v3.0
No auth needed
Prerequisites: Network access to the target Zimplit CMS instance · PHP environment to run the exploit script
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026