By weakness (CWE)
CWE-94: related vulnerabilities
CVEs classified under CWE-94. Understanding the weakness class helps prioritize systemic fixes over one-off patches.
136 published vulnerabilities · page 2 of 2
- CVE-2026-13557MEDIUM 4.3
A cross-site scripting (XSS) vulnerability exists in itsourcecode Online Hotel Management System version 1.0. An attacker can inject malicious scripts through the 'Name' parameter in the room management admin interface, which are then reflected back to users who interact with the affected page. This requires user interaction (such as clicking a malicious link) to trigger, but once executed, the injected code runs in the victim's browser with the same privileges as their session.
- CVE-2026-13567MEDIUM 4.3
A reflected cross-site scripting (XSS) vulnerability has been identified in code-projects Online Music Site version 1.0. The flaw exists in the feedback form handler (/Frontend/Feedback.php) and can be exploited by injecting malicious code into form fields (name, email, address, or message). When a victim visits a malicious link crafted by an attacker, the injected code executes in their browser, potentially allowing credential theft, session hijacking, or malware distribution. Public exploit code is already available, raising the attack likelihood.
- CVE-2026-14633MEDIUM 4.3
A cross-site scripting (XSS) vulnerability exists in the Ecommerce-CodeIgniter-Bootstrap project's hidden REST API endpoint at /index.php/api/product/set. An attacker can inject malicious scripts via the title or description parameters, which are then reflected back to users. This requires a user to interact with a crafted link or request, but once exploited, it allows arbitrary JavaScript execution in the victim's browser context. The vulnerability has been publicly disclosed, and the affected codebase uses a rolling release model, meaning patch deployment is version-agnostic.
- CVE-2026-14634MEDIUM 4.3
A cross-site scripting (XSS) vulnerability exists in the Ecommerce-CodeIgniter-Bootstrap project affecting the Subscribed Emails Admin Page. An attacker can manipulate the User-Agent header to inject malicious scripts that execute in the context of an administrator's browser session. The vulnerability requires user interaction (an admin must visit a page with the malicious header present) and does not allow unauthorized data access or system availability impact, but could enable account compromise or administrative action abuse. Proof-of-concept code is publicly available, elevating the practical risk despite the CVSS medium rating.
- CVE-2026-14656MEDIUM 4.3
A stored or reflected cross-site scripting (XSS) vulnerability exists in code-projects Assessment Management version 1.0, specifically in the user removal functionality at /admin/remove-user.php. An attacker can inject malicious JavaScript through the ID parameter, which executes in the browser of any admin who clicks a crafted link. This does not require the attacker to authenticate, but does require user interaction—typically clicking a malicious link. The vulnerability has been publicly disclosed, increasing exposure risk.
- CVE-2026-14704MEDIUM 4.3
A cross-site scripting (XSS) vulnerability exists in stephen-kruger bluebox through version 4.5.12. An attacker can manipulate the 'code' argument to inject malicious scripts that execute in a victim's browser. The attack requires user interaction (such as clicking a link) but can be launched remotely. Public exploits are available, increasing the risk of active exploitation.
- CVE-2026-15187MEDIUM 4.3
A prototype pollution vulnerability exists in enquirer, a Node.js package for interactive command-line prompts, affecting versions up to 2.4.1. The flaw allows an authenticated attacker to manipulate object prototypes through the question.name parameter when using the Enquirer.set method, potentially modifying application behavior. The vulnerability requires authenticated access and does not directly expose sensitive data, but could enable privilege escalation or unintended state changes within applications that rely on enquirer. Public exploit code is available.
- CVE-2026-15202MEDIUM 4.3
YzmCMS versions up to 7.5 contain a cross-site scripting (XSS) vulnerability in the header handling component that allows attackers to inject malicious scripts into web pages. The flaw exists in the `get_url` function within `/yzmphp/yzmphp.php`, where the HTTP_HOST parameter is not properly sanitized before being used. An attacker can craft a malicious link that, when clicked by a user, executes arbitrary JavaScript in their browser—potentially stealing session data, credentials, or redirecting them to malicious sites. The vulnerability requires user interaction (clicking a link) but can be exploited remotely without authentication.
- CVE-2026-1606MEDIUM 4.3
GitLab has patched a vulnerability affecting its Community Edition and Enterprise Edition that allowed authenticated users to hide content within Snippets through improper input validation. An attacker with valid GitLab credentials could exploit this to conceal code or text in a Snippet, potentially obscuring malicious or sensitive content from other users who view it. The vulnerability requires authentication and carries a CVSS score of 4.3 (MEDIUM severity), indicating moderate risk that warrants timely patching but does not represent an emergency threat.
- CVE-2026-10228LOW 3.5
A cross-site scripting (XSS) vulnerability exists in the raisulislamg4 student_management_system_by_php project. The flaw resides in the admission_form_check.php file, where user input passed through the Message parameter is not properly sanitized before being reflected in the web response. An authenticated attacker can craft malicious input that, when viewed by another user, executes arbitrary JavaScript in their browser. The vulnerability requires user interaction (clicking a malicious link) and affects only the integrity of data, not confidentiality or availability. Public exploit details are available, though the CVSS 3.5 score reflects the relatively constrained attack scenario requiring authentication and browser-based execution.
- CVE-2026-10234LOW 3.5
Mettle sendportal versions up to 3.0.1 contain a cross-site scripting (XSS) vulnerability in the Campaign Handler component. An authenticated attacker can inject malicious scripts through the content parameter in the /webview/ endpoint, potentially allowing them to steal session cookies, perform actions on behalf of users, or redirect users to malicious sites. The vulnerability requires user interaction to be effective and does not grant direct administrative access. Exploit code is publicly available, elevating practical risk despite the low CVSS score.
- CVE-2026-10244LOW 3.5
SourceCodester Pharmacy Sales and Inventory System version 1.0 contains a cross-site scripting (XSS) vulnerability in the medicine name creation function. An authenticated user can inject malicious script code through the medicine_name parameter, which executes in the context of other users' browsers. The vulnerability requires user interaction (clicking a link or visiting a page) to trigger, and an attacker must have valid login credentials to exploit it. Public exploits are now available.
- CVE-2026-10245LOW 3.5
SourceCodester Pharmacy Sales and Inventory System version 1.0 contains a cross-site scripting (XSS) vulnerability in its supplier creation functionality. An authenticated user can inject malicious code through the company name field when creating a supplier record. This code executes in the browsers of other users who view the supplier information, potentially allowing attackers to steal session tokens, redirect users to malicious sites, or perform unauthorized actions on their behalf. Public exploits for this vulnerability are already available.
- CVE-2026-10246LOW 3.5
A stored cross-site scripting (XSS) vulnerability exists in SourceCodester Pharmacy Sales and Inventory System version 1.0. An authenticated user can inject malicious scripts through the medicine presentation creation function, which are then executed in the browsers of other users who view that data. The attack requires user interaction and does not grant elevated privileges, but can be used to steal session tokens, redirect users, or perform actions on their behalf within the application.
- CVE-2026-10247LOW 3.5
A cross-site scripting (XSS) vulnerability exists in SourceCodester Pharmacy Sales and Inventory System version 1.0. An authenticated attacker can inject malicious scripts through the generic_name parameter in the create_generic_name function, which the application will then execute in users' browsers. This could allow the attacker to steal session cookies, hijack user accounts, or manipulate pharmacy data. The vulnerability requires user interaction to trigger and an authenticated account to exploit, limiting its immediate impact, but public exploit code is now available.
- CVE-2026-10567LOW 3.5
A stored cross-site scripting (XSS) vulnerability exists in 1Panel-dev CordysCRM versions up to 1.4.1. An authenticated attacker can inject malicious JavaScript into the Description field of the ModuleFormController, which will execute in the browsers of other users who view the affected module form. The vulnerability requires user interaction (viewing the crafted form) to trigger, and does not grant the attacker direct access to sensitive data or system functions. Upgrading to version 1.7.0 resolves the issue.
- CVE-2026-11520LOW 3.5
SourceCodester Inventory System version 1.0 contains a cross-site scripting (XSS) vulnerability in the header.php file that allows authenticated users to inject malicious scripts through multiple parameters. An attacker with valid credentials can craft a specially crafted request to inject JavaScript that executes in the browsers of other users, potentially stealing session data or performing unauthorized actions on their behalf. Public exploit code is available, increasing the practical risk despite the low CVSS score.
- CVE-2026-11534LOW 3.5
A cross-site scripting (XSS) vulnerability exists in imvks786's student_management_system application. The flaw allows attackers to inject malicious scripts through the name, address, or fname parameters in the /add.php file. An attacker with authenticated access can craft a malicious request that, when clicked by another user, executes arbitrary JavaScript in that user's browser. The vulnerability is publicly known, and the development team has been notified but has not yet responded with a patch.
- CVE-2026-12129LOW 3.5
CodeAstro Human Resource Management System version 1.0 contains a cross-site scripting (XSS) vulnerability in its Dashboard Interface. An attacker with login credentials can inject malicious scripts through the todo_data parameter in the /dashboard/add_tod endpoint. When another authenticated user views the affected page, the injected script executes in their browser, potentially allowing credential theft, session hijacking, or unauthorized actions performed on their behalf. The vulnerability requires user interaction—specifically, a victim must visit a page containing the malicious payload—and can only be exploited by someone with valid system access.
- CVE-2026-12130LOW 3.5
CVE-2026-12130 is a reflected cross-site scripting (XSS) vulnerability in CodeAstro Human Resource Management System version 1.0. An authenticated user can inject malicious scripts through the 'protitle' parameter on the Projects Management Page, which are then executed in the browsers of other users who view the injected content. The vulnerability requires user interaction (a victim must click a crafted link) and does not grant an attacker elevated privileges or direct data access, which limits its severity. However, it can be used to steal session cookies, redirect users, or perform actions on behalf of authenticated users within the HR system.
- CVE-2026-13504LOW 3.5
A cross-site scripting (XSS) vulnerability exists in code-projects Project Management System version 1.0 affecting the Mail Compose Page (/mail.php). An authenticated user can inject malicious scripts that execute in another user's browser when they interact with crafted email content. While the vulnerability requires login credentials and user interaction to exploit, public disclosure means attackers have access to exploitation methods.
- CVE-2026-13558LOW 3.5
CodeAstro Complaint Management System version 1.0 contains a cross-site scripting (XSS) vulnerability in its Report Handler component. An authenticated user can inject malicious script by manipulating the 'Report Title' field when adding a new report, which then executes in the browsers of other users viewing that report. Exploitation requires valid login credentials and user interaction (clicking a link or visiting a report page), but public exploit code is now available.
- CVE-2026-13570LOW 3.5
SourceCodester Inventory Management System version 1.0 contains a cross-site scripting (XSS) vulnerability in its user registration endpoint. An authenticated attacker can inject malicious code through the full_name parameter in the /api/users_handler.php file, which gets reflected in the application without proper sanitization. This allows the attacker to execute JavaScript in the browsers of other users who view the affected data, potentially stealing session tokens or performing actions on their behalf.
- CVE-2026-14752LOW 3.5
CVE-2026-14752 is a cross-site scripting (XSS) vulnerability in mjperpinosa stumasy, an open-source project using rolling releases. An authenticated attacker can manipulate the 'reference' argument in the add_definition function (found in application/PHP/objects/notes/add_into_dictionary.php) to inject malicious scripts. The vulnerability requires user interaction and authenticated access, limiting its immediate impact. Exploit code has been publicly disclosed, though the vendor has not yet responded to the early disclosure notification.
- CVE-2026-14791LOW 3.5
A cross-site scripting (XSS) vulnerability exists in Crater Invoice versions up to 6.0.6, specifically in how the application handles invoice notes. An authenticated user can inject malicious script code through the notes field, which gets executed in the browsers of other users who view that invoice. The vulnerability requires user interaction (clicking or viewing a crafted invoice) to trigger, but poses a real risk in multi-user invoicing environments where attackers may have legitimate access.
- CVE-2026-15311LOW 3.5
NousResearch hermes-agent contains a cross-site scripting (XSS) vulnerability in its Matrix Adapter component. When the MatrixAdapter processes Markdown-formatted messages and converts them to HTML, it fails to properly sanitize user-controlled input. An authenticated attacker can inject malicious scripts that execute in the context of another user's browser session, potentially stealing session tokens or performing actions on their behalf. The vulnerability requires the attacker to have valid credentials and user interaction (such as clicking a link), which limits its immediate threat scope. A fix is under review but not yet officially released.
- CVE-2026-10112LOW 2.4
CVE-2026-10112 is a stored or reflected cross-site scripting (XSS) vulnerability in the Dashboard Page component of STUDENT-MANAGEMENT-SYSTEM version 1.0. An attacker with high privileges can inject malicious scripts through the Name parameter, which are then executed in the browsers of users who view the affected page. The vulnerability requires user interaction and has a low CVSS score of 2.4, but exploitation has already been disclosed publicly.
- CVE-2026-10514LOW 2.4
A cross-site scripting (XSS) vulnerability exists in CordysCRM versions up to 1.6.2. The flaw is located in a request parameter handling component and allows attackers with administrative privileges to inject malicious scripts that execute in users' browsers. While public exploit code is available, the attack requires both high-level credentials and user interaction (such as clicking a malicious link), significantly limiting real-world risk. Upgrading to version 1.7.0 resolves the issue.
- CVE-2026-10529LOW 2.4
A cross-site scripting (XSS) vulnerability has been discovered in westboy CicadasCMS affecting the Task Scheduling Management Module. The flaw exists in the ScheduleJobController component and can be triggered by an authenticated user with elevated privileges through a specially crafted request. While the vulnerability requires administrative or high-privilege access to exploit, the presence of user interaction (rendering) combined with public availability of exploit details elevates attention. The CMS uses a rolling release model, making definitive version tracking difficult, though the affected commit hash has been identified.
- CVE-2026-11338LOW 2.4
A reflected cross-site scripting (XSS) vulnerability exists in SourceCodester Ship Ferry Ticket Reservation System version 1.0. An authenticated administrative user with high privileges can inject malicious JavaScript into the Username parameter on the user management page, which executes in the browsers of other users who view the manipulated content. The vulnerability requires user interaction and administrative access to trigger, limiting its immediate exposure but potentially enabling unauthorized account manipulation or credential theft within administrative workflows.
- CVE-2026-11434LOW 2.4
FluentCMS version 0.0.5 contains a cross-site scripting (XSS) vulnerability in its Blocks Plugin, specifically within the /admin/blocks file. An authenticated administrator with high privileges can inject malicious scripts that execute in the browsers of other users viewing the affected page. The vulnerability requires user interaction (such as clicking a link) to trigger. Public exploit code is available, though the low CVSS score reflects the requirement for high-privilege authentication and user interaction to succeed.
- CVE-2026-11468LOW 2.4
A cross-site scripting (XSS) vulnerability exists in SourceCodester Hospitals Patient Records Management System version 1.0. An authenticated administrator with high privileges can inject malicious scripts through the room_types page by manipulating the room parameter. When another user visits the affected page, the injected script executes in their browser, potentially allowing session hijacking, credential theft, or malware distribution. The vulnerability requires both administrative access to initiate the attack and user interaction (clicking a link or visiting a crafted URL) for the payload to execute. While the CVSS score is low, the healthcare context and potential for patient data exposure warrant careful attention.
- CVE-2026-11491LOW 2.4
CodeAstro Human Resource Management System version 1.0 contains a stored cross-site scripting (XSS) vulnerability in its Notice Board Management feature. An attacker with high privileges can inject malicious JavaScript into the Notice Title field, which is then executed in the browsers of other users viewing that notice. The vulnerability requires user interaction (a victim must view the affected notice) and has already been disclosed publicly with exploit code available.
- CVE-2026-12202LOW 2.4
A stored or reflected cross-site scripting (XSS) vulnerability exists in Intelliants Subrion CMS versions up to 4.0.3. The flaw resides in the Blocks Endpoint component, where improper handling of CSS class name parameters allows an attacker to inject malicious scripts. Because the vulnerability requires administrative privileges to exploit and user interaction is needed for the attack to succeed, the overall risk is low. However, the public disclosure of this issue means threat actors now have detailed information about how to craft attacks.
- CVE-2026-14655LOW 2.4
A cross-site scripting (XSS) vulnerability exists in code-projects Assessment Management version 1.0, specifically in the admin/view-users.php file. An authenticated administrator with elevated privileges can inject malicious code through the User parameter, which executes in the browsers of other users viewing the affected page. This allows an attacker to steal session tokens, redirect users, or perform actions on their behalf. Exploitation requires both high-level access and user interaction, limiting real-world attack surface.
- CVE-2026-15321LOW 2.4
MyEMS versions up to 6.4.0 contain a stored cross-site scripting (XSS) vulnerability in the Admin Backend API. The issue exists in the svg.py file's on_post function, where user-supplied data in the 'new_values' parameter is not properly sanitized before being stored or rendered. An authenticated administrator with high privileges can inject malicious scripts that will execute in the browsers of other users who interact with the affected feature. The vulnerability has a public exploit, though the low CVSS score reflects the requirement for administrative credentials and user interaction to trigger the attack.