CVE-2026-105173
A flaw has been found in code-projects Human Resource Management 1.0. This affects an unknown part of the file /humanresourcemanagementsyste
CVSS
3.5
Bajo
EPSS
—
KEV
—
Exploit Today
0
0-100
Publicado: 5 oct 2026 · Última mod.: 5 oct 2026 · CWE-79 · CWE-94
Sin historial EPSS suficiente todavía.
A flaw has been found in code-projects Human Resource Management 1.0. This affects an unknown part of the file /humanresourcemanagementsystem/src/store/EventStore.php of the component Event Creation. Executing a manipulation of the argument eventSubject can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used.
- code-projects.orghttps://code-projects.org/
- github.comhttps://github.com/ahmad-masa100/CVEsmasa100/blob/main/Stored%20Cross-Site%20Scripting%20(XSS)%20in%20Human%20Resource%20Management%20System%20in%20PHP.md
- vuldb.comhttps://vuldb.com/cve/CVE-2026-105173
- vuldb.comhttps://vuldb.com/submit/970488
- vuldb.comhttps://vuldb.com/vuln/413405
- vuldb.comhttps://vuldb.com/vuln/413405/cti
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-1052264.7 MED—
———A security flaw has been discovered in osCommerce osCommerce2 up to 2.3.4.1. This vulnerability affects the function include of the file admin/newsletters.php of the component Newsletter Management. Performing a manipulation of the argument module results in code injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.4hCVE-2026-1052254.3 MED—
———A vulnerability was identified in osCommerce osCommerce2 up to 2.3.4.1. This affects the function include of the file includes/classes/payment.php of the component Payment Page. Such manipulation of the argument MODULE_PAYMENT_INSTALLED leads to code injection. The attack can be executed remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.4hCVE-2026-1051883.5 BAJ—
———A vulnerability was found in code-projects Human Resource Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /views/admin/liveEventHistory.php of the component Live Event History. The manipulation of the argument eventSubject results in cross site scripting. The attack may be launched remotely. The exploit has been made public and could be used.4hCVE-2026-1052207.8 ALT—
——0Twine 2 desktop through 2.12.0 contains a cross-site scripting vulnerability in importStories() that executes markup from imported story files in the editor window. Attackers can craft a story file whose script calls the twineElectron openWithScratchFile IPC bridge to write and open a .bat file, executing code as the user.10hCVE-2026-1052245.4 MED—
——0YesWiki before 4.6.7 contains a cross-site scripting vulnerability in the Bazar valeur action that allows page editors to inject script by rendering unescaped HTML fetched from a remote URL. Attackers can point tools/bazar/actions/valeur.php at a controlled server returning BAZ_fiche_titre markup with an img onerror handler, executing script in every viewer's browser.17hCVE-2026-1050898.7 ALT—
——0WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 URL. The value is rendered unescaped in YouPHPFlix2 templates and channel playlists, letting attackers break out of onclick strings or iframe src attributes to execute JavaScript in victims' browsers.17h