CVE-2026-7222
A vulnerability was determined in code-projects Coaching Management System 1.0. Affected by this vulnerability is an unknown functionality o
CVSS
3.5
Bajo
EPSS
0.2%
p14
KEV
—
Exploit Today
4
0-100
Publicado: 28 abr 2026 · Última mod.: 24 jul 2026 · CWE-79 · CWE-94
0.2%EPSS · 30 días0.2%
2026-07-282026-08-24
A vulnerability was determined in code-projects Coaching Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /cims/modules/student/complaint.php of the component Complaint Form Page. This manipulation of the argument Complaint causes cross site scripting. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-782827.1 ALT—
——0Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.9hCVE-2026-782647.1 ALT—
——0Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.8hCVE-2026-782637.1 ALT—
——0Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.8hCVE-2026-325567.1 ALT—
——0Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.9hCVE-2026-524909.8 CRÍ—
——0An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c8hCVE-2026-715036.1 MED—
——0Dolibarr before 24.0.0 contains a reflected cross-site scripting vulnerability in the extra fields administration template where the type request parameter is echoed without JavaScript-context encoding into an inline script block and no Content-Security-Policy header is emitted. An unauthenticated attacker can cause an authenticated administrator to open a crafted URL to execute arbitrary JavaScript in that session and create a persistent administrator account.1d