MEDIUM
code-projects Social Networking Site Alert home.php cross site scripting
Published Mar 27, 2026
5.1
MEDIUMCVSS 4.0
EPSS 0.33%
Description
A vulnerability was identified in code-projects Social Networking Site 1.0. The impacted element is an unknown function of the file /home.php of the component Alert Handler. The manipulation of the argument content leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Affected products
-
Affected
- 1.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Code-Projects | Social Networking Site | unknown | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (6)
- https://code-projects.org/ product
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-16760 Advisory
- https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/Stored%20Cross-Site%20Scripting%20(XSS)%20in%20PHP%20Social%20Networking%20Site.md exploit
- https://vuldb.com/?ctiid.353856 signaturepermissions-required
- https://vuldb.com/?id.353856 vdb-entrytechnical-description
- https://vuldb.com/?submit.777815 third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://code-projects.org/ | product | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-16760 | Advisory | |
| https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/Stored%20Cross-Site%20Scripting%20(XSS)%20in%20PHP%20Social%20Networking%20Site.md | exploit | |
| https://vuldb.com/?ctiid.353856 | signaturepermissions-required | |
| https://vuldb.com/?id.353856 | vdb-entrytechnical-description | |
| https://vuldb.com/?submit.777815 | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Mar 27, 2026
Updated Mar 31, 2026
Reserved Mar 27, 2026
Link CVE-2026-4969
CISA Vulnrichment
Updated Mar 31, 2026
Red Hat
No data
GitHub
No data