SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-19922

LOW · CVSS 3.5 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-16 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The Online Shopping System 1.0 has a vulnerability in the /checkout.php file that allows for cross-site scripting (XSS) through manipulation of the 'amount_1' parameter. This flaw can be exploited remotely, potentially compromising user data and session integrity. Organizations using this system should prioritize remediation to mitigate the risk of XSS attacks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19922
Severity
LOW
CVSS
3.5
EPSS
0.20%

Original NVD Description

A security flaw has been discovered in code-projects Online Shopping System 1.0. Affected by this issue is some unknown functionality of the file /checkout.php. Performing a manipulation of the argument amount_1 results in cross site scripting. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.