SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-82554

MEDIUM · CVSS 4.3 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-30 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A cross-site scripting vulnerability exists in the SourceCodester Queue Management System 1.0, specifically within the /api/add_customer.php file, allowing remote attackers to manipulate the "Name" argument. This flaw could lead to the execution of malicious scripts in the context of a user's session, potentially compromising sensitive information. Organizations using this system should prioritize patching this vulnerability to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82554
Severity
MEDIUM
CVSS
4.3
EPSS
0.27%

Original NVD Description

A flaw has been found in SourceCodester Queue Management System 1.0. This affects an unknown part of the file /api/add_customer.php. This manipulation of the argument Name causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been published and may be used.