CVE-2026-2222
A weakness has been identified in code-projects Online Reviewer System 1.0. Affected by this vulnerability is an unknown functionality of the file /system/system/admins/manage/users/btn_functions.php. Executing a manipulation of the argument firstname can lead to cross site scripting. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
- Affected products
- Code-Projects Online Reviewer System
- Fabian Online Reviewer System
- = 1.0
- Fix
- Available
- CVSS 3.1
- 4.8 MEDIUM
- EPSS
- 0.2% (10th percentile)
- Weakness
- CWE-94, CWE-79
- NVD status
- Analyzed
- Published
- 2026-02-09
CVE-2026-2222 at NVD
3 known exploits for CVE-2026-2222
Proof-of-concept code and exploit modules indexed by Sploitus