Sploitus

CVE-2026-2224

No indexed exploits for CVE-2026-2224 yet

A vulnerability was detected in code-projects Online Reviewer System 1.0. This affects an unknown part of the file /system/system/admins/manage/users/btn_functions.php. The manipulation of the argument firstname results in cross site scripting. It is possible to launch the attack remotely. The exploit is now public and may be used.

Fabian Online Reviewer System
= 1.0
Fix
Available
CVSS 3.1
5.4 MEDIUM
EPSS
0.2% (9th percentile)
Weakness
CWE-79, CWE-94
NVD status
Analyzed
Published
2026-02-09
CVE-2026-2224 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-2224 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-2224 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.