CVE-2026-15595: SourceCodester Class and Exam Timetabling System forsubject.php cross site scripting
Published Jul 13, 2026
·Updated
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /forsubject.php. This manipulation of the argument subject causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
1 affected component
Sourcecodester Class and Exam Timetabling System=1.0
Event History
Jul 13, 2026
CVE Published
via MITRE·08:30 PM
Data Sourced
via MITRE·08:30 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-15595?
The severity of CVE-2026-15595 is rated medium with a score of 4.3.
2
How do I fix CVE-2026-15595?
To fix CVE-2026-15595, ensure to sanitize and validate input in the forsubject.php file to prevent cross-site scripting.
3
What type of vulnerability is CVE-2026-15595?
CVE-2026-15595 is a Cross-Site Scripting (XSS) vulnerability.
4
Is CVE-2026-15595 remotely exploitable?
Yes, CVE-2026-15595 can be exploited remotely.
5
Which file is affected by CVE-2026-15595?
The affected file in CVE-2026-15595 is forsubject.php in the SourceCodester Class and Exam Timetabling System.