CVE-2026-19378: code-projects Task Management System CommentSave.php cross site scripting
A vulnerability was found in code-projects Task Management System 1.0. This issue affects some unknown processing of the file /user/CommentSave.php. The manipulation of the argument comment/taskid/mineId/recId/myName/myImage results in cross site scripting. It is possible to launch the attack remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19378?
The severity of CVE-2026-19378 is rated as medium with a score of 4.3.
What type of vulnerability is CVE-2026-19378?
CVE-2026-19378 is a cross site scripting (XSS) vulnerability.
How do I fix CVE-2026-19378?
To fix CVE-2026-19378, ensure that user input is properly sanitized and validated in the CommentSave.php file.
What software is affected by CVE-2026-19378?
CVE-2026-19378 affects the code-projects Task Management System version 1.0.
What can attackers gain from exploiting CVE-2026-19378?
Exploiting CVE-2026-19378 can allow attackers to execute malicious scripts in the context of the user's browser.