CVE-2026-19922: code-projects Online Shopping System checkout.php cross site scripting
Published Aug 16, 2026
·Updated
A security flaw has been discovered in code-projects Online Shopping System 1.0. Affected by this issue is some unknown functionality of the file /checkout.php. Performing a manipulation of the argument amount1 results in cross site scripting. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
1 affected component
Code-projects Online Shopping System=1.0
Event History
Aug 16, 2026
CVE Published
via MITRE·12:15 AM
Data Sourced
via MITRE·12:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-19922?
CVE-2026-19922 has a low severity rating of 3.5.
2
What type of vulnerability is identified in CVE-2026-19922?
CVE-2026-19922 is a cross site scripting (XSS) vulnerability.
3
How can CVE-2026-19922 be exploited?
CVE-2026-19922 can be exploited by manipulating the argument 'amount_1' in the /checkout.php file.
4
What software is affected by CVE-2026-19922?
CVE-2026-19922 affects Code-projects Online Shopping System version 1.0.
5
What is the potential impact of CVE-2026-19922?
CVE-2026-19922 can lead to cross site scripting attacks, potentially affecting user data.