CVE-2026-6003: code-projects Simple IT Discussion Forum user.php cross site scripting
Published Apr 10, 2026
·Updated
A security vulnerability has been detected in code-projects Simple IT Discussion Forum 1.0. This issue affects some unknown processing of the file /admin/user.php. Such manipulation of the argument fname leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
Affected Software
1 affected component
Code-projects Simple IT Discussion Forum=1.0
Event History
Apr 10, 2026
CVE Published
via MITRE·02:15 AM
Data Sourced
via MITRE·02:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 AM
DescriptionSeverityWeakness
May 19, 58294
Event
via NVD·02:45 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-6003?
CVE-2026-6003 has a medium severity due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2026-6003?
To fix CVE-2026-6003, sanitize user input in the fname parameter to prevent script injection.
3
Which software is affected by CVE-2026-6003?
CVE-2026-6003 affects version 1.0 of the code-projects Simple IT Discussion Forum.
4
What type of vulnerability is CVE-2026-6003?
CVE-2026-6003 is classified as a cross-site scripting (XSS) vulnerability.
5
Where is the vulnerability located in the Simple IT Discussion Forum?
The vulnerability in CVE-2026-6003 is found in the /admin/user.php file.