CVE-2026-91854: code-projects Record Management System reg.php cross site scripting
Published Sep 15, 2026
·Updated
A vulnerability was identified in code-projects Record Management System 1.0. Affected is an unknown function of the file main/reg.php. Such manipulation of the argument desc leads to cross site scripting. The attack may be launched remotely. The exploit is publicly available and might be used.
Affected Software
1 affected component
Record Management System=1.0
Event History
Sep 15, 2026
CVE Published
via MITRE·04:30 PM
Data Sourced
via MITRE·04:30 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The attack can be launched remotely and requires no privileges, but it requires user interaction. An attacker would need to cause a user to interact with crafted content that reaches the desc argument in main/reg.php.
2
Is exploit code available?
Yes. A public exploit is available, so attempts to exploit the issue may be more likely.
3
Which product version is confirmed affected?
The affected product is code-projects Record Management System version 1.0. The available data does not identify a fixed version or workaround.