VYPR
Vypr IntelligenceAI-generatedAug 20, 2026· 15 CVEs

Code Projects: 15 SQLi & XSS Vulnerabilities Disclosed Together, Exploits Publicly Available

Code Projects applications vulnerable to 15 SQLi and XSS flaws disclosed in a single batch, with public exploits increasing risk.

Key findings

  • 15 CVEs disclosed together for Code Projects applications between Aug 15-20, 2026.
  • Predominantly SQL injection vulnerabilities, with some XSS flaws also present.
  • Multiple products affected, including inventory, user management, and e-commerce systems.
  • High-severity flaws (CVSSv3 7.3) are common, with publicly available exploits.
  • Urgent patching advised due to widespread impact and exploitability.

On August 20, 2026, a batch of 15 vulnerabilities affecting various Code Projects applications was disclosed, with the earliest disclosure on August 15, 2026. The vulnerabilities span multiple products including Simple Inventory System, Login Registration System, Employee Management System, Assessment Management, Hospital Information System, Online Job Portal System, Task Management System, Online Shopping System, and Online Food Order System. The majority of these flaws are SQL injection vulnerabilities, with a few instances of Cross-Site Scripting (XSS) also present. The widespread nature and the presence of publicly disclosed exploits for many of these issues highlight a significant risk for users of these systems.

Several Code Projects applications are impacted by SQL injection vulnerabilities. CVE-2026-76990 in Simple Inventory System 1.0 affects the delete.php file, allowing remote SQL injection via the 'ID' argument. Similarly, CVE-2026-76764 in Employee Management System 1.0 impacts the Admin Login Endpoint in process/aprocess.php, exploitable through the 'mailuid' argument. The Hospital Information System 1.0 is affected by CVE-2026-75986, where the User Login Handler in includes/users/UsersController.php allows remote SQL injection via the 'email' argument. The Task Management System 1.0 has CVE-2026-75778, a SQL injection flaw in its Login Form component (index.php) due to manipulation of the 'email' argument. The Online Job Portal System 1.0 is vulnerable via CVE-2026-75986 in its Password Recovery component (ForPass.php) through the 'txtUserName' argument. The Online Shopping System 1.0 is particularly affected, with multiple SQL injection vulnerabilities including CVE-2026-19923 in checkout_process.php via 'total_count', CVE-2026-19921 in homeaction.php via 'cat_id', CVE-2026-19920 in action.php via 'proId', and CVE-2026-19919 in login.php via 'email'. Additionally, the Online Food Order System 1.0 has CVE-2026-19917, an SQL injection vulnerability in delete_food_items1.php exploitable through the 'checkbox' argument.

Beyond SQL injection, Cross-Site Scripting (XSS) vulnerabilities were also disclosed. CVE-2026-19998 in the Online Shopping System 1.0's offersmail.php component allows for remote XSS via manipulation of the 'email' argument. Another XSS vulnerability, CVE-2026-19916, affects the Online Food Order System 1.0's edit_food_items.php file, allowing remote exploitation through the 'dname' argument. The Login Registration System 1.0 is affected by CVE-2026-76799, a medium-severity vulnerability in its SQL Database Backup Handler component (loginsystem/database/login_registration_system.sql) that could lead to file or directory manipulation.

The severity of these vulnerabilities ranges from Low to High, with several High-severity SQL injection flaws carrying a CVSSv3 score of 7.3. The descriptions consistently mention that exploits have been disclosed to the public and may be used, indicating a significant risk of active exploitation. The broad range of affected products and the common vulnerability types suggest a potential systemic issue within Code Projects' development practices or a common set of libraries used across their applications.

Users of Code Projects applications are strongly advised to review their deployed versions and apply any available patches or updates. Given the public availability of exploits, immediate attention to these vulnerabilities is crucial to prevent potential compromise. The disclosure of these 15 CVEs within a short window underscores the importance of prompt security assessments and patching for all products from this vendor.

The batch of vulnerabilities disclosed between August 15 and August 20, 2026, impacts multiple Code Projects applications, with a strong emphasis on SQL injection flaws. Multiple systems, including Online Shopping System and Simple Inventory System, are affected by critical SQL injection vulnerabilities. Cross-Site Scripting (XSS) vulnerabilities were also identified in the Online Shopping System and Online Food Order System. Publicly available exploits for many of these vulnerabilities increase the risk of active exploitation. Users are urged to update their Code Projects applications immediately due to the widespread and severe nature of these flaws. 15 CVEs were disclosed in a single batch, affecting various Code Projects applications with SQL injection and XSS vulnerabilities. The batch of vulnerabilities spans multiple Code Projects products, including inventory, user management, and e-commerce systems. High-severity SQL injection flaws (CVSSv3 7.3) are prevalent across several affected applications. Publicly disclosed exploits for these vulnerabilities necessitate urgent patching. The disclosure window for this batch of vulnerabilities was from August 15 to August 20, 2026. A stylized database icon with visible SQL query lines being corrupted and leaking data. The background is a dark, abstract network pattern.

AI-written article. Grounded in 15 CVE records listed below.