Code Projects: Six Vulnerabilities Including SQLi and XSS Disclosed Together
Six vulnerabilities disclosed on August 31, 2026, impact Code Projects software, including SQL injection and XSS flaws, with remote exploitation potential.

Key findings
- Six vulnerabilities disclosed on August 31, 2026, affect multiple Code Projects software including Typora.
- Vulnerabilities include SQL injection, XSS, and information disclosure, with remote exploitation possible for most.
- CVE-2026-82701 (SQLi) is rated High severity; others range from Medium to Low.
- Affected Code Projects systems include Online Shopping System 1.0, Simple Inventory System 1.0, and Employee Leave Managing System 1.0.
- Typora versions up to 1.13.8/1.14.6 are affected by CVE-2026-82805; upgrading is recommended.
On August 31, 2026, a batch of six vulnerabilities was disclosed affecting various Code Projects software, including Typora, Online Shopping System, Simple Inventory System, and Employee Leave Managing System. The vulnerabilities, disclosed within a nine-hour window, range in severity from Low to High, with several allowing for remote exploitation. The disclosures highlight potential risks for users of these systems, particularly concerning cross-site scripting (XSS) and SQL injection.
Several vulnerabilities stem from improper handling of user inputs, leading to common web attack vectors. Three distinct cross-site scripting (XSS) vulnerabilities were identified: CVE-2026-82805 in Typora's Mermaid Rendering Engine, CVE-2026-82700 in the Online Shopping System's Newsletter Subscription component, and CVE-2026-82622 in the Employee Leave Managing System's Employee Profile Update component. These flaws allow attackers to inject malicious scripts into web pages viewed by other users.
Additionally, a SQL injection vulnerability, CVE-2026-82701, was found in the search functionality of the Code Projects Online Shopping System 1.0. This flaw could permit attackers to manipulate database queries, potentially leading to unauthorized data access or modification. Another vulnerability, CVE-2026-82624, affecting the Simple Inventory System 1.0's Database Backup File Handler, allows for information disclosure, enabling remote attackers to access sensitive data.
The batch includes one high-severity vulnerability, CVE-2026-82701 (SQL injection), and multiple medium-severity flaws, CVE-2026-82805 (XSS), CVE-2026-82700 (XSS), CVE-2026-82625 (XSS), and CVE-2026-82624 (Information Disclosure). A single low-severity vulnerability, CVE-2026-82622 (XSS), was also part of this disclosure. All reported vulnerabilities are remotely exploitable.
According to related coverage, the Simple Inventory System 1.0 and Employee Leave Managing System 1.0, both affected by multiple vulnerabilities in this batch, are running version 1.0. The specific versions affected by CVE-2026-82805 in Typora are up to 1.13.8/1.14.6, and upgrading is recommended. Information regarding patches for the other affected Code Projects systems was not detailed in the provided disclosures.
Users of Typora, Code Projects Online Shopping System, Simple Inventory System, and Employee Leave Managing System should be aware of these disclosures. The simultaneous release of these vulnerabilities underscores the importance of timely patching and security updates for all software components. Further investigation into specific patch availability for the Code Projects systems is advised.