VYPR
Vypr IntelligenceAI-generatedAug 31, 2026· 3 CVEs

Code Projects: Three Vulnerabilities Including XSS Disclosed in Inventory and Leave Systems

Code Projects faces disclosure of three vulnerabilities, including two XSS and one information disclosure flaw, affecting its Simple Inventory System and Employee Leave Managing System.

Key findings

  • Three vulnerabilities disclosed on August 31, 2026, affect Code Projects' Simple Inventory System 1.0 and Employee Leave Managing System 1.0.
  • Two Cross-Site Scripting (XSS) vulnerabilities (CVE-2026-82625, CVE-2026-82622) allow remote code injection via manipulated input fields.
  • An information disclosure vulnerability (CVE-2026-82624) in the Simple Inventory System 1.0 allows remote attackers to access sensitive data.
  • All reported vulnerabilities are remotely exploitable and impact version 1.0 of the affected systems.

On August 31, 2026, a batch of three vulnerabilities was disclosed affecting Code Projects' software. These vulnerabilities, impacting the Simple Inventory System 1.0 and Employee Leave Managing System 1.0, were reported on the same day, indicating a coordinated disclosure event. The issues range in severity from Low to Medium, with CVSS scores between 3.5 and 5.3.

Two of the vulnerabilities are Cross-Site Scripting (XSS) flaws. CVE-2026-82625, found in the User Registration component of the Simple Inventory System 1.0, arises from the manipulation of the 'last_name' argument in the /register.php file. Similarly, CVE-2026-82622, affecting the Employee Profile Update component of the Employee Leave Managing System 1.0, is triggered by manipulating the 'Name' argument in the /EmpManageSys/editaction.php file. Both XSS vulnerabilities can be exploited remotely.

The third vulnerability, CVE-2026-82624, is an information disclosure flaw. This issue resides within the Database Backup File Handler component of the Simple Inventory System 1.0, specifically related to the inventorymanagement.sql file. Remote attackers can exploit this vulnerability by manipulating an unknown function within this component to gain unauthorized access to sensitive information.

Details regarding specific affected versions beyond 1.0 for the affected systems, vendor advisories, or patch availability were not immediately disclosed in the provided information. Users of the Simple Inventory System 1.0 and Employee Leave Managing System 1.0 are advised to monitor Code Projects for any official security bulletins or updates related to these vulnerabilities. The remote exploitability of these flaws underscores the importance of timely patching and security awareness for users of these systems.

AI-written article. Grounded in 3 CVE records listed below.