Unrated severityNVD Advisory· Published Jul 4, 2026· Updated Jul 6, 2026
code-projects Assessment Management remove-user.php cross site scripting
CVE-2026-14656
Description
A security vulnerability has been detected in code-projects Assessment Management 1.0. This affects an unknown part of the file /admin/remove-user.php. The manipulation of the argument ID leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.
Patches
Vulnerability mechanics
References
6- github.com/zzzxc643/CVE1/blob/main/assessment/vul4.mdmitreexploit
- vuldb.com/cve/CVE-2026-14656mitrethird-party-advisory
- vuldb.com/submit/846715mitrethird-party-advisory
- code-projects.orgmitreproduct
- vuldb.com/vuln/376170mitrevdb-entrytechnical-description
- vuldb.com/vuln/376170/ctimitresignaturepermissions-required
News mentions
0No linked articles in our index yet.