Unrated severityNVD Advisory· Published Feb 23, 2026· Updated Feb 26, 2026
CVE-2026-26464
CVE-2026-26464
Description
Stored Cross-Site Scripting (XSS) was found in the /admin/edit_user.php page of Society Management System Portal V1.0, which allows remote attackers to inject and store arbitrary JavaScript code that is executed in users' browsers. This vulnerability can be exploited via the name parameter in a POST HTTP request, leading to execution of malicious scripts when the affected content is viewed by other users, including administrators.
Affected products
2- Society Management System Portal/Society Management System Portaldescription
- Range: = V1.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.