CVE-2026-82625

A vulnerability has been found in code-projects Simple Inventory System 1.0. This affects an unknown part of the file /register.php of the component User Registration. Such manipulation of the argument last_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

  • Published Aug 31, 2026
  • CVSS 2.1 low
  • 0.5% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-82625 at the National Vulnerability Database