CVE-2026-91854

A vulnerability was identified in code-projects Record Management System 1.0. Affected is an unknown function of the file main/reg.php. Such manipulation of the argument desc leads to cross site scripting. The attack may be launched remotely. The exploit is publicly available and might be used.

  • Published Sep 15, 2026
  • CVSS 2.1 low
  • 0.5% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-91854 at the National Vulnerability Database