Cross Site Scripting Vulnerability in Simple IT Discussion Forum by Code-Projects
CVE-2026-5826
Key Information:
- Vendor
Code-projects
- Vendor
- CVE Published:
- 9 April 2026
Badges
What is CVE-2026-5826?
A cross site scripting vulnerability resides in the Simple IT Discussion Forum 1.0 within the /edit-category.php file. This flaw allows an attacker to manipulate the 'Category' argument, which can lead to execution of malicious scripts in the context of users' browsers. The issue is exploitable remotely, making it critical for users to promptly patch their systems to prevent potential attacks. For more details and remediation guidance, visit the official product page or check security databases.
Affected Version(s)
Simple IT Discussion Forum 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
