CVE-2026-1444 MEDIUM

CVE-2026-1444: iJason-Liu Books_Manager add_book_check.php cross site scripting

Vendor Ijason-Liu
Product Books_Manager
Weakness CWE-79 · XSS
Published January 26, 2026
Last update February 23, 2026

CVSS base score

4.8/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P

What the vulnerability does

01Description

A vulnerability has been found in iJason-Liu Books_Manager up to 298ba736387ca37810466349af13a0fdf828e99c. This affects an unknown part of the file controllers/books_center/add_book_check.php. Such manipulation of the argument mark leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable.

Key dates

02Disclosure timeline

January 26, 2026 CVE published
February 23, 2026 Record updated