CVE-2026-14655 MEDIUM

CVE-2026-14655: code-projects Assessment Management view-users.php cross site scripting

Vendor Code-Projects
Product Assessment Management
Weakness CWE-79 · XSS
Published July 4, 2026
Last update July 7, 2026

CVSS base score

4.8/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P

What the vulnerability does

01Description

A weakness has been identified in code-projects Assessment Management 1.0. Affected by this issue is some unknown functionality of the file admin/view-users.php. Executing a manipulation of the argument User can lead to cross site scripting. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.

Key dates

02Disclosure timeline

July 4, 2026 CVE published
July 7, 2026 Record updated

Related vulnerabilities

04Related CVE