CVE-2026-14656 MEDIUM

CVE-2026-14656: code-projects Assessment Management remove-user.php cross site scripting

Vendor Code-Projects
Product Assessment Management
Weakness CWE-79 · XSS
Published July 4, 2026
Last update July 6, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P

What the vulnerability does

01Description

A security vulnerability has been detected in code-projects Assessment Management 1.0. This affects an unknown part of the file /admin/remove-user.php. The manipulation of the argument ID leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.

Key dates

02Disclosure timeline

July 4, 2026 CVE published
July 6, 2026 Record updated

Related vulnerabilities

04Related CVE