What is CVE-2026-19209?
A remote cross site scripting (XSS) vulnerability has been discovered in SourceCodester Photo Share Website 1.0, specifically in the Comment parameter of the `/social/index.php?page=home` file. This allows attackers to execute malicious scripts in users' browsers. It is recommended to temporarily disable the application or await an official patch.
Azərbaycanca: SourceCodester Photo Share Website 1.0-da `/social/index.php?page=home` faylındakı Comment parametrini manipulyasiya edərək uzaqdan yönləndirilmiş cross site scripting (XSS) hücumuna imkan verən boşluq aşkar edilib. Bu zəiflik vasitəsilə təcavüzkar istifadəçi brauzerində zərərli skript icra edə bilər. Müvəqqəti olaraq tətbiqi deaktiv etmək və ya rəsmi patch-ı gözləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: SourceCodester
FAQ2
What type of vulnerability was discovered in SourceCodester Photo Share Website 1.0?
This is a remote cross site scripting (XSS) vulnerability.
Which component of the website must an attacker target to exploit this flaw?
The attacker must manipulate the Comment parameter in the `/social/index.php?page=home` file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.