What is CVE-2026-19922?
CVE-2026-19922 is a cross-site scripting (XSS) vulnerability found in the /checkout.php file of code-projects Online Shopping System 1.0. A remote attacker can exploit it by manipulating the `amount_1` argument. Proper input sanitization and code updates are recommended to mitigate this issue.
Azərbaycanca: CVE-2026-19922, code-projects Online Shopping System 1.0-da /checkout.php faylında aşkarlanmış cross-site scripting (XSS) boşluğudur. Təcavüzkar `amount_1` arqumentini manipulyasiya edərək uzaqdan hücum həyata keçirə bilər. Bu boşluğun aradan qaldırılması üçün daxil olan məlumatların düzgün təmizlənməsi və kod yeniləməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: code-projects
FAQ2
In which file of code-projects Online Shopping System was CVE-2026-19922 discovered?
This XSS vulnerability was discovered in the `/checkout.php` file.
Which argument does an attacker manipulate to exploit CVE-2026-19922?
The attacker can remotely carry out the attack by manipulating the `amount_1` argument.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.