CVE-2026-11520
published 2026-06-08CVE-2026-11520: A weakness has been identified in SourceCodester Inventory System 1.0. Affected by this issue is some unknown functionality of the file header.php. This…
PriorityP419low3.5CVSS 3.1
AVNACLPRLUIRSUCNILAN
EPSS
0.25%
16.1th percentile
A weakness has been identified in SourceCodester Inventory System 1.0. Affected by this issue is some unknown functionality of the file header.php. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. Multiple parameters might be affected.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sourcecodester | inventory_system | — | — |
CVSS provenance
nvdv3.13.5LOWCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
nvdv4.02.0LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A weakness has been identified in SourceCodester Inventory System 1.0.
ghsa_unreviewed·2026-06-08
CVE-2026-11520 [LOW] CWE-79 A weakness has been identified in SourceCodester Inventory System 1.0.
A weakness has been identified in SourceCodester Inventory System 1.0. Affected by this issue is some unknown functionality of the file header.php. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. Multiple parameters might be affected.
VulDB
SourceCodester Inventory System 1.0 header.php cross site scripting
vuldb·2026-06-07
CVE-2026-11520 [LOW] SourceCodester Inventory System 1.0 header.php cross site scripting
A vulnerability, which was classified as problematic, has been found in SourceCodester Inventory System 1.0. Affected by this issue is some unknown functionality of the file header.php. This manipulation causes cross site scripting.
The identification of this vulnerability is CVE-2026-11520. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
Multiple parameters might be affected.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-08
Published