CVE-2026-14655
published 2026-07-04CVE-2026-14655: A weakness has been identified in code-projects Assessment Management 1.0. Affected by this issue is some unknown functionality of the file…
PriorityP415low2.4CVSS 3.1
AVNACLPRHUIRSUCNILAN
EPSS
0.35%
26.8th percentile
A weakness has been identified in code-projects Assessment Management 1.0. Affected by this issue is some unknown functionality of the file admin/view-users.php. Executing a manipulation of the argument User can lead to cross site scripting. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| code-projects | assessment_management | — | — |
CVSS provenance
nvdv3.12.4LOWCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
nvdv4.01.9LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.03.3LOWAV:N/AC:L/Au:M/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A weakness has been identified in code-projects Assessment Management 1.0.
ghsa_unreviewed·2026-07-05
CVE-2026-14655 [LOW] CWE-79 A weakness has been identified in code-projects Assessment Management 1.0.
A weakness has been identified in code-projects Assessment Management 1.0. Affected by this issue is some unknown functionality of the file admin/view-users.php. Executing a manipulation of the argument User can lead to cross site scripting. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
VulDB
code-projects Assessment Management 1.0 admin/view-users.php User cross site scripting
vuldb·2026-07-03
CVE-2026-14655 [LOW] code-projects Assessment Management 1.0 admin/view-users.php User cross site scripting
A vulnerability, which was classified as problematic, was found in code-projects Assessment Management 1.0. Affected by this issue is some unknown functionality of the file admin/view-users.php. Executing a manipulation of the argument User can lead to cross site scripting.
This vulnerability appears as CVE-2026-14655. The attack may be performed from remote. In addition, an exploit is available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-04
Published