CVE-2026-82700
published 2026-08-31CVE-2026-82700: A vulnerability was found in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown functionality of the file /offersmail.php…
PriorityP424medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
EPSS
0.27%
19.5th percentile
A vulnerability was found in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown functionality of the file /offersmail.php of the component Newsletter Subscription. The manipulation of the argument email results in cross site scripting. The attack may be performed from remote. The exploit has been made public and could be used.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| code-projects | online_shopping_system | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
nvdv4.02.1LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A vulnerability was found in code-projects Online Shopping System 1.0.
ghsa_unreviewed·2026-08-31
CVE-2026-82700 [LOW] CWE-79 A vulnerability was found in code-projects Online Shopping System 1.0.
A vulnerability was found in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown functionality of the file /offersmail.php of the component Newsletter Subscription. The manipulation of the argument email results in cross site scripting. The attack may be performed from remote. The exploit has been made public and could be used.
VulDB
code-projects Online Shopping System 1.0 Newsletter Subscription /offersmail.php email cross site scripting
vuldb·2026-08-30
CVE-2026-82700 [LOW] code-projects Online Shopping System 1.0 Newsletter Subscription /offersmail.php email cross site scripting
A vulnerability categorized as problematic has been discovered in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown functionality of the file /offersmail.php of the component Newsletter Subscription. The manipulation of the argument email results in cross site scripting.
This vulnerability was named CVE-2026-82700. The attack may be performed from remote. In addition, an exploit is available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://code-projects.org/https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/Stored%20Cross-Site%20Scripting%20(XSS)%20in%20Online%20Shopping%20System%20PHP%20email%20Parameter.mdhttps://vuldb.com/cve/CVE-2026-82700https://vuldb.com/submit/894394https://vuldb.com/vuln/397189https://vuldb.com/vuln/397189/cti
2026-08-31
Published