SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-15532

LOW · CVSS 2.4 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

The User Management Module of the SourceCodester Online Book Store System 1.0 is vulnerable to cross-site scripting due to improper handling of user input in the Name/Username argument. This flaw allows remote attackers to execute scripts in the context of a user's session, potentially compromising sensitive information. Organizations using this system should prioritize remediation to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-15532
Severity
LOW
CVSS
2.4
EPSS
0.21%

Original NVD Description

A vulnerability was identified in SourceCodester Online Book Store System 1.0. This issue affects some unknown processing of the component User Management Module. Such manipulation of the argument Name/Username leads to cross site scripting. The attack can be executed remotely. The exploit is publicly available and might be used.