SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-82625

MEDIUM · CVSS 4.3 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-31 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A cross-site scripting vulnerability exists in the User Registration component of the Simple Inventory System, specifically within the /register.php file, allowing attackers to manipulate the 'last_name' argument. This flaw can be exploited remotely, potentially leading to unauthorized script execution in users' browsers. Organizations using this system should prioritize remediation to mitigate the risk of client-side attacks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82625
Severity
MEDIUM
CVSS
4.3
EPSS
0.27%

Original NVD Description

A vulnerability has been found in code-projects Simple Inventory System 1.0. This affects an unknown part of the file /register.php of the component User Registration. Such manipulation of the argument last_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.