LOW 2.1 NVD
CVE-2026-19998
A weakness has been identified in code-projects Online Shopping System 1.0. Impacted is an unknown function of the file offersmail.php. Executing a manipulation
A weakness has been identified in code-projects Online Shopping System 1.0. Impacted is an unknown function of the file offersmail.php. Executing a manipulation of the argument email can lead to cross site scripting. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
References
- https://code-projects.org/
- https://github.com/zzzxc643/CVE1/blob/main/online-shopping-system/vul6.md
- https://vuldb.com/cve/CVE-2026-19998
- https://vuldb.com/submit/871816
- https://vuldb.com/vuln/391199
This low severity vulnerability with a CVSS score of 2.1 was published on 2026-08-17 via NVD.
vulnfeed aggregates 11808 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.