PatchSiren cyber security CVE debrief
CVE-2026-5834 code-projects CVE debrief
A vulnerability was detected in code-projects Online Shoe Store 1.0. Affected is an unknown function of the file /admin/admin_running.php. Performing a manipulation of the argument product_name results in cross site scripting. It is possible to initiate the attack remotely. The vulnerability has a CVSS score of 1.9, indicating a low severity. Users with administrative access should be aware of this vulnerability and take steps to mitigate it. The exploit is now public and may be used.
- Vendor
- code-projects
- Product
- Online Shoe Store
- CVSS
- LOW 1.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-09
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-09
- Advisory updated
- 2026-07-24
Who should care
Users of code-projects Online Shoe Store 1.0, particularly those with administrative access, should be aware of this vulnerability and take steps to mitigate it. This includes applying vendor patches or updates if available, implementing compensating controls such as web application firewalls or intrusion detection systems, and monitoring for suspicious activity.
Technical summary
The vulnerability is a cross-site scripting (XSS) issue in the /admin/admin_running.php file of code-projects Online Shoe Store 1.0. The vulnerability occurs when user input is not properly sanitized, allowing an attacker to inject malicious code. This could potentially allow an attacker to steal user data or take control of the affected system. The CVSS score for this vulnerability is 1.9, indicating a low severity.
Defensive priority
Low priority, as the CVSS score is 1.9, but still requires attention to prevent potential attacks.
Recommended defensive actions
- Inventory and verify the presence of code-projects Online Shoe Store 1.0 in your environment.
- Apply vendor patches or updates if available.
- Implement compensating controls, such as web application firewalls or intrusion detection systems, to detect and prevent attacks.
- Monitor for suspicious activity and exception tracking.
- Review and update incident response plans to address potential attacks.
- Conduct regular security audits and vulnerability assessments.
- Verify the integrity of affected systems and data.
Evidence notes
The CVE record was published on 2026-04-09T04:17:20.980Z and was last modified on 2026-07-24T08:10:00.150Z. The NVD entry is currently Deferred. Evidence is limited to public sources and may not reflect the full scope or impact of this vulnerability. Defenders should verify the presence of affected product deployments in their environments and review official advisories for further details.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-5834 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-5834
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-5834 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-5834
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://code-projects.org/
-
Source reference
Unverified legacy reference
URL: https://github.com/lonelyuan/vunls/issues/5
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/788339
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/356290
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/356290/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.