PatchSiren cyber security CVE debrief
CVE-2026-93975 code-projects CVE debrief
A vulnerability was found in code-projects Assessment Management 1.0, specifically in the admin/edit-user.php file of the User Editing component. The manipulation of certain arguments leads to cross-site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This vulnerability impacts the confidentiality, integrity, and availability of the system. Defenders should assess the exposure of their systems and prioritize verification and remediation efforts.
- Vendor
- code-projects
- Product
- Assessment Management
- CVSS
- LOW 1.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-20
- Original CVE updated
- 2026-09-20
- Advisory published
- 2026-09-20
- Advisory updated
- 2026-09-20
Who should care
Defenders responsible for code-projects Assessment Management 1.0 systems should assess exposure and prioritize verification and remediation efforts. This includes reviewing the system's configuration, identifying potential entry points, and implementing patches or mitigations as available. Additionally, defenders should monitor systems for potential exploitation attempts and review compensating controls for exposed systems.
Why it matters
Defenders should care about CVE-2026-93975 because it is a cross-site scripting vulnerability in code-projects Assessment Management 1.0 that may allow remote exploitation. Affected systems should be identified and patched or mitigated to prevent potential attacks. The exploit has been disclosed to the public and may be used.
- Verify potential exposure to cross-site scripting attacks
- Assess the risk of remote exploitation
- Prioritize patching or mitigation efforts for affected systems
- Monitor systems for potential exploitation attempts
Technical summary
The vulnerability is located in the admin/edit-user.php file of the User Editing component in code-projects Assessment Management 1.0. The manipulation of certain arguments (name, sname, email, username, password, id) leads to cross-site scripting. The attack may be initiated remotely. The vulnerability impacts the confidentiality, integrity, and availability of the system. Defenders should assess the exposure of their systems and prioritize verification and remediation efforts. The exploit has been disclosed to the public and may be used.
Defensive priority
Defenders should prioritize verifying the presence of this vulnerability in their systems and applying patches or mitigations as available.
Recommended defensive actions
- Verify the presence of this vulnerability in code-projects Assessment Management 1.0 systems
- Apply patches or mitigations as available
- Monitor systems for potential exploitation attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide information on the vulnerability, but details on affected versions, exploitation, and remediation are limited. The exploit has been disclosed to the public and may be used. There is no information on publicly available exploits. The vulnerability is located in the admin/edit-user.php file of the User Editing component in code-projects Assessment Management 1.0.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-93975 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-93975
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-93975 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-93975
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://code-projects.org/
-
Source reference
Unverified legacy reference
URL: https://github.com/zzzxc643/CVE1/blob/main/2026-8-24/vul2.md
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-93975
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/944587
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/407934
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/407934/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.