PatchSiren

Rizwan17 CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW Rizwan17 CVE published 2026-09-10

CVE-2026-87926

A cross-site scripting vulnerability exists in Rizwan17's inventory-management-system up to a specific commit (bfe78a330d01bb26b9daec5dc9ecd5c77900e03f). The issue is located in the login page's handling of the 'msg' argument in index.php. This could allow an attacker to inject malicious scripts. The system does not use versioning, making it difficult to determine affected and unaffected releases. The pro [truncated]

MEDIUM Rizwan17 CVE published 2026-09-09

CVE-2026-87921

A vulnerability was identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. The function update_record of the file includes/manage.php is affected by sql injection via the arguments update_category, cid, update_brand, or update_product. This issue can be exploited remotely and a public exploit is available.