CVE-2026-5834 is a cross-site scripting (XS) vulnerability in code-projects Online Shoe Store version 1.0, specifically affecting the product_name parameter in the /admin/admin_running.php file. The vulnerability allows an attacker to inject malicious scripts through manipulation of user-supplied input in an administrative interface. The vulnerability carries a CVSS v3.1 score of 2.4 (LOW) with a network attack vector and low attack complexity, indicating it is remotely accessible but requires high-level privileges and user interaction to exploit. The attack has no impact on confidentiality or availability, with only limited integrity implications, making it a low-severity issue overall. Public exploit code is currently available for this vulnerability, though active exploitation appears minimal given its low EPSS score of 0.00032 and absence from the Known Exploited Vulnerabilities catalog. The vulnerability has not gained significant community attention, as evidenced by its low FAUCET risk score of 33.0/100 and inactive status on threat intelligence hot lists, suggesting limited real-world threat to most organizations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Code-Projects | Online Shoe Store | 1.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.