CVE-2026-4835: Code-Projects Accounting System

Low severity, CVSS 3.5. EPSS: 0.3% chance of exploitation in the next 30 days.

A security vulnerability has been detected in code-projects Accounting System 1.0. Impacted is an unknown function of the file /my_account/add_costumer.php of the component Web Application Interface. Such manipulation of the argument costumer_name leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.

Affected products

Published 2026-03-26. Last modified 2026-06-17.