CVE-2026-16156: SourceCodester Class and Exam Timetabling System forexam.php cross site scripting
Published Jul 18, 2026
·Updated
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /forexam.php. The manipulation of the argument day results in cross site scripting. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
1 affected component
Sourcecodester Class and Exam Timetabling System=1.0
Event History
Jul 18, 2026
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-16156?
The severity of CVE-2026-16156 is rated as low with a score of 3.5.
2
What type of vulnerability is CVE-2026-16156?
CVE-2026-16156 is a cross site scripting (XSS) vulnerability.
3
What part of the application is affected by CVE-2026-16156?
CVE-2026-16156 affects the /forexam.php file in the SourceCodester Class and Exam Timetabling System.
4
How does the vulnerability CVE-2026-16156 manifest?
The CVE-2026-16156 vulnerability allows for cross site scripting due to manipulation of the 'day' argument.
5
Can CVE-2026-16156 be exploited remotely?
Yes, CVE-2026-16156 can be exploited remotely.