CVE-2026-2214: code-projects for Plugin AdminAddAlbum.php cross site scripting
A weakness has been identified in code-projects for Plugin 1.0. This affects an unknown part of the file /Administrator/PHP/AdminAddAlbum.php. This manipulation of the argument txtalbum causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2214?
CVE-2026-2214 has been identified as a cross-site scripting vulnerability that can be exploited by attackers.
How do I fix CVE-2026-2214?
To fix CVE-2026-2214, ensure proper input validation and escaping for the 'txtalbum' parameter in AdminAddAlbum.php.
What software is affected by CVE-2026-2214?
CVE-2026-2214 affects version 1.0 of the Fabian Online Music Site plugin.
What kind of attack can CVE-2026-2214 facilitate?
CVE-2026-2214 facilitates cross-site scripting (XSS) attacks allowing attackers to inject malicious scripts.
Is CVE-2026-2214 exploitable remotely?
Yes, CVE-2026-2214 can be exploited remotely if the software is accessible over the internet.