CVE-2026-9413: SourceCodester Indian Invoicing System category.php cross site scripting
Published May 25, 2026
·Updated
A vulnerability was identified in SourceCodester Indian Invoicing System 1.0. The affected element is an unknown function of the file /Invoicing/category.php. The manipulation of the argument msg leads to cross site scripting. The attack may be initiated remotely. The exploit is publicly available and might be used.
Affected Software
1 affected component
Sourcecodester Indian Invoicing System=1.0
Event History
May 25, 2026
CVE Published
via MITRE·01:15 AM
Data Sourced
via MITRE·01:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-9413?
The severity of CVE-2026-9413 is classified as medium with a CVSS score of 4.3.
2
How do I fix CVE-2026-9413?
To fix CVE-2026-9413, ensure that user input is properly sanitized and validated in the category.php file.
3
What type of vulnerability is CVE-2026-9413?
CVE-2026-9413 is a cross-site scripting (XSS) vulnerability.
4
Can CVE-2026-9413 be exploited remotely?
Yes, CVE-2026-9413 can be exploited remotely by manipulating the msg argument.
5
What is the affected software for CVE-2026-9413?
The affected software for CVE-2026-9413 is the SourceCodester Indian Invoicing System version 1.0.