{"id":81186,"date":"2026-06-28T19:00:08","date_gmt":"2026-06-28T15:30:08","guid":{"rendered":"https:\/\/afaghhosting.net\/blog\/cve-2026-13504-code-projects-project-management-system-mail-compose-mail-php-cross-site-scripting\/"},"modified":"2026-06-28T19:00:08","modified_gmt":"2026-06-28T15:30:08","slug":"cve-2026-13504-code-projects-project-management-system-mail-compose-mail-php-cross-site-scripting","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/cve-2026-13504-code-projects-project-management-system-mail-compose-mail-php-cross-site-scripting\/","title":{"rendered":"CVE-2026-13504 &#8211; code-projects Project Management System Mail Compose mail.php cross site scripting"},"content":{"rendered":"<p>CVE ID :CVE-2026-13504<\/p>\n<p>  Published : June 28, 2026, 3:30 p.m. | 15\u00a0minutes ago<\/p>\n<p>  Description :A vulnerability has been found in code-projects Project Management System 1.0. This vulnerability affects unknown code of the file \/mail.php of the component Mail Compose Page. Such manipulation leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.<\/p>\n<p>  Severity: 0.0 | NA<\/p>\n<p>  Visit the link for more details, such as CVSS details, affected products, timeline, and more&#8230;\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CVE ID :CVE-2026-13504 Published : June 28, 2026, 3:30 p.m. | 15\u00a0minutes ago Description :A vulnerability has been found in code-projects Project Management System 1.0. This vulnerability affects unknown code of the file \/mail.php of the component Mail Compose Page. Such manipulation leads to cross site scripting. The attack may be performed from remote. The &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-81186","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/81186","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=81186"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/81186\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=81186"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=81186"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=81186"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}