---
id: CVE-2026-13504
title: A vulnerability has been found in code-projects Project Management System 1.0
summary: >-
  A vulnerability has been found in code-projects Project Management System 1.0.
  This vulnerability affects unknown code of the file /mail.php of the component
  Mail Compose Page. Such manipulation leads to cross site scripting. The attack
  …
severity: low
cvss: 3.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-79
  - CWE-94
published: '2026-06-28'
updated: '2026-06-28'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-13504'
references:
  - url: 'https://code-projects.org/'
    label: cna@vuldb.com
  - url: 'https://github.com/MyMySSS/CVE123/blob/main/cve4/PMS_CVE_Submission.md'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-13504'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/838683'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/374499'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/374499/cti'
    label: cna@vuldb.com
tags:
  - nvd
ingestedAt: '2026-06-29T13:42:12.025Z'
epss: 0.00348
epssPercentile: 0.25621
---

## Overview

A vulnerability has been found in code-projects Project Management System 1.0. This vulnerability affects unknown code of the file /mail.php of the component Mail Compose Page. Such manipulation leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
