---
id: CVE-2026-86226
title: >-
  A security flaw has been discovered in Projectwolds Online Attendance System
  1.0
summary: >-
  A security flaw has been discovered in Projectwolds Online Attendance System
  1.0. Affected by this issue is some unknown functionality of the file
  profile.php. The manipulation of the argument email results in cross site
  scripting. The a…
severity: low
cvss: 3.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-79
  - CWE-94
vendor: Projectwolds
product: Online Attendance System
affected:
  - online_attendance_system 1.0
published: '2026-09-06'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T16:18:22.997'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86226'
references:
  - url: 'https://github.com/CyberShailendra1/Online-Attendance-System-Projectworlds'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-86226'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/898328'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/399379'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/399379/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-08T15:03:50.294617Z'
epss: 0.00331
epssPercentile: 0.23532
ingestedAt: '2026-09-07T12:10:14.411Z'
---

## Overview

A security flaw has been discovered in Projectwolds Online Attendance System 1.0. Affected by this issue is some unknown functionality of the file profile.php. The manipulation of the argument email results in cross site scripting. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
