LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-3763 - Vulnerability Analysis

MediumCVSS: 4.3

Last Updated: March 9, 2026

code-projects Simple Flight Ticket Booking System - Stored XSS

Published: March 8, 2026Updated: March 9, 2026PoC AvailableRemote Exploitable

Overview

code-projects Simple Flight Ticket Booking System 1.0 contains a stored XSS caused by input manipulation in showhistory.php, letting remote attackers execute scripts, exploit requires crafted input.

Severity & Score

Severity: Medium
CVSS Score: 4.3

Impact

Remote attackers can execute scripts in users' browsers, potentially stealing session data or performing actions on behalf of users.

Mitigation

Update to the latest version or apply patches to sanitize inputs in showhistory.php.

Details

CVE ID
CVE-2026-3763
Severity
Medium
CVSS Score
4.3
Type
stored_xss
Status
confirmed

CWE

  • CWE-79

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N