Ghostwire

CVE-2026-6159: A vulnerability has been found in code-projects Simple ChatBox up to 1.0. Affected by this vulnerability is an unknown...

MEDIUM CVSS 5.5 EPSS 0.03%

Published: April 13, 2026 | Last Modified: April 14, 2026

Description

A vulnerability has been found in code-projects Simple ChatBox up to 1.0. Affected by this vulnerability is an unknown functionality of the file /chatbox/insert.php of the component Endpoint. Such manipulation of the argument msg leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

Ghostwire Analysis — What This Means Practically

Exploitation Probability (EPSS): Low — 0.03% (9th percentile)

Low exploitation probability based on current threat landscape data. Standard patching timeline is appropriate.

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References