Sourcecodester · Inventory Management System · CVE-2026-90695
**Name of the Vulnerable Software and Affected Versions**
SourceCodester Inventory Management System version 1.0
**Description**
An issue exists within the Vendor Management component in the file `/api/vendors handler.php` (API Endpoint). A remote attacker can perform a manipulation that results in cross site scripting, a technique where malicious scripts are injected into trusted websites.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.