# CASCA evidence receipt — CVE-2026-16202

- Generation: `gen-56ccdaf914f7b4be95b689ccae7dc20d`
- As known: 2026-07-19T05:00:42+00:00
- Comparison: first_public_core_generation
- Score policy: public-priority-v1.0.1
- Conflict: not observed in this generation

## Source assertions

- **VulDB** (original_assertion): container — SourceCodester Class and Exam Timetabling System CYS.php cross site scripting
  - Observed: 2026-07-19T04:35:17.31812+00:00
  - Citation: https://www.cve.org/CVERecord?id=CVE-2026-16202

## CVSS assessments

- **VulDB** (unknown, CVSS 4.0): 5.1 — display only
  - Evidence class: direct_cve_record_display_only; source rank: not applicable
  - Validation: display-only direct record assessment
  - Vector: `CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P`
- **VulDB** (unknown, CVSS 3.1): 3.5 — display only
  - Evidence class: direct_cve_record_display_only; source rank: not applicable
  - Validation: display-only direct record assessment
  - Vector: `CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R`
- **VulDB** (unknown, CVSS 3.0): 3.5 — display only
  - Evidence class: direct_cve_record_display_only; source rank: not applicable
  - Validation: display-only direct record assessment
  - Vector: `CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R`
- **VulDB** (unknown, CVSS 2.0): 4 — display only
  - Evidence class: direct_cve_record_display_only; source rank: not applicable
  - Validation: display-only direct record assessment
  - Vector: `AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR`

## Limitations and unknowns

- CISA KEV absence is unknown, not evidence of no exploitation.
- No eligible dated FIRST EPSS observation is present.
- Affected or fixed status applies only to the exact cited product and version scope; unresolved scope remains unknown.
- NVD-carried upstream facts remain derivative and are not independent corroboration.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Factor D is unknown in Public Core because no accepted canonical mapping-obligation ledger is present.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.

Generated from CASCA normalized evidence. This receipt is not proof that an asset is affected, unaffected, safe, or fixed.
