Vulnerabilities
70 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-36235 | A SQL injection vulnerability was found in the scheduleSubList.php file of itsourcecode Online Student Enrollment System v1.0. A SQL injection vulnerability was found in the scheduleSubList.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that the 'subjcode' parameter is directly embedded into the SQL query via string interpolation without any sanitization or validation. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2026-5334 | A weakness has been identified in itsourcecode Online Enrollment System 1.0. A weakness has been identified in itsourcecode Online Enrollment System 1.0. Impacted is an unknown function of the file /enrollment/index.php?view=edit&id=3 of the component Parameter Handler. This manipulation of the argument deptid causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2026-3730 | A security flaw has been discovered in itsourcecode Free Hotel Reservation System 1.0. A security flaw has been discovered in itsourcecode Free Hotel Reservation System 1.0. The affected element is an unknown function of the file /hotel/admin/mod_amenities/index.php?view=edit. Performing a manipulation of the argument amen_id/rmtype_id results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. NVD description · AI analysis pending | 5.5 | <1% | PoC ×2 |
| — | |
| CVE-2026-3261 | A flaw has been found in itsourcecode School Management System 1.0. A flaw has been found in itsourcecode School Management System 1.0. This impacts an unknown function of the file /settings/index.php of the component Setting Handler. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2026-2939 | A vulnerability was found in itsourcecode Student Management System 1.0. A vulnerability was found in itsourcecode Student Management System 1.0. The impacted element is an unknown function of the file /add_student/ of the component Add Student Module. The manipulation results in cross site scripting. It is possible to launch the attack remotely. The exploit has been made public and could be used. NVD description · AI analysis pending | 1.9 | <1% | PoC ×2 |
| — | |
| CVE-2026-2190 +1 in the same advisory: …2189 | A security flaw has been discovered in itsourcecode School Management System 1.0. A security flaw has been discovered in itsourcecode School Management System 1.0. This impacts an unknown function of the file /ramonsys/user/controller.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2026-2073 | A vulnerability was determined in itsourcecode School Management System 1.0. A vulnerability was determined in itsourcecode School Management System 1.0. This affects an unknown function of the file /ramonsys/user/index.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2026-2014 | A security flaw has been discovered in itsourcecode Student Management System 1.0. A security flaw has been discovered in itsourcecode Student Management System 1.0. This impacts an unknown function of the file /ramonsys/billing/index.php. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2026-1701 | A security vulnerability has been detected in itsourcecode School Management System 1.0. A security vulnerability has been detected in itsourcecode School Management System 1.0. This issue affects some unknown processing of the file /enrollment/index.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. Due to contradicting product definitions in the original disclosure, this CVE was initially incorrectly assigned to the Student Management System. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2026-1176 | A security flaw has been discovered in itsourcecode School Management System 1.0. A security flaw has been discovered in itsourcecode School Management System 1.0. Affected is an unknown function of the file /subject/index.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2026-0544 | A security flaw has been discovered in itsourcecode School Management System 1.0. A security flaw has been discovered in itsourcecode School Management System 1.0. This affects an unknown part of the file /student/index.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2025-15074 | A vulnerability was identified in itsourcecode Online Frozen Foods Ordering System 1.0. A vulnerability was identified in itsourcecode Online Frozen Foods Ordering System 1.0. This vulnerability affects unknown code of the file /customer_details.php. Such manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2025-15073 | A vulnerability was determined in itsourcecode Online Frozen Foods Ordering System 1.0. A vulnerability was determined in itsourcecode Online Frozen Foods Ordering System 1.0. This affects an unknown part of the file /contact_us.php. This manipulation of the argument Name causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2025-13298 | A vulnerability was detected in itsourcecode Web-Based Internet Laboratory Management System 1.0. A vulnerability was detected in itsourcecode Web-Based Internet Laboratory Management System 1.0. This affects an unknown function of the file /enrollment/controller.php. Performing a manipulation results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2025-11432 +1 in the same advisory: …11433 | A vulnerability was identified in itsourcecode Leave Management System 1.0. A vulnerability was identified in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /reset.php. Such manipulation of the argument employid leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. NVD description · AI analysis pending | 5.5 group max | <1% | PoC |
| — | |
| CVE-2025-10673 | A vulnerability was determined in itsourcecode Student Information Management System 1.0. A vulnerability was determined in itsourcecode Student Information Management System 1.0. The impacted element is an unknown function of the file /admin/modules/class/index.php. This manipulation of the argument classId causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2025-10599 | A security flaw has been discovered in itsourcecode Web-Based Internet Laboratory Management System 1.0. A security flaw has been discovered in itsourcecode Web-Based Internet Laboratory Management System 1.0. Impacted is the function User::AuthenticateUser of the file login.php. Performing manipulation of the argument user_email results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2025-10592 | A security vulnerability has been detected in itsourcecode Online Public Access Catalog OPAC 1.0. A security vulnerability has been detected in itsourcecode Online Public Access Catalog OPAC 1.0. This impacts an unknown function of the file mysearch.php of the component POST Parameter Handler. Such manipulation of the argument search_field/search_text leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. NVD description · AI analysis pending | 2.1 | <1% | PoC |
| — | |
| CVE-2025-10404 +1 in the same advisory: …10405 | A vulnerability was found in itsourcecode Baptism Information Management System 1.0. A vulnerability was found in itsourcecode Baptism Information Management System 1.0. This impacts an unknown function of the file /rptbaptismal.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2025-10113 +1 in the same advisory: …10112 | A security vulnerability has been detected in itsourcecode Student Information Management System 1.0. A security vulnerability has been detected in itsourcecode Student Information Management System 1.0. This affects an unknown function of the file /admin/modules/room/index.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2025-10111 | A security flaw has been discovered in itsourcecode Student Information Management System 1.0. A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is an unknown function of the file /admin/modules/instructor/index.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be exploited. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2025-10062 | A vulnerability was determined in itsourcecode Student Information Management System 1.0. A vulnerability was determined in itsourcecode Student Information Management System 1.0. This affects an unknown part of the file /admin/login.php. Executing manipulation of the argument uname can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2025-9839 | A security flaw has been discovered in itsourcecode Student Information Management System 1.0. A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is an unknown function of the file /admin/modules/course/index.php. Performing manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2025-9595 | A vulnerability was found in code-projects Student Information Management System 1.0. A vulnerability was found in code-projects Student Information Management System 1.0. The impacted element is an unknown function of the file /login.php. The manipulation of the argument uname results in cross site scripting. The attack may be performed from a remote location. The exploit has been made public and could be used. NVD description · AI analysis pending | 2.1 | <1% | PoC |
| — | |
| CVE-2025-7182 | A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0 and classified as problematic. A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/modules/subject/edit.php. The manipulation of the argument pre leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NVD description · AI analysis pending | 2.1 | <1% | PoC |
| — | |
| CVE-2024-7495 | A vulnerability, which was classified as critical, was found in itsourcecode Laravel Accounting System 1.0. A vulnerability, which was classified as critical, was found in itsourcecode Laravel Accounting System 1.0. This affects an unknown part of the file app/Http/Controllers/HomeController.php. The manipulation of the argument image leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273621 was assigned to this vulnerability. NVD description · AI analysis pending | 5.3 | <1% | PoC |
| — | |
| CVE-2024-37873 | SQL injection vulnerability in view_payslip.php in Itsourcecode Payroll Management System Project In PHP With Source Code 1.0 allows remote attackers to execute SQL injection vulnerability in view_payslip.php in Itsourcecode Payroll Management System Project In PHP With Source Code 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2024-37870 | SQL injection vulnerability in processscore.php in Learning Management System Project In PHP With Source Code 1.0 allows attackers to execute arbitrary SQL comm SQL injection vulnerability in processscore.php in Learning Management System Project In PHP With Source Code 1.0 allows attackers to execute arbitrary SQL commands via the id parameter. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2024-6196 | A vulnerability was found in itsourcecode Banking Management System 1.0 and classified as critical. A vulnerability was found in itsourcecode Banking Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file admin_class.php. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-269168. NVD description · AI analysis pending | 6.9 | <1% | PoC |
| — | |
| CVE-2024-6195 +1 in the same advisory: …6194 | A vulnerability has been found in itsourcecode Tailoring Management System 1.0 and classified as critical. A vulnerability has been found in itsourcecode Tailoring Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file orderadd.php. The manipulation of the argument customer leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-269167. NVD description · AI analysis pending | 5.3 | <1% | PoC |
| — | |
| CVE-2024-6193 | A vulnerability, which was classified as critical, has been found in itsourcecode Vehicle Management System 1.0. A vulnerability, which was classified as critical, has been found in itsourcecode Vehicle Management System 1.0. This issue affects some unknown processing of the file driverprofile.php. The manipulation of the argument driverid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-269165 was assigned to this vulnerability. NVD description · AI analysis pending | 6.9 | <1% | PoC |
| — | |
| CVE-2024-37840 | SQL injection vulnerability in processscore.php in Itsourcecode Learning Management System Project In PHP With Source Code v1.0 allows remote attackers to execu SQL injection vulnerability in processscore.php in Itsourcecode Learning Management System Project In PHP With Source Code v1.0 allows remote attackers to execute arbitrary SQL commands via the LessonID parameter. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — |