CVE-2026-86267Medium· 6.3▾ TwilightPoC availableA security vulnerability has been detected in itsourcecode Information System Society Membership System 1.0. This issue affects some unknown processing of the file /society/check_student.php. The manipulation of the argument student_id l…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 34.7 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
A security vulnerability has been detected in itsourcecode Information System Society Membership System 1.0. This issue affects some unknown processing of the file /society/check_student.php. The manipulation of the argument student_id leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-93963Medium· 6.3A security vulnerability has been detected in itsourcecode Leave Management System 1.0
CVE-2026-92364Medium· 6.3A vulnerability has been found in itsourcecode Leave Management System 1.0
CVE-2026-90796Medium· 6.3A vulnerability was identified in itsourcecode Leave Management System 1.0
CVE-2026-90574Medium· 6.3A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0
CVE-2026-90525Medium· 6.3A weakness has been identified in itsourcecode Sales and Inventory System 1.0
CVE-2026-90600Medium· 6.3A vulnerability has been found in itsourcecode Sales and Inventory System 1.0