CVE-2026-86278Medium· 4.3▾ TwilightPoC availableA vulnerability was found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The affected element is an unknown function of the file manage_subjects.php. The manipulation of the argument msg/title/content re…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 23.7 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
A vulnerability was found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The affected element is an unknown function of the file manage_subjects.php. The manipulation of the argument msg/title/content results in cross site scripting. The attack may be performed from remote. The exploit has been made public and could be used.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-94033Low· 3.5A vulnerability has been found in SourceCodester Drug Recommendation System 1.0
CVE-2026-94016Low· 2.4A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0
CVE-2026-92385Low· 2.4A vulnerability has been found in SourceCodester Online Food Ordering System 1.0
CVE-2026-90615Medium· 4.3A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0
CVE-2026-90695Low· 3.5A vulnerability was found in SourceCodester Inventory Management System 1.0
CVE-2026-90694Low· 3.5A vulnerability has been found in SourceCodester Inventory Management System 1.0