itsourcecode has 33 CVEs on record between 2025 and 2026. Disclosure cadence is accelerating: 32 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 32. The median CVSS is 6.3 (medium). None have a confirmed exploitation report. The dominant weakness classes are CWE-74 (32) and CWE-89 (32). Most affected products: Sales and Inventory System (22), Leave Management System (6), Information System Society Membership System (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.3
- Publish → KEV
- —
- Last 90 days
- 32 prev 0
Products
- Sales and Inventory System 22
- Leave Management System 6
- Information System Society Membership System 1
- Loan Management System 1
- Online Medicine Delivery System 1
- School Management System 1
Worst active — by depth score
CVE-2026-90789High· 7.3A weakness has been identified in itsourcecode Leave Management System 1.052CVE-2026-86268High· 7.3A vulnerability was detected in itsourcecode School Management System 1.052CVE-2026-92364Medium· 6.3A vulnerability has been found in itsourcecode Leave Management System 1.047CVE-2026-90796Medium· 6.3A vulnerability was identified in itsourcecode Leave Management System 1.047CVE-2026-90700Medium· 6.3A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.047
itsourcecode vulnerabilities
CVEs affecting itsourcecode, newest first. Open any entry for full detail, references, and exploit status.
33 CVEsRSS
CVE-2026-94032Medium· 6.3A flaw has been found in itsourcecode Leave Management System 1.0
A flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown part of the file /module/department/index.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack re…
CVE-2026-93963Medium· 6.3A security vulnerability has been detected in itsourcecode Leave Management System 1.0
A security vulnerability has been detected in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/department/controller.php. The manipulation of the argument DEPTID leads to sql injection. The a…
CVE-2026-92526Medium· 6.3A flaw has been found in itsourcecode Leave Management System 1.0
A flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/leave/index.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched re…
CVE-2026-92364Medium· 6.3PoCA vulnerability has been found in itsourcecode Leave Management System 1.0
A vulnerability has been found in itsourcecode Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /module/employee/index.php. The manipulation of the argument ID leads to sql injection. It…
CVE-2026-90796Medium· 6.3PoCA vulnerability was identified in itsourcecode Leave Management System 1.0
A vulnerability was identified in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/company/index.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated r…
CVE-2026-90795Medium· 4.3PoCA vulnerability was determined in itsourcecode Loan Management System 1.0
A vulnerability was determined in itsourcecode Loan Management System 1.0. The impacted element is an unknown function of the file navbar.php. Executing a manipulation of the argument page can lead to cross site scripting. It is possible…
CVE-2026-90700Medium· 6.3PoCA security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0
A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/pro_edit1.php. Such manipulation of the argument prodcode leads to sql injection. The attack ca…
CVE-2026-90789High· 7.3PoCA weakness has been identified in itsourcecode Leave Management System 1.0
A weakness has been identified in itsourcecode Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Executing a manipulation of the argument user_email can lead to sql injection. The a…
CVE-2026-90574Medium· 6.3PoCA security flaw has been discovered in itsourcecode Sales and Inventory System 1.0
A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/emp_transac.php?action=add. The manipulation of the argument firstname results in sql injection. The …
CVE-2026-90525Medium· 6.3PoCA weakness has been identified in itsourcecode Sales and Inventory System 1.0
A weakness has been identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/cust_pos_trans.php. Executing a manipulation of the argument firstname can lead to sql injection. The atta…
CVE-2026-90600Medium· 6.3PoCA vulnerability has been found in itsourcecode Sales and Inventory System 1.0
A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/inv_edit1.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated rem…
CVE-2026-90597Medium· 6.3PoCA security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0
A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/sup_edit1.php. Such manipulation of the argument ID leads to sql injection. The att…
CVE-2026-86675Medium· 6.3PoCA vulnerability was identified in itsourcecode Sales and Inventory System 1.0
A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown part of the file /pages/us_edit.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely.…
CVE-2026-86517Medium· 6.3PoCA flaw has been found in itsourcecode Sales and Inventory System 1.0
A flaw has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is the function mysqli_query of the file /pages/us_searchfrm.php. Executing a manipulation of the argument ID can lead to sql injection. It is pos…
CVE-2026-86310Medium· 6.3PoCA vulnerability has been found in itsourcecode Sales and Inventory System 1.0
A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/cust_edit1.php. Such manipulation of the argument ID leads to sql injection. The attack can be …
CVE-2026-86309Medium· 6.3PoCA flaw has been found in itsourcecode Sales and Inventory System 1.0
A flaw has been found in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/pro_searchfrm.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. …
CVE-2026-86291Medium· 6.3PoCA security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0
A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/us_edit1.php. Such manipulation of the argument ID leads to sql injection. The attack can be l…
CVE-2026-86270Medium· 6.3PoCA vulnerability has been found in itsourcecode Sales and Inventory System 1.0
A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is an unknown function of the file /pages/settings_edit.php. Such manipulation of the argument ID leads to sql injection. The attack may …
CVE-2026-86269Medium· 6.3PoCA flaw has been found in itsourcecode Sales and Inventory System 1.0
A flaw has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/emp_edit1.php. This manipulation of the argument ID causes sql injection. The attack is possible to be c…
CVE-2026-86268High· 7.3PoCA vulnerability was detected in itsourcecode School Management System 1.0
A vulnerability was detected in itsourcecode School Management System 1.0. Impacted is an unknown function of the file User_Login.php. The manipulation of the argument email results in sql injection. The attack can be executed remotely. …
CVE-2026-86267Medium· 6.3PoCA security vulnerability has been detected in itsourcecode Information System Society Membership System 1.0
A security vulnerability has been detected in itsourcecode Information System Society Membership System 1.0. This issue affects some unknown processing of the file /society/check_student.php. The manipulation of the argument student_id l…
CVE-2026-86265Medium· 6.3PoCA vulnerability has been found in itsourcecode Sales and Inventory System 1.0
A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/us_transac.php. Such manipulation of the argument Username leads to sql injectio…
CVE-2026-86245Medium· 6.3PoCA vulnerability was detected in itsourcecode Sales and Inventory System 1.0
A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_transac.php. Performing a manipulation of the argument companyname results in …
CVE-2026-86236Medium· 6.3PoCA vulnerability has been found in itsourcecode Sales and Inventory System 1.0
A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This issue affects some unknown processing of the file /pages/pro_transac.php?action=add. Such manipulation of the argument Name leads to sql injection. The a…
CVE-2026-86235Medium· 6.3PoCA flaw has been found in itsourcecode Sales and Inventory System 1.0
A flaw has been found in itsourcecode Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /pages/pos_transac.php?action=add. This manipulation of the argument Customer causes sql injection. The attack can …
CVE-2026-86234Medium· 6.3PoCA vulnerability was detected in itsourcecode Sales and Inventory System 1.0
A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. This affects an unknown part of the file /pages/cust_transac.php?action=add. The manipulation of the argument firstname results in sql injection. It is possible…
CVE-2026-86233Medium· 6.3PoCA security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0
A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /pages/us_del.php?type=user. The manipulation of the argument ID leads to sql inj…
CVE-2026-86232Medium· 6.3PoCA weakness has been identified in itsourcecode Sales and Inventory System 1.0
A weakness has been identified in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_del.php?type=supplier. Executing a manipulation of the argument ID can lead …
CVE-2026-86164Medium· 6.3PoCA security flaw has been discovered in itsourcecode Sales and Inventory System 1.0
A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/trans_view.php. The manipulation of the argument ID results in sql injection. The attack may be perfor…
CVE-2026-86163Medium· 6.3PoCA vulnerability was identified in itsourcecode Sales and Inventory System 1.0
A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/pro_del.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carr…