itsourcecode has 33 CVEs on record between 2025 and 2026. Disclosure cadence is accelerating: 32 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 32. The median CVSS is 6.3 (medium). None have a confirmed exploitation report. The dominant weakness classes are CWE-74 (32) and CWE-89 (32). Most affected products: Sales and Inventory System (22), Leave Management System (6), Information System Society Membership System (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.3
- Publish → KEV
- —
- Last 90 days
- 32 prev 0
Products
- Sales and Inventory System 22
- Leave Management System 6
- Information System Society Membership System 1
- Loan Management System 1
- Online Medicine Delivery System 1
- School Management System 1
Worst active — by depth score
CVE-2026-90789High· 7.3A weakness has been identified in itsourcecode Leave Management System 1.052CVE-2026-86268High· 7.3A vulnerability was detected in itsourcecode School Management System 1.052CVE-2026-93963Medium· 6.3A security vulnerability has been detected in itsourcecode Leave Management System 1.047CVE-2026-92364Medium· 6.3A vulnerability has been found in itsourcecode Leave Management System 1.047CVE-2026-90796Medium· 6.3A vulnerability was identified in itsourcecode Leave Management System 1.047
itsourcecode vulnerabilities
CVEs affecting itsourcecode, newest first. Open any entry for full detail, references, and exploit status.
33 CVEsRSS
CVE-2026-85383Medium· 6.3PoCitsourcecode Sales and Inventory System inv_del.php sql injection
A flaw has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/inv_del.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be ex…
CVE-2026-85205Medium· 6.3A vulnerability was determined in itsourcecode Online Medicine Delivery System 1.0
A vulnerability was determined in itsourcecode Online Medicine Delivery System 1.0. This issue affects the function addwishlist of the file /customer/controller.php?action=addwish of the component Wishlist. This manipulation of the argum…
CVE-2025-10592Medium· 6.3A security vulnerability has been detected in itsourcecode Online Public Access Catalog OPAC 1.0
A security vulnerability has been detected in itsourcecode Online Public Access Catalog OPAC 1.0. This impacts an unknown function of the file mysearch.php of the component POST Parameter Handler. Such manipulation of the argument search…