CVE-2026-103115
A security flaw has been discovered in OS4ED openSIS-Classic up to 9.3. This affects an unknown function of the file functions/CustomFieldsF
CVSS
6.3
Medium
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 30, 2026 · Last modified: Sep 30, 2026 · CWE-74 · CWE-89
Not enough EPSS history yet.
A security flaw has been discovered in OS4ED openSIS-Classic up to 9.3. This affects an unknown function of the file functions/CustomFieldsFnc.php of the component Student Search. The manipulation of the argument cust results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-972938.5 HIG—
———Contributor SQL Injection in Media LIbrary Assistant <= 3.41 versions.4hCVE-2026-972878.5 HIG—
———Contributor SQL Injection in Event Tickets <= 5.29.5 versions.4hCVE-2026-968287.6 HIG—
———Administrator SQL Injection in Category Discount Woocommerce <= 5.18 versions.4hCVE-2026-968277.6 HIG—
———Administrator SQL Injection in Admin Notices Manager <= 1.6.0 versions.4hCVE-2026-968229.3 CRI—
———Unauthenticated SQL Injection in Books Gallery <= 4.8.3 versions.4hCVE-2026-963467.6 HIG—
———Author SQL Injection in WP ERP <= 1.17.9 versions.4h