CVE-2026-103116
A weakness has been identified in OS4ED openSIS-Classic up to 9.3. This impacts the function DBQuery of the file functions/GetStuListFnc.php
CVSS
6.3
Medium
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 30, 2026 · Last modified: Sep 30, 2026 · CWE-74 · CWE-89
Not enough EPSS history yet.
A weakness has been identified in OS4ED openSIS-Classic up to 9.3. This impacts the function DBQuery of the file functions/GetStuListFnc.php of the component Student List Search Endpoint. This manipulation of the argument LO_sort causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-972938.5 HIG—
———Contributor SQL Injection in Media LIbrary Assistant <= 3.41 versions.4hCVE-2026-972878.5 HIG—
———Contributor SQL Injection in Event Tickets <= 5.29.5 versions.4hCVE-2026-968287.6 HIG—
———Administrator SQL Injection in Category Discount Woocommerce <= 5.18 versions.4hCVE-2026-968277.6 HIG—
———Administrator SQL Injection in Admin Notices Manager <= 1.6.0 versions.4hCVE-2026-968229.3 CRI—
———Unauthenticated SQL Injection in Books Gallery <= 4.8.3 versions.4hCVE-2026-963467.6 HIG—
———Author SQL Injection in WP ERP <= 1.17.9 versions.4h