CVE-2026-65494
Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions.
CVSS
7.1
High
EPSS
0.3%
p21
KEV
—
Exploit Today
6
0-100
Published: Jul 23, 2026 · Last modified: Jul 23, 2026 · CWE-89
0.3%EPSS · 30 days0.3%
2026-08-092026-09-05
Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-862706.3 MED—
———A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is an unknown function of the file /pages/settings_edit.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.2hCVE-2026-862696.3 MED—
———A flaw has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/emp_edit1.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.3hCVE-2026-862687.3 HIG—
———A vulnerability was detected in itsourcecode School Management System 1.0. Impacted is an unknown function of the file User_Login.php. The manipulation of the argument email results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.3hCVE-2026-862676.3 MED—
———A security vulnerability has been detected in itsourcecode Information System Society Membership System 1.0. This issue affects some unknown processing of the file /society/check_student.php. The manipulation of the argument student_id leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.3hCVE-2026-862656.3 MED—
———A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/us_transac.php. Such manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.3hCVE-2026-862456.3 MED—
———A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_transac.php. Performing a manipulation of the argument companyname results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.5h