CVE-2026-86168
A security flaw has been discovered in code-projects Content Management System 1.0. The affected element is an unknown function of the file
CVSS
7.3
High
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 6, 2026 · Last modified: Sep 6, 2026 · CWE-74 · CWE-89
Not enough EPSS history yet.
A security flaw has been discovered in code-projects Content Management System 1.0. The affected element is an unknown function of the file /login.php. The manipulation of the argument user_name results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
- code-projects.orghttps://code-projects.org/
- github.comhttps://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/SQL%20Injection%20Vulnerability%20in%20Content%20Management%20System%20%60user_name%60%20Parameter.md
- vuldb.comhttps://vuldb.com/cve/CVE-2026-86168
- vuldb.comhttps://vuldb.com/submit/895608
- vuldb.comhttps://vuldb.com/vuln/399307
- vuldb.comhttps://vuldb.com/vuln/399307/cti
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-861706.3 MED—
———A weakness has been identified in DefaultFuction CRM 1.0.0. The impacted element is an unknown function of the file /modules/orders/edit.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.6hCVE-2026-861646.3 MED—
———A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/trans_view.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.8hCVE-2026-861636.3 MED—
———A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/pro_del.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.8hCVE-2026-861627.3 HIG—
———A vulnerability was determined in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /ajax.php?action=login. Executing a manipulation of the argument Username can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.9hCVE-2026-861617.3 HIG—
———A vulnerability was found in SourceCodester Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=delete_category. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.9hCVE-2026-861607.3 HIG—
———A vulnerability has been found in SourceCodester Online Voting System 1.0. The affected element is an unknown function of the file /ajax.php?action=delete_voting. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.9h