These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A vulnerability was found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The affected element is an unknown function of the file manage_subjects.php. The manipulation of the argument msg/title/content results in cross site scripting. The attack may be performed from remote. This vulnerability has a low CVSS score of 2.1 and is classified as low severity. Defenders should [truncated]
CVE-2026-86277 is a vulnerability in the SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The vulnerability is an authorization bypass in the file delete_exam.php, which can be exploited remotely. The exploit has been disclosed to the public and may be used. Defenders should assess exposure and prioritize verification and mitigation. The vulnerability has been disclosed to the [truncated]
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is the function mysqli_query of the file /admin/modal_add_room.php. The manipulation of the argument room_name leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected is the function mysqli_query of the file /admin/modal_add_product.php. Executing a manipulation of the argument fname can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. This sql injection vulnerability in SourceCodester Class and Exam Ti [truncated]
A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This SQL injection vulnerability impacts the mysqli_query function in /admin/modal_add_coursea.php, allowing remote exploitation via course argument manipulation. The exploit has been made public, increasing the likelihood of exploitation attempts. Defenders should verify exposure, assess potential impact, and prioritize re [truncated]
A SQL injection vulnerability was found in the SourceCodester Class and Exam Timetabling System 1.0, affecting the function mysqli_query of the file /admin/modal_add_course2.php. This vulnerability allows for SQL injection attacks that can be launched remotely. The exploit has been disclosed to the public and may be used. Defenders and administrators of systems using SourceCodester Class and Exam Timetabl [truncated]
A weakness has been identified in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This impacts the function saveUser of the file /public/submit.php. This manipulation of the argument Researcher causes sql injection. The attack may be initiated remotely. Evidence is limited; verify affected scope and vendor remediation status. Monitor for public exploit availability and adjust de [truncated]
The Simple Online Food Ordering System 1.0 is vulnerable to a SQL injection attack in the /admin/ajax.php?action=delete_category file. This vulnerability is caused by improper sanitization of user-supplied input in the ID argument, allowing remote attackers to inject malicious SQL code. The exploit has been publicly disclosed, and the CVSS score is 5.5 (Medium). Administrators and security teams responsib [truncated]
A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=save_category. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. Administrators and users of Simple On [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T04:17:38.277Z and has not been modified since then. This SQL injection vulnerability affects SourceCodester Simple Online Food Ordering System 1.0, specifically in the /admin/ajax.php?action=save_menu file, allowing remote attackers to inject malicious SQL code via the ID argument. System adminis [truncated]
A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0, specifically a SQL injection vulnerability in an unknown function of the file /admin/ajax.php?action=set_appointment. The vulnerability can be exploited remotely via the ID argument, and a public exploit is available. The affected system may be vulnerable to unauthorized data access or modification. Administrators and [truncated]
The SourceCodester Online Examination & Learning Management System 1.0 is vulnerable to an unrestricted file upload issue. This CVE record was published on 2026-08-06T22:16:53.773Z and has not been modified since then. The vulnerability affects the file upload_files.php, allowing remote attackers to potentially execute arbitrary code by uploading malicious files. The CVSS score is 5.3 and the severity is [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. CVE-2025-69941 is a critical SQL injection vulnerability in Tailor Management System 1.0, specifically in the addmeasurement.php file. The vulnerability has a CVSS score of 9.8 and is considered critical. The CVE record was published on 2026-07-30T21:16:52.777Z and has not been modified since then. The NVD entry is currently Deferred. Org [truncated]
A Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Fantastic Blog CMS 1.0, specifically in the pageEditMember.php file via the address field. The CVE record was published on 2026-07-29T21:17:45.760Z and was last modified on 2026-10-05T18:10:00.200Z. The NVD entry is currently Deferred. Defenders responsible for the security of Sourcecodester Fantastic Blog CMS 1.0 deployments should asses [truncated]
A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /BSIS.php. Performing a manipulation of the argument day results in cross site scripting. The attack may be initiated remotely. The exploit has been made public and could be used. Users should apply patches or mitigations to prevent cross-site scripting attacks.
A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0, affecting an unknown functionality of the file /class.php. Manipulation of the argument day leads to cross-site scripting, which can be launched remotely. The exploit has been disclosed to the public and may be used. Users should apply patches or mitigations to prevent cross-site scripting attacks. This issue has a CVS [truncated]
A SQL injection vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0, affecting an unknown function in the /edit_schoolyr.php file. The vulnerability can be exploited remotely through manipulation of the ID argument, leading to potential unauthorized access to sensitive data or system compromise. Users of the system should apply patches or mitigations to prevent SQL injection [truncated]
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /edit_subject.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. Users of SourceCodester Class and Exam Timetabling System 1.0 should apply vendor rem [truncated]
A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_settings of the file /admin/admin_class_novo.php. This manipulation of the argument img causes unrestricted upload. The attack is possible to be carried out remotely. The vulnerability has a CVSS score of 5.1 and a severity of MEDIUM. Users of SourceCodester Pizzafy Ecommerce System 1.0 should be [truncated]
A low-severity vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. The issue is related to cross-site scripting (XSS) in the /forCYS.php file. The attack vector is remote, and the exploit is publicly available. This vulnerability can be exploited by manipulating the course argument, leading to potential security risks for administrators and users of the system.
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /CYS.php. This manipulation of the argument course causes cross-site scripting. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The vulnerability is a cross-site scripting issue, and us [truncated]
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /forexam.php. The manipulation of the argument day results in cross site scripting. The vulnerability exists in the /forexam.php file of SourceCodester Class and Exam Timetabling System 1.0. An attacker can inject malicious scripts by manipulating the 'day' argument, leadin [truncated]
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. The vulnerability exists in the /schoolyr.php file and is caused by the manipulation of the argument sy, leading to cross-site scripting. The attack can be initiated remotely, and the exploit is publicly available. Users of the system should apply patches or mitigations to prevent cross-site scripting attacks. The CVSS [truncated]
A SQL injection vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. The vulnerability affects an unknown functionality of the file /edit_room1.php. A manipulation of the argument ID can lead to SQL injection. The attack may be performed remotely. This vulnerability has been publicly disclosed and may be utilized by attackers. Administrators and users of the system should be aw [truncated]
A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. The affected component is an unknown function of the file /edit_rooma.php. A manipulation of the argument ID results in SQL injection. The attack is possible to be carried out remotely. This vulnerability has a medium severity with a CVSS score of 5.5, indicating a moderate risk to affected systems.
A SQL injection vulnerability was discovered in SourceCodester Class and Exam Timetabling System 1.0. The vulnerability affects an unknown function of the file /edit_exam2.php. Performing a manipulation of the argument ID results in SQL injection. The attack can be initiated remotely. This vulnerability has a medium severity and requires attention from administrators and users of the system.
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is an unknown function of the file /subject.php. Such manipulation of the argument subject leads to cross site scripting. It is possible to launch the attack remotely. The vulnerability is a cross-site scripting (XSS) issue in the /subject.php file of SourceCodester Class and Exam Timetabling Syste [truncated]
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /forsubject.php. This manipulation of the argument subject causes cross-site scripting. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vulnerability is a cross-site scripting issue, and users should [truncated]
A low-severity LFI vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is an unknown function of the file /admin/index.php of the component Administrative Interface. Performing a manipulation of the argument page results in improper control of filename for include/require statement in php program. The vulnerability has a CVSS score of 2.1 and is considered low-s [truncated]
A security flaw has been discovered in SourceCodester Online Book Store System 1.0, affecting the file admin/login.php. The manipulation of the argument Username results in SQL injection, allowing for remote execution of SQL injection attacks. This vulnerability has a CVSS score of 5.5 and is classified as MEDIUM severity. Security teams and administrators responsible for SourceCodester Online Book Store [truncated]