Sourcecodester Syllabus Aligned Learning Management Examination System
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Sourcecodester Syllabus Aligned Learning Management Examination System.
By the Year
In 2026 there have been 9 vulnerabilities in Sourcecodester Syllabus Aligned Learning Management Examination System with an average score of 6.1 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 9 | 6.12 |
It may take a day or so for new Syllabus Aligned Learning Management Examination System vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Sourcecodester Syllabus Aligned Learning Management Examination System Security Vulnerabilities
CSRF in SourceCodester Syllabus-Aligned LMS 1.0
CVE-2026-86281
5.3 - Medium
- September 07, 2026
A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This impacts an unknown function. Performing a manipulation results in cross-site request forgery. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
Session Riding
SourceCodester LMS 1.0: Remote Cleartext Sensitive Data via cict_portal.sql
CVE-2026-86280
6.9 - Medium
- September 07, 2026
A vulnerability was identified in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This affects an unknown function of the file cict_portal.sql. Such manipulation leads to cleartext storage of sensitive information. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Cleartext Storage of Sensitive Information
SourceCodester SLA 1.0 Session Fixation via auth_process.php (CVE-2026-86279)
CVE-2026-86279
5.3 - Medium
- September 07, 2026
A vulnerability was determined in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The impacted element is an unknown function of the file auth_process.php of the component Login. This manipulation causes session fixiation. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
Session Fixation
SourceCodester Syllabus-Aligned LMS 1.0 XSS via manage_subjects.php
CVE-2026-86278
5.3 - Medium
- September 07, 2026
A vulnerability was found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The affected element is an unknown function of the file manage_subjects.php. The manipulation of the argument msg/title/content results in cross site scripting. The attack may be performed from remote. The exploit has been made public and could be used.
XSS
SourceCodester Syllabus-Aligned LMS 1.0 Auth Bypass in delete_exam.php via ID
CVE-2026-86277
6.9 - Medium
- September 07, 2026
A vulnerability has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. Impacted is an unknown function of the file delete_exam.php. The manipulation of the argument ID leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
Insecure Direct Object Reference / IDOR
SourceCodester Syllabus-Aligned LMAES 1.0 HCC via db.php Remote Exec
CVE-2026-86276
6.9 - Medium
- September 07, 2026
A flaw has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This issue affects some unknown processing of the file db.php. Executing a manipulation can lead to hard-coded credentials. The attack can be executed remotely. The exploit has been published and may be used.
Use of Hard-coded Credentials
SourceCodester LMS 1.0 Privilege Escalation via Role Manipulation
CVE-2026-86275
6.9 - Medium
- September 07, 2026
A vulnerability was detected in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This vulnerability affects the function register of the file auth.php. Performing a manipulation of the argument role results in improper privilege management. Remote exploitation of the attack is possible. The exploit is now public and may be used.
Improper Privilege Management
SourceCodester Syllabus-LM 1.0 Unrestricted File Upload via upload_files.php
CVE-2026-14698
6.3 - Medium
- July 05, 2026
A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management and Examination System 1.0. Impacted is an unknown function of the file upload_files.php. Performing a manipulation results in unrestricted upload. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
Unrestricted File Upload
Hardcoded password via raw_password in import_users.php (SourceCodester OLE LMS)
CVE-2026-11552
5.3 - Medium
- June 08, 2026
A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System and Syllabus-aligned Learning Management and Examination System 1.0. Affected by this issue is some unknown functionality of the file import_users.php. The manipulation of the argument raw_password with the input CICT_2026 leads to use of hard-coded password. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. This product is distributed under two entirely different names.
Use of Hard-coded Password
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Sourcecodester Syllabus Aligned Learning Management Examination System or by Sourcecodester? Click the Watch button to subscribe.