Syllabus Aligned Learning Management Examination System Sourcecodester Syllabus Aligned Learning Management Examination System

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Sourcecodester Syllabus Aligned Learning Management Examination System.

By the Year

In 2026 there have been 9 vulnerabilities in Sourcecodester Syllabus Aligned Learning Management Examination System with an average score of 6.1 out of ten.

Year Vulnerabilities Average Score
2026 9 6.12

It may take a day or so for new Syllabus Aligned Learning Management Examination System vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Sourcecodester Syllabus Aligned Learning Management Examination System Security Vulnerabilities

CSRF in SourceCodester Syllabus-Aligned LMS 1.0
CVE-2026-86281 5.3 - Medium - September 07, 2026

A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This impacts an unknown function. Performing a manipulation results in cross-site request forgery. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.

Session Riding

SourceCodester LMS 1.0: Remote Cleartext Sensitive Data via cict_portal.sql
CVE-2026-86280 6.9 - Medium - September 07, 2026

A vulnerability was identified in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This affects an unknown function of the file cict_portal.sql. Such manipulation leads to cleartext storage of sensitive information. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

Cleartext Storage of Sensitive Information

SourceCodester SLA 1.0 Session Fixation via auth_process.php (CVE-2026-86279)
CVE-2026-86279 5.3 - Medium - September 07, 2026

A vulnerability was determined in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The impacted element is an unknown function of the file auth_process.php of the component Login. This manipulation causes session fixiation. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

Session Fixation

SourceCodester Syllabus-Aligned LMS 1.0 XSS via manage_subjects.php
CVE-2026-86278 5.3 - Medium - September 07, 2026

A vulnerability was found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The affected element is an unknown function of the file manage_subjects.php. The manipulation of the argument msg/title/content results in cross site scripting. The attack may be performed from remote. The exploit has been made public and could be used.

XSS

SourceCodester Syllabus-Aligned LMS 1.0 Auth Bypass in delete_exam.php via ID
CVE-2026-86277 6.9 - Medium - September 07, 2026

A vulnerability has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. Impacted is an unknown function of the file delete_exam.php. The manipulation of the argument ID leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.

Insecure Direct Object Reference / IDOR

SourceCodester Syllabus-Aligned LMAES 1.0 HCC via db.php Remote Exec
CVE-2026-86276 6.9 - Medium - September 07, 2026

A flaw has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This issue affects some unknown processing of the file db.php. Executing a manipulation can lead to hard-coded credentials. The attack can be executed remotely. The exploit has been published and may be used.

Use of Hard-coded Credentials

SourceCodester LMS 1.0 Privilege Escalation via Role Manipulation
CVE-2026-86275 6.9 - Medium - September 07, 2026

A vulnerability was detected in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This vulnerability affects the function register of the file auth.php. Performing a manipulation of the argument role results in improper privilege management. Remote exploitation of the attack is possible. The exploit is now public and may be used.

Improper Privilege Management

SourceCodester Syllabus-LM 1.0 Unrestricted File Upload via upload_files.php
CVE-2026-14698 6.3 - Medium - July 05, 2026

A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management and Examination System 1.0. Impacted is an unknown function of the file upload_files.php. Performing a manipulation results in unrestricted upload. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.

Unrestricted File Upload

Hardcoded password via raw_password in import_users.php (SourceCodester OLE LMS)
CVE-2026-11552 5.3 - Medium - June 08, 2026

A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System and Syllabus-aligned Learning Management and Examination System 1.0. Affected by this issue is some unknown functionality of the file import_users.php. The manipulation of the argument raw_password with the input CICT_2026 leads to use of hard-coded password. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. This product is distributed under two entirely different names.

Use of Hard-coded Password

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Sourcecodester Syllabus Aligned Learning Management Examination System or by Sourcecodester? Click the Watch button to subscribe.

subscribe