Skip to main content
QUIETLYTIC
Vulnerability

5 itsourcecode Sales and Inventory System 1.0 CVEs (CVE-2026-86232)

Five separate CVEs (CVE-2026-86232 through 86236) document the same unauthenticated SQL injection flaw repeated across different pages of itsourcecode Sales and Inventory System 1.0, with public exploit code for each.

CVE-2026-86232
Threat Level
MEDIUM
CVSS
6.3
Status
Monitored
Confidence
Medium
Affected Products
itsourcecode Sales and Inventory System 1.0

Full CVE Roster

All 5 CVEs from this release, ready to paste into a tracker, ticket, or SIEM search.

CVE ID Title CVSS Severity KEV
CVE-2026-86232 — 6.3 medium
CVE-2026-86233 — 6.3 medium
CVE-2026-86234 — 6.3 medium
CVE-2026-86235 — 6.3 medium
CVE-2026-86236 — 6.3 medium

Five separate CVE IDs — CVE-2026-86232, 86233, 86234, 86235, and 86236 — document the same underlying SQL injection flaw, each in a different page of itsourcecode’s Sales and Inventory System 1.0. As with the SourceCodester Class and Exam Timetabling System findings covered separately, this article treats all five together rather than publishing five near-identical pages.

What the vulnerability does

Per NVD’s descriptions, each affected page (/pages/sup_del.php, /pages/us_del.php, /pages/cust_transac.php, /pages/pos_transac.php, and /pages/pro_transac.php) passes a user-controlled parameter — ID, firstname, Customer, or Name depending on the page — directly into a database query without sanitization, resulting in SQL injection. NVD’s descriptions state each is remotely exploitable with public exploit code available.

The CVSS 3.1 base score of 6.3 (medium) across all five is lower than the SourceCodester cluster’s 7.3, reflecting a lower-privilege access requirement and narrower confidentiality/integrity/availability impact per NVD’s vector scoring for this application.

What we don’t yet have

These records trace to NVD and VulDB submission entries; no CISA KEV listing or vendor-issued patch is documented. Confidence is medium — itsourcecode, like SourceCodester, distributes free/low-cost student and small-business project templates rather than maintaining them as commercial software with a formal patch cadence.

Why this matters

Five separate injectable endpoints across delete, add, and transaction pages point to the same systemic pattern already noted for SourceCodester’s product: unsanitized query construction copy-pasted across multiple handlers in the same codebase. Any deployment of this application should assume additional unreported instances of the same flaw exist beyond these five, and audit all database query construction rather than patching only the specific reported files.

Frequently Asked Questions

What are CVE-2026-86232 through 86236? Five separate CVE IDs for the same SQL injection vulnerability class, each in a different page of itsourcecode Sales and Inventory System 1.0 — all CVSS 6.3.

Is exploit code available for these vulnerabilities? Yes, per NVD’s descriptions — public exploit code exists for each of the five.

Are these vulnerabilities being actively exploited? No evidence of active exploitation has been reported as of this writing; none are listed in CISA’s KEV catalog.


Data sourced from the National Vulnerability Database (NVD) and VulDB, aggregated September 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulDB

Related intelligence


Analyst tools