Five separate CVE IDs — CVE-2026-86232, 86233, 86234, 86235, and 86236 — document the same underlying SQL injection flaw, each in a different page of itsourcecode’s Sales and Inventory System 1.0. As with the SourceCodester Class and Exam Timetabling System findings covered separately, this article treats all five together rather than publishing five near-identical pages.
What the vulnerability does
Per NVD’s descriptions, each affected page (/pages/sup_del.php, /pages/us_del.php, /pages/cust_transac.php, /pages/pos_transac.php, and /pages/pro_transac.php) passes a user-controlled parameter — ID, firstname, Customer, or Name depending on the page — directly into a database query without sanitization, resulting in SQL injection. NVD’s descriptions state each is remotely exploitable with public exploit code available.
The CVSS 3.1 base score of 6.3 (medium) across all five is lower than the SourceCodester cluster’s 7.3, reflecting a lower-privilege access requirement and narrower confidentiality/integrity/availability impact per NVD’s vector scoring for this application.
What we don’t yet have
These records trace to NVD and VulDB submission entries; no CISA KEV listing or vendor-issued patch is documented. Confidence is medium — itsourcecode, like SourceCodester, distributes free/low-cost student and small-business project templates rather than maintaining them as commercial software with a formal patch cadence.
Why this matters
Five separate injectable endpoints across delete, add, and transaction pages point to the same systemic pattern already noted for SourceCodester’s product: unsanitized query construction copy-pasted across multiple handlers in the same codebase. Any deployment of this application should assume additional unreported instances of the same flaw exist beyond these five, and audit all database query construction rather than patching only the specific reported files.
Frequently Asked Questions
What are CVE-2026-86232 through 86236? Five separate CVE IDs for the same SQL injection vulnerability class, each in a different page of itsourcecode Sales and Inventory System 1.0 — all CVSS 6.3.
Is exploit code available for these vulnerabilities? Yes, per NVD’s descriptions — public exploit code exists for each of the five.
Are these vulnerabilities being actively exploited? No evidence of active exploitation has been reported as of this writing; none are listed in CISA’s KEV catalog.
Data sourced from the National Vulnerability Database (NVD) and VulDB, aggregated September 2026. See more vulnerability intelligence.