Skip to main content
QUIETLYTIC
Vulnerability

7 SourceCodester Class and Exam Timetabling System 1.0 CVEs (CVE-2026-86220)

Seven separate CVEs (CVE-2026-86220 through 86225 and 86298) document the same unauthenticated SQL injection flaw repeated across different admin panel files in SourceCodester Class and Exam Timetabling System 1.0, with public exploit code for each.

CVE-2026-86220
Threat Level
HIGH
CVSS
7.3
Status
Monitored
Confidence
Medium
Affected Products
SourceCodester Class and Exam Timetabling System 1.0

Full CVE Roster

All 7 CVEs from this release, ready to paste into a tracker, ticket, or SIEM search.

CVE ID Title CVSS Severity KEV
CVE-2026-86220 — 7.3 high
CVE-2026-86221 — 7.3 high
CVE-2026-86222 — 7.3 high
CVE-2026-86223 — 7.3 high
CVE-2026-86224 — 7.3 high
CVE-2026-86225 — 7.3 high
CVE-2026-86298 — 7.3 high

Seven separate CVE IDs — CVE-2026-86220, 86221, 86222, 86223, 86224, 86225, and 86298 — document the same underlying flaw, each in a different admin-panel file of SourceCodester’s Class and Exam Timetabling System 1.0. Rather than publish seven near-identical pages, this article covers all seven together, since they share one root cause, one CVSS score, and one remediation.

What the vulnerability does

Per NVD’s descriptions, each affected admin file (modal_add_course.php, modal_add_course1.php, modal_add_course2.php, modal_add_coursea.php, modal_add_product.php, modal_add_room.php, and delete_subject.php) passes a user-controlled parameter — course, fname, room_name, or ID depending on the file — directly into a mysqli_query() call without parameterization, allowing SQL injection. NVD’s descriptions state the attack can be launched remotely and that exploit code is public for each of the seven.

The CVSS vector (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L pattern, base score 7.3 across all seven) reflects a network-reachable, low-complexity flaw requiring low privileges, with limited impact across confidentiality, integrity, and availability — consistent with SQL injection against a database-backed admin panel rather than full system compromise.

What we don’t yet have

These records trace to NVD and VulDB submission entries; no CISA KEV listing or vendor-issued patch is documented in our ingested data. Confidence is medium, and no fixed version is referenced — SourceCodester is a marketplace for free/open student and small-business project templates rather than a maintained commercial vendor, so a formal patch release for this specific product is not guaranteed.

Why this matters

The repeated pattern across seven separate files — the same unsanitized-query mistake copy-pasted into six admin “add” modals and one delete handler — points to a systemic coding practice in this codebase rather than seven isolated bugs, meaning any deployment of this application likely has additional unreported instances of the same flaw beyond these seven. Given the “low privilege required” access level, any authenticated (even low-privilege) user of an affected deployment can extract or manipulate data via the vulnerable query. Organizations running this software should audit all mysqli_query() call sites for the same unparameterized-input pattern, not just patch the seven reported files.

Frequently Asked Questions

What are CVE-2026-86220 through 86225 and CVE-2026-86298? Seven separate CVE IDs for the same SQL injection vulnerability class, each in a different admin-panel file of SourceCodester Class and Exam Timetabling System 1.0 — all CVSS 7.3.

Is exploit code available for these vulnerabilities? Yes, per NVD’s descriptions — public exploit code exists for each of the seven, though this is distinct from confirmed active exploitation.

Are these vulnerabilities being actively exploited? No evidence of active exploitation has been reported as of this writing; none are listed in CISA’s KEV catalog.


Data sourced from the National Vulnerability Database (NVD) and VulDB, aggregated September 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulDB

Related intelligence


Analyst tools