Seven separate CVE IDs — CVE-2026-86220, 86221, 86222, 86223, 86224, 86225, and 86298 — document the same underlying flaw, each in a different admin-panel file of SourceCodester’s Class and Exam Timetabling System 1.0. Rather than publish seven near-identical pages, this article covers all seven together, since they share one root cause, one CVSS score, and one remediation.
What the vulnerability does
Per NVD’s descriptions, each affected admin file (modal_add_course.php, modal_add_course1.php, modal_add_course2.php, modal_add_coursea.php, modal_add_product.php, modal_add_room.php, and delete_subject.php) passes a user-controlled parameter — course, fname, room_name, or ID depending on the file — directly into a mysqli_query() call without parameterization, allowing SQL injection. NVD’s descriptions state the attack can be launched remotely and that exploit code is public for each of the seven.
The CVSS vector (AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L pattern, base score 7.3 across all seven) reflects a network-reachable, low-complexity flaw requiring low privileges, with limited impact across confidentiality, integrity, and availability — consistent with SQL injection against a database-backed admin panel rather than full system compromise.
What we don’t yet have
These records trace to NVD and VulDB submission entries; no CISA KEV listing or vendor-issued patch is documented in our ingested data. Confidence is medium, and no fixed version is referenced — SourceCodester is a marketplace for free/open student and small-business project templates rather than a maintained commercial vendor, so a formal patch release for this specific product is not guaranteed.
Why this matters
The repeated pattern across seven separate files — the same unsanitized-query mistake copy-pasted into six admin “add” modals and one delete handler — points to a systemic coding practice in this codebase rather than seven isolated bugs, meaning any deployment of this application likely has additional unreported instances of the same flaw beyond these seven. Given the “low privilege required” access level, any authenticated (even low-privilege) user of an affected deployment can extract or manipulate data via the vulnerable query. Organizations running this software should audit all mysqli_query() call sites for the same unparameterized-input pattern, not just patch the seven reported files.
Frequently Asked Questions
What are CVE-2026-86220 through 86225 and CVE-2026-86298? Seven separate CVE IDs for the same SQL injection vulnerability class, each in a different admin-panel file of SourceCodester Class and Exam Timetabling System 1.0 — all CVSS 7.3.
Is exploit code available for these vulnerabilities? Yes, per NVD’s descriptions — public exploit code exists for each of the seven, though this is distinct from confirmed active exploitation.
Are these vulnerabilities being actively exploited? No evidence of active exploitation has been reported as of this writing; none are listed in CISA’s KEV catalog.
Data sourced from the National Vulnerability Database (NVD) and VulDB, aggregated September 2026. See more vulnerability intelligence.