{"schema_version":1,"title":"Sambitraj STUDENT-MANAGEMENT-SYSTEM vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 26 vulnerabilities in Sambitraj STUDENT-MANAGEMENT-SYSTEM: 0 in the last 7 days and 10 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-86674, was published on 8 September 2026.","url":"https://junglewise.ai/threats/technologies/student-management-system","json_url":"https://junglewise.ai/threats/technologies/student-management-system.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/student-management-system","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":8,"all_time":26,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":7,"last_90_days":10,"last_365_days":26},"latest":[{"cve":"CVE-2026-86674","cvss":6.3,"epss":0.0038,"slug":"cve-2026-86674-ningzichun-student-management-system-session-fixation-in-login","title":"ningzichun Student Management System session fixation in login","severity":"medium","exploited":false,"published_at":"2026-09-08T19:20:16.963+00:00","url":"https://junglewise.ai/threats/cve-2026-86674-ningzichun-student-management-system-session-fixation-in-login"},{"cve":"CVE-2026-86673","cvss":7.3,"epss":0.0047,"slug":"cve-2026-86673-ningzichun-student-management-system-hard-coded-database","title":"ningzichun Student Management System hard-coded database credentials","severity":"high","exploited":false,"published_at":"2026-09-08T18:21:17.727+00:00","url":"https://junglewise.ai/threats/cve-2026-86673-ningzichun-student-management-system-hard-coded-database"},{"cve":"CVE-2026-86672","cvss":5.3,"epss":0.0048,"slug":"cve-2026-86672-ningzichun-student-management-system-exposed-backup-file","title":"ningzichun Student Management System exposed backup file","severity":"medium","exploited":false,"published_at":"2026-09-08T18:21:17.553+00:00","url":"https://junglewise.ai/threats/cve-2026-86672-ningzichun-student-management-system-exposed-backup-file"},{"cve":"CVE-2026-82699","cvss":2.7,"epss":0.0025,"slug":"cve-2026-82699-sambitraj-student-management-system-cleartext-password-storage","title":"sambitraj Student Management System cleartext password storage","severity":"low","exploited":false,"published_at":"2026-08-31T14:17:27.17+00:00","url":"https://junglewise.ai/threats/cve-2026-82699-sambitraj-student-management-system-cleartext-password-storage"},{"cve":"CVE-2026-82698","cvss":5.3,"epss":0.0053,"slug":"cve-2026-82698-sambitraj-student-management-system-use-of-default-password","title":"sambitraj Student-Management-System use of default password","severity":"medium","exploited":false,"published_at":"2026-08-31T14:17:26.98+00:00","url":"https://junglewise.ai/threats/cve-2026-82698-sambitraj-student-management-system-use-of-default-password"},{"cve":"CVE-2026-82697","cvss":3.7,"epss":0.0046,"slug":"cve-2026-82697-sambitraj-student-management-system-insecure-session-cookie-in","title":"sambitraj Student-Management-System insecure session cookie in login","severity":"low","exploited":false,"published_at":"2026-08-31T14:17:26.783+00:00","url":"https://junglewise.ai/threats/cve-2026-82697-sambitraj-student-management-system-insecure-session-cookie-in"},{"cve":"CVE-2026-82553","cvss":6.3,"epss":0.0035,"slug":"cve-2026-82553-sambitraj-student-management-system-authorization-bypass-in","title":"sambitraj Student Management System authorization bypass in dashboard","severity":"medium","exploited":false,"published_at":"2026-08-30T17:16:39.547+00:00","url":"https://junglewise.ai/threats/cve-2026-82553-sambitraj-student-management-system-authorization-bypass-in"},{"cve":"CVE-2026-78057","cvss":6.3,"epss":0.0033,"slug":"cve-2026-78057-sambitraj-student-management-system-sql-injection-in-management","title":"sambitraj Student Management System SQL injection in management mutation handlers","severity":"medium","exploited":false,"published_at":"2026-08-23T03:16:59.977+00:00","url":"https://junglewise.ai/threats/cve-2026-78057-sambitraj-student-management-system-sql-injection-in-management"},{"cve":"CVE-2026-78056","cvss":6.3,"epss":0.0033,"slug":"cve-2026-78056-sambitraj-student-management-system-sql-injection-in-dashboard","title":"sambitraj Student-Management-System SQL injection in Dashboard","severity":"medium","exploited":false,"published_at":"2026-08-23T03:16:59.777+00:00","url":"https://junglewise.ai/threats/cve-2026-78056-sambitraj-student-management-system-sql-injection-in-dashboard"},{"cve":"CVE-2026-18927","cvss":6.3,"epss":0.0035,"slug":"cve-2026-18927-imranrisal-dev-student-management-system-unrestricted-file-upload","title":"imranrisal-dev Student-Management-System unrestricted file upload in profile image handler","severity":"medium","exploited":false,"published_at":"2026-08-05T17:16:46.24+00:00","url":"https://junglewise.ai/threats/cve-2026-18927-imranrisal-dev-student-management-system-unrestricted-file-upload"},{"cve":"CVE-2026-11534","cvss":3.5,"slug":"cve-2026-11534-imvks786-student-management-system-stored-xss-in-add-php","title":"imvks786 student_management_system stored XSS in add.php","severity":"low","exploited":false,"published_at":"2026-06-08T17:16:40.763+00:00","url":"https://junglewise.ai/threats/cve-2026-11534-imvks786-student-management-system-stored-xss-in-add-php"},{"cve":"CVE-2026-11533","cvss":5.4,"slug":"cve-2026-11533-imvks786-student-management-system-improper-authorization-in-see","title":"imvks786 Student Management System improper authorization in see.php","severity":"medium","exploited":false,"published_at":"2026-06-08T17:16:40.563+00:00","url":"https://junglewise.ai/threats/cve-2026-11533-imvks786-student-management-system-improper-authorization-in-see"},{"cve":"CVE-2026-11532","cvss":6.3,"slug":"cve-2026-11532-imvks786-student-management-system-improper-access-control-in","title":"imvks786 student_management_system improper access control in Student Record Handler","severity":"medium","exploited":false,"published_at":"2026-06-08T17:16:40.363+00:00","url":"https://junglewise.ai/threats/cve-2026-11532-imvks786-student-management-system-improper-access-control-in"},{"cve":"CVE-2026-11531","cvss":7.3,"slug":"cve-2026-11531-imvks786-student-management-system-sql-injection-in-admin-login","title":"imvks786 student_management_system SQL injection in admin_login.php","severity":"high","exploited":false,"published_at":"2026-06-08T17:16:40.2+00:00","url":"https://junglewise.ai/threats/cve-2026-11531-imvks786-student-management-system-sql-injection-in-admin-login"},{"cve":"CVE-2026-11530","cvss":7.3,"slug":"cve-2026-11530-imvks786-student-management-system-sql-injection-in-login","title":"imvks786 student_management_system SQL injection in Login component","severity":"high","exploited":false,"published_at":"2026-06-08T17:16:40.017+00:00","url":"https://junglewise.ai/threats/cve-2026-11530-imvks786-student-management-system-sql-injection-in-login"},{"cve":"CVE-2026-11476","cvss":6.3,"slug":"cve-2026-11476-kushan2k-student-management-system-improper-authorization-in","title":"Kushan2k student-management-system improper authorization in Profile Update Endpoint","severity":"medium","exploited":false,"published_at":"2026-06-08T02:16:23.747+00:00","url":"https://junglewise.ai/threats/cve-2026-11476-kushan2k-student-management-system-improper-authorization-in"},{"cve":"CVE-2026-11475","cvss":6.3,"slug":"cve-2026-11475-kushan2k-student-management-system-sql-injection-in","title":"Kushan2k student-management-system SQL injection in GradeController","severity":"medium","exploited":false,"published_at":"2026-06-08T02:16:23.577+00:00","url":"https://junglewise.ai/threats/cve-2026-11475-kushan2k-student-management-system-sql-injection-in"},{"cve":"CVE-2026-11474","cvss":7.3,"slug":"cve-2026-11474-kushan2k-student-management-system-unrestricted-upload-in","title":"Kushan2k student-management-system unrestricted upload in RegisterService.php","severity":"high","exploited":false,"published_at":"2026-06-08T01:16:23.073+00:00","url":"https://junglewise.ai/threats/cve-2026-11474-kushan2k-student-management-system-unrestricted-upload-in"},{"cve":"CVE-2026-10777","cvss":7.3,"slug":"cve-2026-10777-ealpha072-student-management-system-improper-authentication-in","title":"ealpha072 Student-Management-System improper authentication in admin backend","severity":"high","exploited":false,"published_at":"2026-06-03T23:16:17.28+00:00","url":"https://junglewise.ai/threats/cve-2026-10777-ealpha072-student-management-system-improper-authentication-in"},{"cve":"CVE-2026-10619","cvss":7.3,"slug":"cve-2026-10619-sayan365-student-management-system-improper-authentication-in","title":"sayan365 student-management-system improper authentication in administrative endpoints","severity":"high","exploited":false,"published_at":"2026-06-02T21:16:26.18+00:00","url":"https://junglewise.ai/threats/cve-2026-10619-sayan365-student-management-system-improper-authentication-in"},{"cve":"CVE-2026-10272","cvss":6.5,"slug":"cve-2026-10272-a4m4-student-management-system-improper-authorization-in-admin","title":"a4m4 Student-Management-System improper authorization in admin/deleteform.php","severity":"medium","exploited":false,"published_at":"2026-06-01T17:16:43.7+00:00","url":"https://junglewise.ai/threats/cve-2026-10272-a4m4-student-management-system-improper-authorization-in-admin"},{"cve":"CVE-2026-10271","cvss":6.3,"slug":"cve-2026-10271-a4m4-student-management-system-authentication-bypass-in-admin","title":"a4m4 Student-Management-System authentication bypass in admin endpoint","severity":"medium","exploited":false,"published_at":"2026-06-01T17:16:43.5+00:00","url":"https://junglewise.ai/threats/cve-2026-10271-a4m4-student-management-system-authentication-bypass-in-admin"},{"cve":"CVE-2026-10112","cvss":2.4,"slug":"cve-2026-10112-sambitraj-student-management-system-stored-xss-in-dashboard-page","title":"sambitraj STUDENT-MANAGEMENT-SYSTEM stored XSS in Dashboard Page","severity":"low","exploited":false,"published_at":"2026-05-30T08:16:16.18+00:00","url":"https://junglewise.ai/threats/cve-2026-10112-sambitraj-student-management-system-stored-xss-in-dashboard-page"},{"cve":"CVE-2026-10111","cvss":7.3,"slug":"cve-2026-10111-sambitraj-student-management-system-sql-injection-in-login-pages","title":"sambitraj STUDENT-MANAGEMENT-SYSTEM SQL injection in login pages","severity":"high","exploited":false,"published_at":"2026-05-30T08:16:16.013+00:00","url":"https://junglewise.ai/threats/cve-2026-10111-sambitraj-student-management-system-sql-injection-in-login-pages"},{"cve":"CVE-2026-9562","cvss":7.3,"slug":"cve-2026-9562-sambitraj-student-management-system-broken-access-control-in","title":"sambitraj STUDENT-MANAGEMENT-SYSTEM broken access control in dashboards","severity":"high","exploited":false,"published_at":"2026-05-26T17:16:57.413+00:00","url":"https://junglewise.ai/threats/cve-2026-9562-sambitraj-student-management-system-broken-access-control-in"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"Sambitraj STUDENT-MANAGEMENT-SYSTEM","slug":"student-management-system","vendor":{"name":"Sambitraj","slug":"sambitraj","url":"https://junglewise.ai/threats/vendors/sambitraj"},"aliases":[],"category":"web-application","homepage":"https://github.com/sambitraj/STUDENT-MANAGEMENT-SYSTEM","repo_url":"https://github.com/sambitraj/STUDENT-MANAGEMENT-SYSTEM","description":"STUDENT-MANAGEMENT-SYSTEM is a web-based application designed for managing student records and academic data.","url":"https://junglewise.ai/threats/technologies/student-management-system"},"most_severe":[{"cve":"CVE-2026-86673","cvss":7.3,"epss":0.0047,"slug":"cve-2026-86673-ningzichun-student-management-system-hard-coded-database","title":"ningzichun Student Management System hard-coded database credentials","severity":"high","exploited":false,"published_at":"2026-09-08T18:21:17.727+00:00","url":"https://junglewise.ai/threats/cve-2026-86673-ningzichun-student-management-system-hard-coded-database"},{"cve":"CVE-2026-11531","cvss":7.3,"slug":"cve-2026-11531-imvks786-student-management-system-sql-injection-in-admin-login","title":"imvks786 student_management_system SQL injection in admin_login.php","severity":"high","exploited":false,"published_at":"2026-06-08T17:16:40.2+00:00","url":"https://junglewise.ai/threats/cve-2026-11531-imvks786-student-management-system-sql-injection-in-admin-login"},{"cve":"CVE-2026-11530","cvss":7.3,"slug":"cve-2026-11530-imvks786-student-management-system-sql-injection-in-login","title":"imvks786 student_management_system SQL injection in Login component","severity":"high","exploited":false,"published_at":"2026-06-08T17:16:40.017+00:00","url":"https://junglewise.ai/threats/cve-2026-11530-imvks786-student-management-system-sql-injection-in-login"},{"cve":"CVE-2026-11474","cvss":7.3,"slug":"cve-2026-11474-kushan2k-student-management-system-unrestricted-upload-in","title":"Kushan2k student-management-system unrestricted upload in RegisterService.php","severity":"high","exploited":false,"published_at":"2026-06-08T01:16:23.073+00:00","url":"https://junglewise.ai/threats/cve-2026-11474-kushan2k-student-management-system-unrestricted-upload-in"},{"cve":"CVE-2026-10777","cvss":7.3,"slug":"cve-2026-10777-ealpha072-student-management-system-improper-authentication-in","title":"ealpha072 Student-Management-System improper authentication in admin backend","severity":"high","exploited":false,"published_at":"2026-06-03T23:16:17.28+00:00","url":"https://junglewise.ai/threats/cve-2026-10777-ealpha072-student-management-system-improper-authentication-in"},{"cve":"CVE-2026-10619","cvss":7.3,"slug":"cve-2026-10619-sayan365-student-management-system-improper-authentication-in","title":"sayan365 student-management-system improper authentication in administrative endpoints","severity":"high","exploited":false,"published_at":"2026-06-02T21:16:26.18+00:00","url":"https://junglewise.ai/threats/cve-2026-10619-sayan365-student-management-system-improper-authentication-in"},{"cve":"CVE-2026-10111","cvss":7.3,"slug":"cve-2026-10111-sambitraj-student-management-system-sql-injection-in-login-pages","title":"sambitraj STUDENT-MANAGEMENT-SYSTEM SQL injection in login pages","severity":"high","exploited":false,"published_at":"2026-05-30T08:16:16.013+00:00","url":"https://junglewise.ai/threats/cve-2026-10111-sambitraj-student-management-system-sql-injection-in-login-pages"},{"cve":"CVE-2026-9562","cvss":7.3,"slug":"cve-2026-9562-sambitraj-student-management-system-broken-access-control-in","title":"sambitraj STUDENT-MANAGEMENT-SYSTEM broken access control in dashboards","severity":"high","exploited":false,"published_at":"2026-05-26T17:16:57.413+00:00","url":"https://junglewise.ai/threats/cve-2026-9562-sambitraj-student-management-system-broken-access-control-in"},{"cve":"CVE-2026-10272","cvss":6.5,"slug":"cve-2026-10272-a4m4-student-management-system-improper-authorization-in-admin","title":"a4m4 Student-Management-System improper authorization in admin/deleteform.php","severity":"medium","exploited":false,"published_at":"2026-06-01T17:16:43.7+00:00","url":"https://junglewise.ai/threats/cve-2026-10272-a4m4-student-management-system-improper-authorization-in-admin"},{"cve":"CVE-2026-86674","cvss":6.3,"epss":0.0038,"slug":"cve-2026-86674-ningzichun-student-management-system-session-fixation-in-login","title":"ningzichun Student Management System session fixation in login","severity":"medium","exploited":false,"published_at":"2026-09-08T19:20:16.963+00:00","url":"https://junglewise.ai/threats/cve-2026-86674-ningzichun-student-management-system-session-fixation-in-login"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}