CVE-2026-16155: Sourcecodester Class And Exam Timetabling System
Low severity, CVSS 3.5. EPSS: 0.3% chance of exploitation in the next 30 days.
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /schoolyr.php. The manipulation of the argument sy leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
Affected products
- Sourcecodester Class And Exam Timetabling System: version 1.0 only
Published 2026-07-18. Last modified 2026-07-21.